ArcaneDoor attacks linked to Chinese threat actors

Threat operation UAT4356, also known as Storm-1849, which was behind the ArcaneDoor cyberespionage campaign that targeted Cisco firewalls and other vendors’ perimeter network devices, has been associated with China following an investigation of the group’s attack infrastructure, according to The Hacker News. Aside from most of the operation’s online hosts with the SSL certificate having been linked with ChinaNet and Tencent autonomous systems, UAT4356 has also used an IP address referencing an anti-censorship tool based on an open-source project with a Chinese language website, a report from Censys showed.

Source: SC Magazine

 


Date:

Categorie(s):