A major cyber-espionage campaign involving hackers linked to the Chinese government has targeted the websites of Dharamshala-based Tibetan news outlet Tibet Post and the website of Gyudmed Tantric University, a religious institute based in Hunsur Rabyaling in South India. gudme
.
Revealed in the report of Insect Group
A hacking group possibly sponsored by the Chinese government has attacked two websites belonging to the Tibetan community through TAG-112. The purpose of which was to spread the Cobalt Strike beacon to users’ computers and further compromise them with malware. This has been revealed in a report released by Insect Group, the threat research division of Recorded Future, a Massachusetts-based cyber security consulting firm.
Did not delete any data
TAG-112 may be a subgroup of the Chinese advanced persistent threat group Evasive Panda. Also known as TAG-102 and Stormbamboo because of significant similarities in attack tactics, techniques and procedures, Recorded Future’s Insect Group analysis revealed. John Condra, senior director of Insect Group, said that although we do not know the activity performed by TAG-112 on the devices compromised in this campaign, due to their potential cyber espionage and targeting of the Tibetan community, it is almost certain That they were engaged in information collection and surveillance rather than destructive attacks.
Tibet Post International’s website hacked thrice A staff member at Tibet Post International, an online news outlet that publishes in English, Tibetan and Chinese, said on condition of anonymity that their website has faced cyberattacks affecting their digital operations. The first hack targeted the online news outlet’s Chinese web site in July 2023, shortly after it published an article on the Dalai Lama’s birthday celebrations. A second hack occurred in late May which compromised their English website. After this, recently two weeks ago their English website faced another attack.
Source link
[ad_3]