Chinese spies spent months inside aerospace engineering firm's network via legacy IT
ID: 3c9ab3ca-874e-536a-8a77-2c339cf1b9b0
STIX ID: report--3c9ab3ca-874e-536a-8a77-2c339cf1b9b0
Feed Name: The Register (Security)
A Chinese state-sponsored APT gained access to a US-headquartered engineering manufacturer's network by exploiting an exposed IBM AIX server running an Apache Axis admin portal with default credentials. Operators installed an AxisInvoker web shell, harvested Kerberos data and added SSH keys for persistence, then expanded into the Windows environment using NTLM relay, Cobalt Strike, and a fast-reverse proxy to enumerate and attempt credential theft; the intrusion persisted for roughly four months before detection and removal, raising significant supply-chain and intellectual-property theft concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
