Chinese hackers bypass 2FA

Chinese hackers bypass 2FA
(Image credit: Veriato)

A Chinese hacking group has been able to successfully target Western government entities by bypassing Two-Factor Authentication protections.

According to Dutch cybersecurity company, Fox-IT, the hackers were able to remain undetected in compromised systems precisely because they were able to exploit existing security tools already present.

Exploited software

The claims were made by Fox-IT after a two year investigation into compromised systems, which they released in a whitepaper in which they identified the hackers’ activities and methods.

The key actor was identified as the APT20 hacking group, which is claimed to have worked under the authority of the Chinese government for nearly ten years. The group targets government agencies and Managed Service Providers (MSPs) by exploiting vulnerabilities in web servers to access networks.

From there, they can install web shells to facilitate moving through the IT networks, focusing on enterprise application platforms. The hackers also targeted user workstations with administrator privileges, as well as password vaults.

The most surprising finding was that Two-Factor Authentication (2FA) protocols could be bypassed in vulnerable systems, with the hackers able to generate their own software tokens for access within exploited software.

Fox-IT reports that the easiest way to defend against such attacks is by robust use of segmentation, as well as leveraging Microsoft’s Enhanced Security Administrative Environment (ESAE) for greater security.

Via ZDnet

Brian Turner

Brian has over 30 years publishing experience as a writer and editor across a range of computing, technology, and marketing titles. He has been interviewed multiple times for the BBC and been a speaker at international conferences. His specialty on techradar is Software as a Service (SaaS) applications, covering everything from office suites to IT service tools. He is also a science fiction and fantasy author, published as Brian G Turner.

Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
Google Gemini Robotics
Gemini just got physical and you should prepare for a robot revolution
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'