Article: Chinese hackers secretly use Microsoft TechNet for malware assault


#AceSocialNews – Featured Report: China:May.15: Chinese hackers have been using Microsoft’s TechNet website to hide malware attack controls used to carry out assaults on all manner of different groups.

Web security firm FireEye reports that the APT (advanced persistent threat) 17 group has been hiding encoded domain names in the comments section of the forum on the popular Microsoft technical documentation site.

The group created accounts to leave the comments and when computers infected by APT17’s malware visited the pages they contacted the domains that then pointed the computers in the direction of a command-and-control server owned by APT17.

“Given its effectiveness, we anticipate that this encoding and obfuscation will become a truly pervasive tactic adopted by threat actors around the world. However, by working closely with companies like Microsoft and targeted organisations to develop threat intelligence, we can assist security professionals and disrupt these activities,” said Laura Galante, manager of threat intelligence at FireEye.

Chinese hackers secretly use Microsoft TechNet for malware assault




About Ace Worldwide News Group

After 30 years of providing my services in Warwickshire in the United Kingdom. I am in the process of building a network of news sites in finance,business, property, social and healthcare under the name of "Ace News Group" together with providing goods and services through our sales and marketing news. I also have an organisation and fully fledged management consultancy agency. This provides contracts to enable people to provide their news, goods and services.

2 responses

  1. I’m impressed, I have to admit. Seldom do I encounter
    a blog that’s both equally educative and engaging, and let me tell you, you’ve hit the nail on the head.
    The problem is an issue that not enough men and women are speaking intelligently about.
    I am very happy I stumbled across this during my search for something regarding this.