The National Internet Emergency Response Center (CNCERT) has issued a comprehensive report detailing a cyberattack orchestrated by the United States against a leading Chinese research institute specializing in advanced material design. The attackers exploited security vulnerabilities to infiltrate the system, procure administrator account passwords, deploy backdoors and Trojans, and exfiltrate sensitive files. Additionally, they capitalized on software update mechanisms to infiltrate 276 hosts with Trojans, resulting in the theft of business secrets and personal data. These attacks predominantly occurred during the late-night to early-morning hours, Beijing time, and employed jump IP addresses to evade detection, indicative of a high degree of anti-forensic sophistication. The perpetrators demonstrated proficiency in utilizing open-source tools for concealment, and the backdoors and Trojans were designed to operate solely in memory, highlighting their advanced technical prowess.
