Anthropic claims to have disrupted an online mass surveillance system from China, gathering global intel on religious groups that Beijing deems 'suspicious'. Incidentally we tracked it together with @nestedintel weeks earlier. Meet BABEL - Here is the playbook. 1/8
Not sure if the word 'Gang' is fitting the nature of ST pretty well at this stage, but still a good report: "Salt Typhoon is the cyber-spy gang that hacked telecommunications and government agencies to gain stealthy, long-term access to victim organizations going back as far as 2019. These hacks, however, weren’t discovered until late 2023." - https://t.co/VeW4AjSXF7
Selling off 'dedicated lines' ( routers that can go past the GFW) for private use and SMEs is big business in China. Authorities are often in a pickle. Officially they are supposed to stop all of that.
But technically it is still challenging, also many SMEs in China need unrestricted access to the global internet. Getting an official permit is often cumbersome and takes times, not everyone is eligible as well. Therefore a certain amount of this stuff is tolerated.
Until some directive from "higher up" is coming to crack down on it, then it's a few weeks of busy-work with the regional cyber-police. Until it falls back into status-quo.
A trove of 4.8M confidential bank records spanning 20 years shows how ICBC officers ignored red flags and breached internal anti-money laundering policies under pressure from the bank’s Beijing headquarters, ICIJ's #ChinaCapital investigation found. https://t.co/EizoGMhFV2
@UK_Daniel_Card I'd say this issue goes even more basic and comes down to who they hire as "analysts". Even the best governed system can't tackle incompetence born from the guy in front of the box and a 'command-action-chain' that just takes in the stuff as 'face value' and acts upon it.
Looks like AI is not the general problem but as usual, the incompetence and sloppiness of the human individual who operates it. https://t.co/nEIfqiWvf4
🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree
Google says an undercover Mandiant analyst infiltrated TeamPCP's inner circle as the hacking group compromised open-source software and ultimately breached more than 1,000 companies.
⠀
The analyst gained access to TeamPCP's core "CanisterWorm" chat in March, joining a group of roughly 12 members and watching the operation from the inside.
⠀
The mole also gained access to a server containing credentials stolen from victims, including usernames, passwords, and access tokens.
Google used that visibility to alert cloud and technology providers, revoke compromised credentials, and send hundreds of notifications to affected organizations.
⠀
The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.
Google obtained the exploit code, verified that it worked after minor modifications, and privately notified the developer so the vulnerability could be patched.
⠀
TeamPCP's campaign compromised hundreds of open-source packages and affected organizations including GitHub, Mistral AI, Mercor, the European Commission, and employee devices at OpenAI.
⠀
Google says operational security mistakes later helped investigators identify an alleged TeamPCP member, with information passed to the FBI.
Two Australians accused of being principal participants in TeamPCP were arrested last month.
Video shown in US courtroom reveals apparently a Huawei technician stealing hardware from T-Mobile US according to @innercitypress revealed during the EDNY trial : https://t.co/bqAGucYXk1
Well, looks like the Anthropic report didn't go down well in Beijing. When the MSS comes knocking on your door, things usually turn pretty ugly ...fast.
First SMS Blaster Scammer Arrested in Singapore Was Targeting WhatsApp Users - https://t.co/Lcqx8P5eIf
Chinese gangsters used SMS blaster smishing to take control of Singaporean WhatsApp accounts as a stepping stone to authorized push payment fraud.
Good find by @Huntio: Chinese issued TLS certs lead to a SpiceRAT cluster already flagged by Bitdefender in their report on 'SilkParasite'. The cluster hosted copies of official state energy companies from Central Asia. https://t.co/Cd3Anwi2oN 's research could reveal that SpiceRAT, NodeEdgeRAT and NomadRAT share the same infra. https://t.co/skLCYpX47F
WSJ has more on the Chinese cyber security company 'ZRON' and the extend of their espionage operations against diplomats and government members from foreign nations, which we have reported on before. NetAskari will have some more on that too soon. https://t.co/O3DlthSGk2
Today's cybercriminals don't need coding skills. They need a subscription.
Sophos researchers found "Luciferus," an underground AI service marketed with no guardrails, including malware development support.
Learn more: https://t.co/BuINpLQNUl
Another evidence that AI is increasingly used for Big-Data analysis and tracking and surveilling individuals and groups in China. Often still relying on legacy systems, the AI component gains ground quickly as system architectures and their implementation are catching up.
Every target was then classified using PRC-style intelligence sector categories written entirely in Simplified Chinese: 国防/军工关联 (defense/military), 选举/投票系统 (election/voting systems), 能源企业 (energy), 航天/空间 (aerospace), 电信企业 (telecom), 政府/市政/公共服务 (government/municipal)"
@Yusufcancakiir That seems pretty much like an operator box to me...and that it is based in Nepal and much of the logs are in CN...well...definitely needs some closer inspection.