China-backed hackers reportedly breached a Digital Certificate Authority


By MYBRANDBOOK


China-backed hackers reportedly breached a Digital Certificate Authority

A suspected Chinese state-sponsored actor known as Billbug, has breached a digital certificate authority as well as government and defense agencies located in different countries in Asia as part of an ongoing campaign since at least March 2022.

 

The activity appears to be driven by espionage and data-theft, however, no data is said to have been stolen till now. Researchers at Symantec said, “The targeting of a certificate authority is notable, as if the attackers were able to successfully compromise it to access certificates, they could potentially use them to sign malware with a valid certificate, and help it avoid detection on victim machines.”

 

However, it was noted that there is no evidence to indicate that Billbug was successful in compromising the digital certificates. The ability of this actor to compromise multiple victims at once indicates that this threat group remains a skilled and well-resourced operator that is capable of carrying out sustained and wide-ranging campaigns.

 

Also known as Bronze Elgin, Lotus Blossom, Lotus Panda, Spring Dragon, and Thrip, Billbug is an advanced persistent threat (APT) group that is believed to operate on behalf of Chinese interests, targeting government and military organizations in South East Asia.

 E-Magazine 
 VIDEOS  Placeholder image

Copyright www.mybrandbook.co.in @1999-2024 - All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.
Other Initiatives : www.varindia.com | www.spoindia.org