In The News

Foreign Hackers Stole Information From Defense Contractors, Researchers Say

Foreign hackers are suspected of breaching several organizations, including defense contractors, and accessing sensitive information, according to a report by cybersecurity researchers.

Hackers stole documents from at least nine entities in the technology, defense, healthcare, energy and education industries after first breaching the organizations in September, according to research conducted by Palo Alto Networks. Researchers were not yet sure of the identities of the hackers but said they verified that several methods and tools used in the breaches are similar to those used by suspected Chinese hackers.

“Ultimately, the actor was interested in stealing credentials, maintaining access and gathering sensitive files from victim networks for exfiltration,” the researchers wrote.

The hackers reportedly breached and stole data from defense contractors, potentially compromising sensitive information sent by the Department of Defense to the contractors, according to the researchers.

“In aggregate, access to that information can be really valuable,” Ryan Olson, vice president of threat intelligence at Palo Alto Networks, told CNN. “Even if it’s not classified information, even if it’s just information about how the business is doing.”

The hackers were reportedly able to access the organizations by exploiting vulnerabilities in their cloud software from technology company Zoho, allowing them to deploy a tool called KdcSponge that stole passwords and sensitive documents.

“KdcSponge is a novel credential-stealing tool that is deployed against domain controllers to steal credentials. KdcSponge injects itself into the Local Security Authority Subsystem Service (LSASS) process and will hook specific functions to gather usernames and passwords,” the researchers wrote.

When reached for comment, the Cybersecurity Infrastructure and Security Agency’s (CISA) executive assistant director for cybersecurity Eric Goldstein told the Daily Caller News Foundation that the agency is working with Palo Alto Networks to respond to the threat.

“Through the Joint Cyber Defense Collaborative (JCDC), CISA worked with Palo Alto Networks to understand, amplify, and drive action in response to the activity identified in this report,” Goldstein said. “This partnership reflects the value of the JCDC, in which government and the private sector work together to gain visibility and reduce risks that no organization can achieve alone.”

Content created by The Daily Caller News Foundation is available without charge to any eligible news publisher that can provide a large audience. For licensing opportunities of our original content, please contact licensing@dailycallernewsfoundation.org

Ailan Evans

Share
Published by
Ailan Evans
Tags: hackers

Recent Posts

Judge Takes Sledgehammer To National Firearms Act

A federal judge ruled Wednesday that the National Firearms Act (NFA) no longer applies to…

12 hours ago

China Picks Up Pace In Global Race To Unlock Limitless Energy

As the world continues its search for power sources to feed an ever-expanding technological boom,…

12 hours ago

Forget the Big Tent, The Dems Have Thrown in the Towel

The Democrats are being steamrolled by the Socialists, and they are letting them use the…

12 hours ago

The Gen Z Fallacy: Algorithmic Captivity, “CulturePills,” and the New Academic Devshirme

We are witnessing a profound sociological paradox. Generation Z is statistically the most formally "educated"…

12 hours ago

Could The Suppression Of Suppressors Be Coming To An End?

The heroic actions of an armed citizen during a Saturday shooting at an Idaho restaurant…

12 hours ago

Guy Who Dropped Out Of Race Blows Out Trump-Backed Republican Amir Hassan In Swing Seat Primary

A little-known candidate soundly defeated President Donald Trump’s pick for a swing House seat Tuesday…

12 hours ago