{"id":396,"date":"2024-09-23T08:28:33","date_gmt":"2024-09-23T08:28:33","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=396"},"modified":"2024-09-23T08:28:33","modified_gmt":"2024-09-23T08:28:33","slug":"chinese-hackers-exploit-geoserver-flaw-to-target-apac-nations-with-eagledoor-malware","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2024\/09\/23\/chinese-hackers-exploit-geoserver-flaw-to-target-apac-nations-with-eagledoor-malware\/","title":{"rendered":"Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"579\" src=\"https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-1024x579.png\" alt=\"\" class=\"wp-image-397\" srcset=\"https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-1024x579.png 1024w, https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-300x170.png 300w, https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-768x434.png 768w, https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-1536x868.png 1536w, https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image-850x480.png 850w, https:\/\/familiebuckens.nl\/wp-content\/uploads\/2024\/09\/image.png 1800w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and EAGLEDOOR) to infiltrate and exfiltrate data. The use of public cloud services for hosting malicious files and the multi-protocol support of EAGLEDOOR highlight the complexity and adaptability of their operations.&#8221;<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2024\/09\/23\/chinese-hackers-exploit-geoserver-flaw-to-target-apac-nations-with-eagledoor-malware\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2024\/09\/chinese-hackers-exploit-geoserver-flaw.html\">Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware (thehackernews.com)<\/a><span class=\"screen-reader-text\">: Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. &#8220;They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,3],"tags":[31,13],"class_list":["post-396","post","type-post","status-publish","format-standard","hentry","category-geopolitics","category-malware","tag-31","tag-china"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=396"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions"}],"predecessor-version":[{"id":398,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions\/398"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}