UPDATED 20:59 EDT / DECEMBER 24 2019

SECURITY

Chinese hacking group has found new way to bypass two-factor authentication

A group with alleged links to the Chinese government has been accused of hacking networks worldwide, but in a rare twist it’s said to be bypassing two-factor authentication in the process.

The hack was detailed late last week by security researchers from Fox-IT Holding B.V. APT20, the group behind the campaign, targets web servers as the first point of entry with a particular focus on Jboss.

Once through the door, the group installs web shells then spreads throughout the network. Showing fairly typical behavior, the group seeks out passwords and administrator accounts to obtain more information from their targets utilizing virtual network credentials for more secure access.

Where it gets interesting is that the researchers claim they found evidence that APT20 was gaining access to VPN accounts that were protected by 2FA. Hacking 2FA isn’t new, and the process involved is somewhat complicated, but APT20 is said to have found a new way to bypass the process.

The hackers are believed to have stolen an RSA SecurID software token from a hacked system, then modified the key to work on different systems.

“The software token is generated for a specific system, but of course this system specific value could easily be retrieved by the actor when having access to the system of the victim,” the security researchers explained. “As it turns out, the actor does not actually need to go through the trouble of obtaining the victim’s system-specific value, because this specific value is only checked when importing the SecurID Token Seed, and has no relation to the seed used to generate actual 2-factor tokens. This means the actor can actually simply patch the check which verifies if the imported soft token was generated for this system, and does not need to bother with stealing the system-specific value at all.”

While specifically applying to software-based tokens, the method is disturbing particularly given that 2FA is regularly held up as a way to prevent hacking such as this.

A full copy of the research into the group can be found here.

Photo: Pexels

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.