Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Klaralven

(7,510 posts)
Fri Oct 8, 2021, 04:27 PM Oct 2021

Never mind Russia: Turkey and Vietnam are Microsoft's new state-backed hacker threats du jour

Iran, Turkey and both North and South Korea are bases for nation-state cyber attacks, Microsoft has claimed – as well as old favourite Russia.

While more than half of cyberattacks spotted by Redmond came from Russia, of more interest to the wider world is information from the US megacorp's annual Digital Defence Report about lesser-known nation state cyber-attackers.

"After Russia, the largest volume of attacks we observed came from North Korea, Iran and China; South Korea, Turkey (a new entrant to our reporting) and Vietnam were also active but represent much less volume," said MS in a post announcing its findings.

While the usual suspects of Russia, China and North Korea are highlighted in the report, Vietnam's APT32 was highlighted by Microsoft's infosec people for targeting "human rights and civil organisations."

The Vietnam-linked group has a track record of not only spying on these but also "foreign corporations with a vested interest in Vietnam's manufacturing, consumer products, and hospitality sectors", according to Thailand's CERT.

"In the last year, espionage, and more specifically, intelligence collection, has been a far more common goal than destructive attacks," said Microsoft in its report, focusing on state threats to cyber security in general rather than Vietnam specifically. "While nations other than Iran mostly refrained from destructive attacks, they did continue to compromise victims that would be prime candidates for destructive attacks if tensions increased to the point where governments made strategic decisions to escalate cyber warfare."

Alongside Vietnam as a newer entrant to the ranks of state-backed threats was Turkey, singled out for hacking Middle Eastern and Balkans telcos. Threat group UNC1326 (aka SeaTurtle) was previously reported on in depth by Cisco Talos in 2019, which pointed out that SeaTurtle was targeting "national security organisations in the Middle East and North Africa" that wanted to gain "persistent access to sensitive networks and systems."

https://www.theregister.com/2021/10/08/microsoft_digital_defence_report/

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Never mind Russia: Turkey and Vietnam are Microsoft's new state-backed hacker threats du jour (Original Post) Klaralven Oct 2021 OP
russia is just outsourcing the work. Javaman Oct 2021 #1
South Korea is the most disturbing... LeftInTX Oct 2021 #2
Latest Discussions»General Discussion»Never mind Russia: Turkey...