https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Hacking group

Operation Wocao Exposes One of China’s Hidden Hacking Groups

  • Written by Pam Baker
  • December 20, 2019
Report reveals new details on APT20 believed to be working on behalf of Chinese government in espionage purposes.

A new report by Netherlands-based Fox-IT, part of U.K.-based NCC Group, exposes in greater detail a previously underreported threat actor believed to be operating on behalf of the Chinese government for espionage purposes. The researchers identified victims in 10 countries, ranging from government entities to managed service providers, and across several industries, including energy, health care and high-tech.

For the past two years, the group has been stealing passwords and circumventing two-factor authentications as well as performing other malevolent activities. Fox-IT researchers believe the hacking group is APT20, judging by the patterns in tools, techniques and procedures. Government-backed hacking groups tend to be well funded, resource rich and highly focused. This makes finding their footprints particularly challenging for security teams.

The Fox-IT security researchers assigned the name Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) to the group’s hacking activities, which often slide by undetected.  According to the report, details on how this group operates include:

  • They carry out most of their activities on the basis of access through legitimate channels.
  • For backup purposes, they may keep additional access methods in place.
  • They move through the network, directly singling out workstations of employees with privileged access.
  • On these systems, the contents of passwords vaults (password managers) are directly targeted and retrieved.
  • As much as is possible, they remove file system-based forensic traces of their activities, making it much harder for investigators to determine what happened after the fact.
  • On the basis of the above, an attacker can efficiently achieve their goal of exfiltrating data, sabotaging systems, maintaining access and jumping to additional targets.
  • Overall the actor has been able to stay under the radar even though the tools and techniques they use for their hacking operations are relatively simple and to the point.

Fox-IT recommends the following actions to help mitigate this threat actor:

  • Zero Trust or Robust segmentation must be one of the guiding principles of any infrastructure, both for systems and identities. As part of that, leveraging Microsoft’s Enhanced Security Administrative Environment (ESAE) where applicable will greatly increase resilience and can prevent many attacks from succeeding.
  • Timely detection of and adequate response to any serious incident should include a combination of high-level and low-level telemetry from network and endpoints.

There are other steps that can be taken to improve defenses too, including patching skill gaps.

Lucy Security's Collin Bastable

Lucy Security’s Collin Bastable

“Up to 30% of untrained staff are highly susceptible to the attacks that do succeed. Just like technical defenses, staff can be ‘patched’ to reduce their vulnerabilities to phishing attacks, by training them in a holistic, integrated way. Treat people and systems as parts of the whole,” said Colin Bastable, CEO of security awareness training company Lucy Security.

“A holistic approach to cybersecurity is essential — deploy technical defenses and ‘patch’ your staff to significantly protect assets through defense in depth,” Bastable added.

MSSPs and other security providers are advised to stay vigilant against nation state threat actors, as they tend to target both public and private entities to obtain information for espionage purposes, to influence elections, to gain access to other targets and to create havoc and damage in the real world.

The Center for Strategic & International keeps tabs on nation state attacks. It has determined China to be a top offender. Its “Survey of Chinese-linked Espionage in the United States Since 2000” report lists 137 publicly reported instances of Chinese espionage directed at the United States.

“It reached this conclusion from examining public data only.  The true depth of China’s efforts — and successes — in penetrating western networks is probably still unknown,” warns Strand Consult in a threat brief.

Tags: MSPs Business of Security Cloud and Edge MSSP Insider Security Training and Policies

Most Recent


  • AI spells the end of end-user security
    AI Spells the End of End User Security
    We need to do a hard reset on our expectations for end user security.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.
  • Joseph Chong Enterprise Connect
    ‘Collaborate Happy’: Zoom, Google Cloud, AWS Showcase New AI, Machine Learning Tools
    “Things that are not possible are possible,” said Google Cloud at Enterprise Connect.
  • Growth
    Okta Launching Updated Partner Program to Accelerate Growth
    Okta wants to engage with its partners more strategically.

One comment

  1. Avatar Alvin Bernstein January 2, 2020 @ 9:17 am
    Reply

    I had my offices servers and applications at an MSP that had its own data center, but the service and performance was terrible, and we had a feeling that security was simply not up to par with what we needed for HIPAA compliance and disaster recovery. Our medical offices throughout New Jersey could not afford any downtime. I met with several other vendors and finally found one that provided honest advice and recommendations. Baroan Technologies really stood apart from the rest and migrated us to Microsoft Azure. This way we know that it is not up to a basic MSP like Synoptek anymore, but the servers are really in Azure. I also like that I’m not in a vendor lock with any MSP. I can transfer the Azure servers to the management of any company that I want. Baroan handles everything for a fixed fee. We have two factor MFA with DUO and Microsoft for our email, our terminal server, just about everything. I got peace of mind, so I never have to think about a disaster like what happened with Synoptek and their customers. I recommend that any business that has their servers at the private data center of any MSP should question why it is so. Find an IT vendor like Baroan Technologies that cares more about your business then just their own interests and take steps before there is a disaster.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here
  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware

March 30, 2023

National Women’s History Month: Channel Women on Getting Good Advice

March 30, 2023

Amplify 2023: HP Tackling Tough Market with ‘Realistic Optimism’

March 29, 2023

Industry Perspectives

View all

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

.@HP thanks partners, promises to reduce wait times and complexity across organization. #HPAmplify… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@Kyndryl #layoffs impacting a percentage of workforce. dlvr.it/SllFbF https://t.co/Bo77KdJMpx

March 30, 2023
ChannelFutures

[email protected] makes #DE&I a priority year-round, not just for @womenshistmonth. “A constant cadence of activism… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 Tune into the latest CFTV episode, brought to you by @HitachiVantara, all about how you can identify your competi… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

“Things that are not possible are possible,” said @Google's @behshad_behzadi at #EnterpriseConnect about generative… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 We asked 2023 #ChannelInfluencer @peter_kujawa from Service Leadership what his secret sauce is- his work philoso… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@okta rolling out redesigned partner program. #cybersecurity dlvr.it/SlkYJl https://t.co/52Wx5prcNS

March 30, 2023
ChannelFutures

Need some advice? Women in the communications and IT channel share some of the best they’ve ever received about wor… twitter.com/i/web/status/1…

March 30, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X