Chinese hackers secretly use Microsoft TechNet for malware assault

Hackers strike!

Chinese hackers have been using Microsoft's TechNet website to hide malware attack controls used to carry out assaults on all manner of different groups.

Web security firm FireEye reports that the APT (advanced persistent threat) 17 group has been hiding encoded domain names in the comments section of the forum on the popular Microsoft technical documentation site.

The group created accounts to leave the comments and when computers infected by APT17's malware visited the pages they contacted the domains that then pointed the computers in the direction of a command-and-control server owned by APT17.

"Given its effectiveness, we anticipate that this encoding and obfuscation will become a truly pervasive tactic adopted by threat actors around the world. However, by working closely with companies like Microsoft and targeted organisations to develop threat intelligence, we can assist security professionals and disrupt these activities," said Laura Galante, manager of threat intelligence at FireEye.

Other forums could be targeted

FireEye went on to explain that it would be easy for APT17 to use the same tactic on other forums and message boards should they wish to, and the security of TechNet was not compromised as a result of the attack.

Historically, APT17 has targeted US government entities, international nongovernmental organisations and private companies across the globe especially those in the defence industry, law firms, information technology firms and mining companies.

Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired