Several Chinese government-backed threat groups have been observed targeting companies and governments in the European Union.
This claim is from a joint publication by the EU Cybersecurity Authority (ENISA) and the Computer Emergency Response Team for the European Union Institutions, Institutions and Agencies (CERT-EU).
The document, published Wednesday, directly mentions a specific persistent and targeted attack (APT). APT27APT30, APT31, Ke3chang, Gallium, mustang panda.
“On 19 July 2021, the EU called on Chinese authorities to take action against malicious cyber activity originating from their territory related to APT31.” Publication.
“These malicious cyber activities, which had a significant impact, targeted EU and Member State government institutions and political organizations, as well as major European industries.”
About a year later, Belgium also called on Chinese authorities to take action against malicious cyber activities by Chinese attackers, the document adds.
“These threat actors pose a significant and persistent threat to the European Union,” wrote ENISA and CERT-EU. “Recent operations by these actors have focused primarily on information theft, primarily by establishing a permanent foothold within the network infrastructure of strategically related organizations.”
To defend against these and similar threat actors, the European agency said defenders should follow the guidelines provided in the joint publication and the Cybersecurity Mitigation for Critical Threats compiled by rice field SURE ME.
These include following vendor best practices for hardening products, managing administrator accounts and critical assets, and ensuring appropriate access controls for end users and external third-party contractors.
“ENISA and CERT-EU call on all public and private sector organizations within the EU to apply the recommendations contained in this document in a consistent and systematic manner,” the publication said. I’m here.
“These recommendations are intended to reduce the risk of being compromised by the APTs mentioned and to significantly improve the cybersecurity posture and enhance the overall resilience of these organizations to cyberattacks. is.”
The joint advisory came just days after the Chinese threat actor DEV-0147 was attacked. Discovered targeting South American diplomatic institutions.