
Security researchers from Sophos have detailed evolving tactics by Chinese advanced persistent threat groups through the analysis of their telemetry on campaigns targeting its customers between December 2018 and November 2023.
Sophos assessed and identified that the exploits developed by the threat actors were shared with multiple Chinese state-sponsored frontline groups (Volt Typhoon, APT31 APT41), which have differing objectives, capabilities, and post-exploitation tooling.
The analysis was conducted in response to calls from the UK NCSC and the US CISA for technology developers to provide transparency around the scale of exploitation of edge network devices by state-sponsored adversaries.
These attacks have targeted well-known manufacturers, including Fortinet, Barracuda, SonicWall, Check Point, D-Link, Cisco, Juniper, NetGear, and Sophos.
Initial activity – December 2018 – Victim – Cyberoam
Chinese attackers’ efforts to collect intelligence to aid in the development of malware targeting network devices by installing a remote access trojan on a low-privilege computer is used to drive a wall-mounted video display in the Cyberoam offices. This was done by utilizing a previous unseen and complex rootkit dubbed Cloud Snooper and a novel technique to pivot into cloud infrastructure by leveraging a misconfigured AWS SSM Agent.
The next course of activities seen in early 2020, and continuing through much of 2022, in wjich the attackers exploited a series of previously unknown vulnerabilities they had discovered and then operationalized, targeting WAN-facing services, inorder to retrieve data stored on the comprised devices and deliver payloads insider the device firmware.
These attacks were linked to a research community centered in Chengdu, China, which is believed to be conducting vulnerability research and sharing their findings with vendors and other entities associated with the Chinese government that includes Sichuan Silence Information Technology and the University of Electronic Science and Technology of China.
Another trend seen in which Chinese attackers remain persistent that they help them from immediate discovery. This involved various methods of blocking telemetry being sent from compromised devices to Sophos, designed to prevent the firm from getting the desired data.
Sophos added that the trail of data it could follow with open-source intelligence practices shrank considerably in later attacks due to improvements in the operational security practices of exploit developers.
For more information, refer to the blog

