Five Eyes and Microsoft accuse China of attacking US infrastructure again
Compromised SOHO-grade routers help, too. The Mimikatz tool, which often appears in news of cyber attacks, has been used by Volt Typhoon's crew.of the tale, Volt Typhoon uses command line tools to"collect data, including credentials from local and network systems."
The gang places that info in a file it tries to exfiltrate, then uses stolen credentials to maintain a persistent presence in target networks. "In addition, Volt Typhoon tries to blend into normal network activity by routing traffic through compromised small office and home office network equipment, including routers, firewalls, and VPN hardware. They have also been observed using custom versions of open source tools to establish a command and control channel over proxy to further stay under the radar," Microsoft suggests.
The Five Eyes advisory points out that Windows makes these activities possible."One of the actor's primary tactics, techniques, and procedures is living off the land, which uses built-in network administration tools to perform their objectives," the advisory states.
"Defenders must evaluate matches to determine their significance, applying their knowledge of the system and baseline behavior. Additionally, if creating detection logic based on these commands, network defenders should account for variability in command string arguments, as items such as ports used may be differ across environments."
United Kingdom Latest News, United Kingdom Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
This new mode could make Microsoft Edge more of a gamer's browserCould gamers flock to Microsoft Edge?
Read more »
Chelmsford construction firm promises to address dust problemA neighbouring firm says 'phenomenal' amounts of dust is damaging cars and getting in workers' eyes.
Read more »
Microsoft's AI gamble with Windows Copilot could be another ClippyWindows Copilot for Windows 11 brings more AI to your PC via Bing Chat
Read more »
How to watch the Microsoft Build 2023 keynote liveFind out about the company's latest developments in the code and app development world
Read more »
Microsoft has a new AI-powered plan to defeat Apple – but there's one big problemMicrosoft won't stop with its AI plans - should Apple be worried?
Read more »
New weekly Xbox Game Pass Quests are now live for another 275 Microsoft Reward PointsThe new weekly Xbox Game Pass quests are now live. We've got the roundup of every quest on offer, how to complete them, and how many Microsoft Rewards Points you'll get for doing so.
Read more »