Detect the new network aimed at Vietnam

Department of Safety information (TT&TT) suggested the agencies, organizations and businesses nationwide test, reviewing the system information, potentially affected by the new APT.

As APT was safety experts forecast information is one of the trends attack highlights in year 2024 and all the next year, along with denial of service distributed – DDoS and attack data encryption extortion – ransomware. ‘Mustang Panda’ is known to be one of the attacking team, APT has done many campaigns as to the agencies and organizations in southeast Asia, including Vietnam.

Report information security Vietnam quarter of 2024 by Viettel Cyber Security implementation was evaluated Mustang Panda is 1 in 4 groups attack the APT has a large impact on the organizations and enterprises in Vietnam. Experts Viettel Cyber Security also commented, however, the number of malicious code due to ‘Mustang Panda’ dispersal reduced, but there are more sophisticated level, this group has changed and improved many techniques to cause difficulties in the detection and investigation of the attack.

Department of Safety information (TT&TT) issued the warning about the campaign, new attack of the ‘Mustang Panda’ aimed at Vietnam.

Specifically, the Department of Safety information to know, in the process of monitoring safety information on the space network, recently the Monitoring center, safe space network national – NCSC Department has detected and recorded the behavior, attack the group ‘Mustang Panda’ in the campaign aimed at organizations in Vietnam.

Campaign new attack of the ‘Mustang Panda’ use the ‘bait’ revolves around the field of education and tax, on the application of the approach angle, and taking advantage of tools like ‘forfiles.exe’ to execute the malicious file is hosted at server C&C. The target that is heading towards is the government organization, non-profit organizations, educational institutions...

Analysis of the expert also pointed out that two campaign attack of the ‘Mustang Panda’ was recorded in the months of 4 and 5 aimed at enterprises and organizations in Vietnam have used text file that contains content related to the tax authorities, and educational institutions. Both campaigns have in common is derived from the phishing emails with file attachments, malicious.

Tan cong APT Viet Nam anh 2

The units across the country, including the business of providing telecommunication services, Internet are required to check the system potentially affected by the attack.

Photo: vietnam.net.

To ensure information security for the information system of units, contribute to ensuring safety for all of Vietnam, the Department of Safety information, the proposed unit in charge of IT, information security ministries and departments, local; corporations, the state corporation; The business of providing telecommunication services, Internet and digital platforms along the financial institutions, commercial banks conduct the inspection, reviewing system information within the scope of management are likely to be affected by the campaign to attack by the group ‘Mustang Panda’ done.

The agencies, organizations and businesses also need to actively monitor the information related to the campaign aims to perform block, avoid the risk of being attacked. At the same time, strengthen the supervision and ready embodiment, the processor when it detects signs of exploitation, network attacks, and regularly monitor channel warnings of the authorities, as well as the organization on information security for the timely detection of the risk of network attacks.
Source: znews.vn