Monday, April 12, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Facebook links APT32, Vietnam’s primary hacking group, to local IT firm

December 13, 2020
in Internet Security
Facebook sues two Chrome extension makers for scraping user data
588
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Image via Alex Haney

In a surprising and unexpected announcement on Thursday, the Facebook security team has revealed the real identity of APT32, one of today’s most active state-sponsored hacking group, believed to be linked to the Vietnamese government.

Special feature


Cyberwar and the Future of Cybersecurity

You might also like

Ransomware: The internet’s biggest security crisis is getting worse. We need a way out

Washington State educational organizations targeted in cryptojacking spree

Critical Zoom vulnerability triggers remote code execution without user input


Cyberwar and the Future of Cybersecurity

Today’s security threats have expanded in scope and seriousness. There can now be millions — or even billions — of dollars at risk when information security isn’t handled properly.

Read More

The company said it took this step after it detected APT32 using its platform to spread malware in attempts to infect users.

“Our investigation linked this activity to CyberOne Group [archived website, archived Facebook page], an IT company in Vietnam (also known as CyberOne Security, CyberOne Technologies, Hành Tinh Company Limited, Planet and Diacauso),” said Nathaniel Gleicher, Head of Security Policy at Facebook, and Mike Dvilyanski, Cyber Threat Intelligence Manager.

A CyberOne spokesperson could not be reached for comment over the phone, as a previously listed phone number was offline. Emails sent to the company bounced.

APT32 used Facebook to approach targets

According to Gleicher and Dvilyanski, APT32 operated on Facebook by creating accounts and pages for fictitious personas, usually posing as activists or business entities.

Using romantic or other lures, the group would often share links with their targets to various domains they either hacked or operated themselves.

The links would usually lead to phishing or malware, or would even include links to Android apps that the group had managed to upload on the official Play Store, allowing them to spy on their victims.

Based on its insights into this campaign, Facebook said the group targeted entities such as:

  • Vietnamese human rights activists locally and abroad
  • Foreign governments, including those in Laos and Cambodia
  • Non-governmental organizations
  • News agencies
  • and, businesses across information technology, hospitality, agriculture and commodities, hospitals, retail, the auto industry, and mobile services

Facebook said that besides taking down the group’s accounts and pages, they have also blocked the group’s domains, so they can’t be re-used again under new accounts APT32 might set up in the future.

The social network also shared YARA rules and malware signatures, so other social networks and security firms can also take action and protect their users.

A long string of hacks

Believed to have begun operating in 2014, the APT32 group is also often referred to as OceanLotus.

Its past operations are a literal smorgasbord of activity, and the group has been linked to attacks on almost everything of interest to the Vietnamese state.

This not only included the affairs of neighboring countries, but also attacks on political dissidents and activists, and even private businesses that the group might believe are of interest to the Vietnamese government.

The best example of this targeting has been the group’s widespread attacks on automakers in 2019. In what experts have described as a persistent campaign to steal intellectual property to support Vietnam’s state-funded fledgling automotive startup VinFast, the group hit and stole data from the likes of BMW, Hyundai, Toyota Australia, Toyota Japan, and even Toyota Vietnam, all in succession, in a small time window.

Furthermore, when the coronavirus pandemic hit the world earlier this year, APT32 also re-focused on gathering COVID-19 data, even targeting government officials in Wuhan, China, where the first cases were recorded, seeking information about the disease.

This versatility in targeting is a staple of a mature threat actor. But this versatility also extends to its arsenal of hacking tools. Social engineering, drive-by downloads, Office bugs, custom malware, abusing open-source tools, public exploits, macOS malware — the group has used them all.

Although often ignored in cyber-security reports because of its links to Vietnam, the group has often shown prowess in shifting tactics and hacking tools across the years, a sign that they have the resources and knowledge to adapt.

Facebook’s attribution will be controversial & disputed

According to Facebook, this maturity comes from the fact that behind APT32 is an actual cyber-security firm. But if Facebook is accurate in its attribution remains to be seen.

Facebook’s actions are surprising, to say the least, and are bound to attract scrutiny not only from government officials in Vietnam and all the hacked countries but also from the cyber-security industry.

This is because doxing nation-state groups is something that has been, until today, usually left to prosecutors or anonymous vigilantes only.

Cyber-security firms usually tip-toe around attribution to any government, let alone linking groups to various intelligence agencies or local contractors.

Besides the US Department of Justice and a group known as IntrusionTruth, nobody has dared cross this line.

But if we learned anything, it is that the DOJ is usually also reading and looking into any public attribution of nation-state groups. Three of the four IntrusionTruth doxings have eventually turned into official DOJ cases.

Credit: Zdnet

Previous Post

4 tips to upgrade your programmatic advertising with Machine Learning

Next Post

Global Machine Learning Software Market With Top Growing Companies Forecast 2020-2026 – The Courier

Related Posts

Ransomware: The internet’s biggest security crisis is getting worse. We need a way out
Internet Security

Ransomware: The internet’s biggest security crisis is getting worse. We need a way out

April 12, 2021
Washington State educational organizations targeted in cryptojacking spree
Internet Security

Washington State educational organizations targeted in cryptojacking spree

April 10, 2021
Critical Zoom vulnerability triggers remote code execution without user input
Internet Security

Critical Zoom vulnerability triggers remote code execution without user input

April 10, 2021
Nation-state cyber attacks targeting businesses are on the rise
Internet Security

Nation-state cyber attacks targeting businesses are on the rise

April 10, 2021
These are the terrible passwords that people are still using. Here’s how to do better
Internet Security

These are the terrible passwords that people are still using. Here’s how to do better

April 9, 2021
Next Post
Global Machine Learning Software Market With Top Growing Companies Forecast 2020-2026 – The Courier

Global Machine Learning Software Market With Top Growing Companies Forecast 2020-2026 – The Courier

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Ransomware: The internet’s biggest security crisis is getting worse. We need a way out
Internet Security

Ransomware: The internet’s biggest security crisis is getting worse. We need a way out

April 12, 2021
Data Center Infrastructure Market is Projected to Reach USD 100 Billion by 2027
Data Science

Data Center Infrastructure Market is Projected to Reach USD 100 Billion by 2027

April 12, 2021
Hawaiʻi’s Keck Observatory Aids in Discovery of Rare “Quadruply Imaged Quasars”
Machine Learning

Hawaiʻi’s Keck Observatory Aids in Discovery of Rare “Quadruply Imaged Quasars”

April 12, 2021
Interpretive Analytics in One Picture
Data Science

Interpretive Analytics in One Picture

April 12, 2021
AI and Machine Learning Driven Contract Lifecycle Management for Government Contractors
Machine Learning

AI and Machine Learning Driven Contract Lifecycle Management for Government Contractors

April 12, 2021
Cambridge Quantum Computing Pioneers Quantum Machine Learning Methods for Reasoning
Machine Learning

Cambridge Quantum Computing Pioneers Quantum Machine Learning Methods for Reasoning

April 11, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Ransomware: The internet’s biggest security crisis is getting worse. We need a way out April 12, 2021
  • Data Center Infrastructure Market is Projected to Reach USD 100 Billion by 2027 April 12, 2021
  • Hawaiʻi’s Keck Observatory Aids in Discovery of Rare “Quadruply Imaged Quasars” April 12, 2021
  • Interpretive Analytics in One Picture April 12, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates