Jump to content

Malwarebytes and Chinese hackers


Recommended Posts

What you see are mostly web pages. However the control workstation used to access a RAT did show MBAM Pro active. The server or manager end may not be detected. It is the RAT that is seen on compromised systems, not the administrative server or manager side software. If MalwareBytes' Malware Researcher's could get a hold of that software I'm sure that signatures would be created. It is the client side or RAT that is most seen and detected.

Watching the video leaves many questions such as the time frame the video was generated and the version of MBAM Pro. plus what signatures were used at the time of the video.

There are just too many variables to draw a complete conclusion.

Note also Mandiant was hired by the NY Times (NYT) to research who had hacked into the NYT network. It has been alleged that APT1 is a malicious actor(s) of Unit 61398 of China's People's Liberation Army (PLA). If true, we are not talking about day-2-day common off the shelf malware but most likely state created malware specifically targeting victims. Thus the software may have a very small scope of distribution and thus not seen and subsequently not detected by MBAM. Often those that are seen by MalwareBytes' are subsequently detected but there may be a time differential between the malicious release of the software and the files being found and submitted to MalwareBytes' for detection.

The China's PLA has been known to use Chinese Universities students and the Chinese hacker community to perform data acquisition, hacking and hactivism on behalf of China's government and this has been an ongoing issue since the Hainan Island incident a dozen years ago.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.