Chinese Hacking Groups Used Shared Attack Tool Against US Aerospace Firms, NGOs

Chinese cyber-espionage groups used the same sophisticated hacking tool in campaigns targeting U.S. aerospace companies, nongovernmental organizations, mining companies, and commodity traders, according to two cybersecurity firms that separately investigated the activity.
Volexity, a Virginia-based cybersecurity firm, said on Sept. 21 its discovery of another Chinese hacking group using the same tool added to evidence of coordinated sharing within China’s cyber-espionage community.
The company said the widespread adoption “suggests a coordinated effort within the Chinese CNE community,” referring to computer network exploitation, and assessed that the core tool was likely shared, customized, and used by multiple groups.
Proofpoint, a U.S. cybersecurity company, separately documented on Sept. 9 the same capability in campaigns against a small number of U.S. NGOs, mining companies, commodity-trading firms, and multiple U.S. aerospace companies. It found several espionage groups adopting the tool within days of one another, with most of the observed clusters having a suspected China nexus….