Intelligence

FBI warns US companies on the use of Chinese Tax Software

The FBI has issued an alert to warn US organizations of the risk associated with the use of Chinese tax software that could be infected with malware.

The Federal Bureau of Investigation has issued an alert to inform organizations in the United States of the risk associated with the use of Chinese tax software.

The alert aims at informing US companies in the healthcare, chemical, and
finance sectors of cyber espionage activity by the Chinese government against their business and branches operating in China.

“Compromise of the pharmaceutical supply chain provides malicious actors opportunities for theft of US intellectual property, while public disclosure can cause cascading effects including loss of public trust in both chemical and healthcare institutions.” reads the alert. “As previously highlighted in FBI PIN 20200521-001 released on 21 May 2020 and the US Department of Homeland Security’s joint advisory with Britain’s National Cyber Security Centre, hackers continue to “actively target organizations that include healthcare bodies, pharmaceutical companies, academia, medical research organizations, and local governments.”

At the end of June, the experts from Trustwave spotted GoldenSpy, a new backdoor, that is being distributed embedded in tax payment software (the Aisino Intelligent tax software) that some businesses operating in China are required to install.

The campaign is active since at least April 2020, but experts found some samples that suggest the attacks begun at least December 2016.

A few days after the publishing of the report, an uninstaller was pushed to compromised machines, to completely remove GoldenSpy implementing the removal procedure suggested by Trustwave in its initial report.

Anyway, researchers were able to discover another piece of malware, dubbed GoldenHelper, that was delivered with the same mechanism. GoldenHelper was bundled in the Golden Tax Invoicing Software (Baiwang Edition), which Chinese banks require their clients to install.

This second malware is completely different from GoldenSpy, experts noticed that although it is called “Baiwang Edition”, GoldenHelper was digitally signed by NouNou Technologies, a subsidiary of Aisino Corporation.

According to the alert, at least two Western organizations doing business in China would install the backdoor.

“As early as March 2019, at least two Western companies operating in China detected malware that was delivered through Chinese vendors that were responsible for releasing tax software upgrades following changes in 2018 to China’s value-added tax (VAT).” the alert continues.”The malware launched a backdoor into victim systems, which the FBI assesses likely allows cyber actors to preposition to conduct remote code execution and exfiltration activities on the victim’s network.”

Feds believe that all foreign companies operating in China might be at risk due to the use of the software from Baiwang and Aisino, the two tax software service providers authorized to operate the value-added tax (VAT) system in China.

The alert also includes recommendations on how companies can mitigate the risk of hack intrusions. The FBI also published the indicators of compromise (IoC) for the threats.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, tax software)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

1 hour ago

US offers a $10 million reward for information on four Iranian nationals

The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…

8 hours ago

The street lights in Leicester City cannot be turned off due to a cyber attack

A cyber attack on Leicester City Council resulted in certain street lights remaining illuminated all…

9 hours ago

North Korea-linked APT groups target South Korean defense contractors

The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…

20 hours ago

U.S. Gov imposed Visa restrictions on 13 individuals linked to commercial spyware activity

The U.S. Department of State imposed visa restrictions on 13 individuals allegedly linked to the…

1 day ago

A cyber attack paralyzed operations at Synlab Italia

A cyber attack has been disrupting operations at Synlab Italia, a leading provider of medical…

1 day ago

This website uses cookies.