Did hackers hit PH nuclear agency, shipping firm with alleged Navy ties?

Did hackers hit PH nuclear agency, shipping firm with alleged Navy ties?

A US cybersecurity firm, Hunt.io, reported a hack involving the theft of sensitive files from a Philippine nuclear research agency and a shipbuilding company linked to the Navy, allegedly by Chinese-speaking operatives. The stolen data includes critical information on nuclear materials, safety protocols, personnel details, and strategic plans, with evidence suggesting the attackers used a slow download method to avoid detection. This is AI-generated. Read the article for full context. Report any errors. Did someone just steal sensitive files from a Philippine nuclear research agency, including documents on nuclear materials, radiation safety, government personnel, and security credentials? And did the same operator hack a Philippine shipbuilding company that provides services to the Navy? That’s what a US cybersecurity company called Hunt.io says it discovered on August 13 in a hack they claim was conducted by Chinese-speaking operatives. What did they get? Potentially quite a lot. Hunt.io claimed to have recovered 176 files totaling 372 megabytes (MB) that it said came from the nuclear research agency, out of a vulnerability from ownCloud, a free and open source software for content collaboration and file sharing that is “commonly deployed by organizations as a self-hosted alternative to commercial cloud storage.” The vulnerability, as Hacker News explained, is an “authentication bypass that could allow an attacker to access, modify or delete any file without authentication if the username of the victim is known and the victim has no signing-key configured.” Though the report doesn’t specifically name the targeted agency, the country’s body for nuclear research is the Philippine Nuclear Research Institute under the Department of Science and Technology. Hunt.io said the stolen information includes data on research reactor core components, historical fuel inventories, radiation safety and incident reporting, and people authorized to interact with equipment, providing “a technical picture of the facility: reactor configuration, movement histories, and the individuals authorized to interact with that equipment.” There were also strategic plans for 2023 to 2028, IT documents, personal data sheets, Statements of Assets, Liabilities, and Net worth, curricula vitae (CVs) and résumés, passport-related documents, and employee foreign travel records. ”Strategy documents reveal internal priorities and program direction, which can be valuable to competitors and attackers alike,” Hunt.io said. Hunt.io also found a KeePass password database, encrypted files, and a BitLocker recovery key. Many of the files were already arranged in Chinese-labeled folders. While Hunt.io was able to analyze 372 MB of files, as mentioned above, the total amount of data exfiltrated may be bigger. The company saw a reference to 9 gigabytes (GB) of files that had been marked as exfiltrated but were no longer in the directory. The researchers also found a 192-MB database dump from a biometrics personnel and attendance system, potentially revealing information about employees and their access patterns. Taking it slow One of the more interesting clues was hidden in the alleged attacker’s own code. Scripts used to retrieve files from the nuclear research agency contained comments and descriptions written in Simplified Chinese. Among them were phrases that translate to “low-speed download of nuclear material documents,” “low-speed download of radiation safety key files,” and “low-speed download of IT planning.” Why would hackers deliberately download something slowly? Maybe because they didn’t want anyone to notice. Hunt.io found that the scripts inserted randomized pauses between requests, including gaps of three to six seconds. The researchers believe this was intended to make the traffic less conspicuous and evade detection. “The heavy use of Chinese in the docstrings, code comments, and output folders strongly suggests the operator is a native speaker, or very comfortable with the language,” the company said. This, Hunt.io argued, suggests someone wasn’t simply grabbing everything available. The operators appeared to know what information they wanted. Who is making these claims? Hunt.io is a Florida-based cybersecurity company whose founders have backgrounds in threat-intelligence company Recorded Future, which Mastercard acquired for $2.65 billion in 2024. Hunt.io cofounders Chris Ueland and Courtney Couch previously worked on Recorded Future’s attack surface team, while Hunt.io head of product German Hoeffner previously headed vulnerability research there. More importantly, Hunt.io said it disclosed its findings to the National Computer Emergency Response Team (NCERT) under the Department of Information and Communications Technology (DICT) before publication and held the report until August 25 as part of responsible disclosure. According to Hunt.io, NCERT coordinated notification of the affected organizations. Rappler has sought confirmation from NCERT, and has also reached out to Hunt.io. An old vulnerability Hunt.io said the operator exploited CVE-2023-49105, a critical ownCloud vulnerability that, under certain conditions, can allow files to be accessed without authentication. OwnCloud disclosed the vulnerability way back in November 2023. If Hunt.io’s findings are confirmed, why was a vulnerability, discovered nearly three years earlier, apparently still exploitable? Here’s another interesting development: two days after Hunt.io published its findings, the US Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2023-49105 to its Known Exploited Vulnerabilities (KEV) catalog. One of the requirements for a vulnerability to be added to the KEV catalog is that “there is reliable evidence that the vulnerability has been actively exploited in the wild.” And a Navy-linked company? Hunt.io said it also found evidence that a Philippine marine engineering and shipbuilding company that provides services to the Navy had been digitally compromised. The researchers found 195 MB of allegedly stolen data, including a copy of the company’s WordPress installation, database, and media library. Hunt.io said the operator had obtained credentials and multiple potential ways back into the company’s website. Whether the compromise reached systems or information connected to the company’s Navy work is unclear. Hunt.io also does not attribute the attack to Beijing or any known threat group, but only noted that they are Chinese-speaking, and with “medium confidence” that this is a “targeted” hack meant to quietly collect some potentially very sensitive Philippine information. “The preciseness of the scripts, deliberate organization of stolen data by content, and the nature of the selected data are difficult to reconcile with an opportunistic actor,” it said. – Rappler.com

Original Source

Read the full article at Rappler →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.