Showing posts with label AIVD. Show all posts
Showing posts with label AIVD. Show all posts

Wednesday, February 14, 2024

Chinese Hackers Infect Dutch Military Network


 

Why do you have to have to a solid vulnerability and patch management processes?

Well? The answer is quite easy: To avoid being hacked.


A part of Dutch military network was hacked by Chinese hackers using a FortiGate firewall vulnerability which was first detected in October 2022. (CVE-2022-42475 FortiOS SSL-VPN) The damage was limited due to the network segmantation in the network design.


https://bit.ly/3uwhqN7


"A Chinese cyber-espionage group breached the Dutch Ministry of Defence last year and deployed malware on compromised devices, according to the Military Intelligence and Security Service (MIVD) of the Netherlands."


"During the follow-up investigation, a previously unknown malware strain named Coathanger, a remote access trojan (RAT) designed to infect Fortigate network security appliances, was also discovered on the breached network."


"Even fully patched FortiGate devices may therefore be infected, if they were compromised before the latest patch was applied.


The malware operates stealthily and persistently, hiding itself by intercepting system calls to avoid revealing its presence. It also persists through system reboots and firmware upgrades."


"While the attacks weren't attributed to a specific threat group, MIVD linked this incident with high confidence to a Chinese state-sponsored hacking group and added that this malicious activity is part of a broader pattern of Chinese political espionage targeting the Netherlands and its allies."


"'For the first time, the MIVD has chosen to make public a technical report on the working methods of Chinese hackers. It is important to attribute such espionage activities by China,' said Defense Minister Kajsa Ollongren."


Friday, July 8, 2022

Dutch Security Service Uses Pegasus Software

A never ending story: Privacy vs. Security

Especially in the digital era where we cannot live without being online.

The theme is "Pegasus" this time. Well, Pegasus has been exposed for a couple of years. But bear in mind that there are many Pegasus-like software all around the world.

https://www.securityweek.com/dutch-used-pegasus-spyware-most-wanted-criminal-report

https://www.dutchnews.nl/news/2022/06/197938/

https://www.volkskrant.nl/nieuws-achtergrond/bedoeld-voor-terroristen-gebruikt-tegen-journalisten-wat-je-moet-weten-over-pegasus~b43d7519/

"Dutch secret services have used the controversial Israeli spyware known as Pegasus to hack targets including the country's most-wanted criminal, a news report said on Thursday.

The Netherlands' AIVD secret service in 2019 used the software bought from Israel's NSO Group to access fugitive alleged drugs kingpin Ridouan Taghi, the Volkskrant daily reported.

Pegasus, which can switch on a phone's camera or microphone and harvest its data, was engulfed in controversy last July after several media outlets reported that governments around the world had used it to spy on opponents."

"The newspaper said the AIVD used Pegasus to spy on Taghi "among others" but did not say who else may have been targeted.

The use of the software has raised eyebrows in the privacy-sensitive Netherlands."