At a glance.
- Threat actor targets Taiwan's critical infrastructure sectors.
- ESET describes i-Soon operation.
- Albabat ransomware expands targeting to hit Linux and macOS.
Threat actor targets Taiwan's critical infrastructure sectors.
Cisco Talos warns that a threat actor tracked as "UAT-5918" is targeting critical infrastructure entities in Taiwan, likely to establish long-term access for cyberespionage. The researchers note that the group's TTPs and victimology overlap "substantially" with the Chinese threat actors Volt Typhoon, Flax Typhoon, Earth Estries, and Dalbit. UAT-5918 has targeted entities in telecommunications, healthcare, IT, and other critical infrastructure sectors.
Talos states, "The activity that we monitored suggests that the post-compromise activity is done manually with the main goal being information theft. Evidently, it also includes deployment of web shells across any discovered sub-domains and internet-accessible servers to open multiple points of entry to the victim organizations. UAT-5918's intrusions harvest credentials to obtain local and domain level user credentials and the creation of new administrative user accounts to facilitate additional channels of access, such as RDP to endpoints of significance to the threat actor."