Skip to main content

BMW Hacked !!!! – OceanLotus APT Hackers Group Penetrate The BMW Networks


A well-known APT Hackers group “OceanLotus” breach the automobile giant BMW network, and successfully installed a hacking tool called “Cobalt Strike” which help them to spy and remotely control the system.

Security experts from BMW spotted that hackers penetrate the company network system and remain stayed active since March 2019.

The OceanLotus APT group believed to be active on behalf of the State of Vietnam, and they mainly focus on the automobile industry.

It was previously reported various high profile malware attacks involved by the OceanLotus APT group around the globe since 2014, and the threat group targets private sectors across multiple industries, foreign governments.

Last weekend, security experts from BMW take down the hacked computers and blocked the path that was used by hackers to penetrate the network.

BMW hacked by #OceanLotus in spring 2019
– used CobaltStrike
– no evidence that they had access to central data center in Munich
– Hyundai targeted in the same campaign https://t.co/WPLrqhkkHc

— Florian Roth (@cyb3rops) December 6, 2019


According to Bayerischer Rundfunk’s reports. ” The automobile company from Munich finally took the computers concerned off the grid. , the group’s IT security experts had been monitoring the hackers for months. This is the result of research by the Bayerischer Rundfunk. Also on the South Korean car manufacturer Hyundai, the hackers had it apart.

An anonymous source reported this incident to BR and states that the hackers didn’t access any sensitive information during the attack period.

BMW refused to comment further about the security incidents, but in general, they said: “We have implemented structures and processes that minimize the risk of unauthorized external access to our systems and allow us to quickly detect, reconstruct, and recover in the event of an incident.”

Based on the expert source report OceanLotus hackers also targeted the Hyundai network, and they left several requests unanswered also there is no specific technical details revealed about the incident.

Andreas Rohr of the IT security firm Deutsche Cybersecurity organization (DCSO) said “If hackers have penetrated a corporate network , they usually try to look around as inconspicuously as possible. Once a company has discovered the attackers, it’s important to find out how far hackers have spread. They are watched for this, sometimes for months. “Typically, you benefit from having discovered someone to see where further compromises exist,” 

Experts believe that the same groups may have been involved with previous automobile security breaches such as Toyota hack, in which cybercriminals accessed the server and they may have been leaked 3.1 million customer personal data online

Comments

Popular posts from this blog

What is BLACK WINDOWS 10 V2 windows based penetration testing os,and what are its features.Download link inside

                         Black Windows 10 V2

Mandiant Discloses Critical Vulnerability Affecting Millions of IoT Devices

Today, Mandiant disclosed a critical risk vulnerability in coordination with the Cybersecurity and Infrastructure Security Agency (“CISA”) that affects millions of IoT devices that use the ThroughTek “Kalay” network. This vulnerability, discovered by researchers on Mandiant’s Red Team in late 2020, would enable adversaries to remotely compromise victim IoT devices, resulting in the ability to listen to live audio, watch real time video data, and compromise device credentials for further attacks based on exposed device functionality. These further attacks could include actions that would allow an adversary to remotely control affected devices. At the time of writing this blog post, ThroughTek advertises having more than 83 million active devices and over 1.1 billion monthly connections on their platform. ThroughTek’s clients include IoT camera manufacturers, smart baby monitors, and Digital Video Recorder (“DVR”) products. Unlike the vulnerability published by researchers from Nozomi Ne...