Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - China Hacks Norwegian Software
News & Analysis

China Hacks Norwegian Software

ISBuzz TeamBy ISBuzz TeamFebruary 7, 2019Updated:February 7, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Emails On The Rise
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Recorded Future, in partnership with Rapid7, published a new report that underscores the vulnerabilities that third parties introduce to organizations. The report details a new sustained cyber-espionage campaign by a Chinese threat actor targeting Visma, a major European managed service provider, an international apparel company, and a U.S. firm that does IP law for the pharmaceutical, tech, biomedical and automotive industries.

By targeting managed service providers, the attackers are exploiting the trust companies place in the security of their technology partners. The campaigns were designed to steal IP and to create launching pads for attacks on third-parties associated with the victims. Below are other highlights, and the full report is attached, also available online here.

· The campaign targeting Visma, a $1B Norwegian MSP with 850,000+ customers throughout Europe, and the retailer and U.S. law firm ran from Nov 2017 to Sep 2018.

· In all three incidents, the attackers gained access to networks through deployments of Citrix and LogMeIn remote-access software using stolen valid user credentials.

· Recorded Future identified a new variant of the Trochilus remote access Trojan malware that was used in the attacks, as well as the storage of stolen data in Dropbox.

Experts Comments below: 

#Hackers working on behalf of #Chinese intelligence #breached the network of Norwegian software firm Visma to steal secrets from its #clients, #cybersecurity researchers said yesterday.https://t.co/GGrLNKvWHL

— Haltdos (@halt_dos) February 7, 2019

A serious flaw in Android's operating system framework can let a remote attacker execute computer code on a device by using a "specially crafted PNG file".#cybersecurityhttps://t.co/PD7PwU15T2

— Luke Cooper (@ITsecuritySales) February 7, 2019

Eoin Miller, Principal MDR Analyst at Rapid7:

“Unfortunately, this is the type of nefarious behavior we witness regularly. But there are steps organizations can take to combat these issues. For example, we recommend implementing two-factor authentication for everything. Additionally, strengthening the reviews of authentication attempts against low cost VPN providers or ‘out of the norm’ networks or countries for an individual user is equally important. Organizations should also consider implementing extremely strict application white-listing on sensitive systems.”

.

Simon Whitburn, SVP Cyber Security Services at Nominet:

State hacking campaigns, such as Cloudhopper, that target software supply companies are incredibly dangerous. By breaching one company you can create a backdoor into thousands of others. The information gathered from these types of attacks can then be used for spear phishing attacks on high value individuals which is where serious damage can be done.
“Defending against this type of campaign can be very tough. There is a feeling amongst users that if lots of people trust and use a service then it must be secure. This can result in companies downloading software without checking it themselves first. Cloudhopper demonstrates that this is a dangerous assumption. Whenever a company uses an outside service, even from a reputable source, they need to check that there is nothing malicious lurking in the code. This will add to the deployment time but could help protect organisations against this type of malware spreading. One way of noticing if third party services have been compromised is to measure DNS traffic which could flag if a programme is calling out to a command and control centre.”

Dr. Darren Williams, CEO and Founder at BlackFog:

“With the news that your devices could get hacked just by looking at a photo on your phone, it’s clear that keeping your personal information private is getting harder every day. Even just viewing an innocent-looking image could lead to your data getting leaked without you ever realising. In this day and age, attackers can get in at all angles and they will always be many steps ahead of the average consumer.
“Generally, we can say that about 20% of all data flowing from your phone / device is being sent to China, Russia and the Ukraine on a daily basis (based on internal data collected by BlackFog). This is most often used for data profiling and data coming off the device generally. This can include personal information and files on the device itself. And this is all happening without your knowledge or importantly, your consent. This is why it’s important to take steps to prevent data from leaving your personal devices, such as your laptop or mobile, without your permission. Technology now exists that can stop unwanted data collection and identity profiling by increasingly sophisticated hackers by eliminating content requests that haven’t been requested. Unfortunately, consumers today must resign themselves to the fact that attackers are always going to get in – the key is to prevent them from taking anything out.”

Max Vetter, Chief Cyber Officer at Immersive Labs:

Max Vetter“Software companies are in increasingly being dragged unwittingly in the crosshairs of hacking teams with longer term agendas. They are a ripe target because, whilst being relatively low-profile, often the products they build make up the infrastructure for much bigger end-users. It’s a trojan horse approach – if hackers can find a backdoor in the platforms used by numerous businesses, it can be used time and again.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}