Risky Bulletin Newsletter
September 29, 2023
Risky Biz News: Chinese APT hacks subsidiaries, pivots to corporate headquarters
Presented by
News Editor
Cybersecurity agencies from Japan and the US have issued a joint security advisory about a Chinese APT group that is hacking the overseas subsidiaries of US and Japanese companies and then pivoting to their corporate headquarters.
Known as BlackTech (Palmerworm, Temp.Overboard, Circuit Panda, and Radio Panda), the group targets internet-facing routers as their entry point into victim networks.
To maintain access, the group hot-patches the router firmware with a modified version that bypasses security features and contains a built-in SSH backdoor to maintain future access.