Chinese hackers caught bypassing two-factor authentication

Chinese hackers caught bypassing two-factor authentication, though this is not certain. Below are the assumptions from the Dutch company Fox-IT, which specializes in cybersecurity consulting. It is suggested, though there is no direct evidence, that a group of hackers known as APT20 operates under the auspices of Chinese government organizations.

Chinese hackers caught bypassing two-factor authentication

The first known hacking activity attributed to the APT20 group was discovered in 2011. Between 2016 and 2017, the group disappeared from the radar of experts, and only recently did Fox-IT find traces of APT20's intrusion into the network of one of its clients, which requested an investigation into cybersecurity breaches.

According to Fox-IT, over the past two years, the APT20 group has been involved in hacking and accessing data from government bodies, large companies, and service providers in the USA, France, Germany, Italy, Mexico, Portugal, Spain, the UK, and Brazil. Additionally, hackers from APT20 have been active in sectors such as aviation, healthcare, finance, insurance, energy, and even in areas like gambling and electronic locks.

Typically, APT20 hackers used vulnerabilities in web servers, particularly in the Jboss corporate applications platform, to gain access to their victims' systems. After gaining access and planting shells, hackers infiltrated the victims' networks into all possible systems. The discovered accounts allowed the attackers to steal data using standard tools without installing malware. However, the main issue is that APT20 was allegedly able to bypass two-factor authentication using tokens.

Chinese hackers caught bypassing two-factor authentication

Researchers claim to have found evidence that the hackers connected to VPN accounts secured with two-factor authentication. How this happened is something Fox-IT specialists can only speculate about. The most likely scenario is that the hackers managed to steal an RSA SecurID software token from the compromised system. With the stolen program, the hackers could then generate one-time codes to bypass two-factor protection.

In normal conditions, this is impossible to achieve. The software token does not work without connecting to the local hardware token system. Without it, the RSA SecurID program will issue an error. The software token is created for a specific system, and by having access to the victim's 'hardware', one can obtain a specific number to launch the software token.

Chinese hackers caught bypassing two-factor authentication

Fox-IT specialists claim that it is not necessary to have access to the victim's computer and hardware token to launch a (stolen) software token. The entire initial verification process only occurs during the import of the initial generation vector—a random 128-bit number corresponding to a specific token (SecurID Token Seed). This number is unrelated to the initial number, which then relates to the generation of the actual software token. If the SecurID Token Seed verification can somehow be bypassed (patched), then nothing further will prevent the generation of codes for two-factor authentication. Fox-IT states that the verification bypass can be accomplished by modifying just one instruction. After that, the victim's system will be completely and legally open to the attacker without the use of special utilities and shells.



Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster