Facebook tracks 'OceanLotus' hackers to IT firm in Vietnam

CyberOne reveals little information about itself on its website, saying only that it has around 200 employees providing a range of “essential security technologies”.

December 11, 2020 12:07 pm | Updated 12:13 pm IST - LONDON/HANOI, Dec 11

The ministry has previously denied connections to OceanLotus attacks.

The ministry has previously denied connections to OceanLotus attacks.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

Cybersecurity investigators at Facebook have traced a hacking group long suspected of spying on behalf of the Vietnamese government to an IT company in Ho Chi Minh City.

The announcement on Friday is the first time Facebook has publicly exposed an offensive hacking operation and, if confirmed, would be a rare case of suspected state-backed cyberspies being tracked to a specific organisation.

The hackers, known as OceanLotus or APT32, have been accused for years of spying on political dissidents, businesses and foreign officials. Reuters reported this year that the group had attempted to break into China's Ministry of Emergency Management and the government of Wuhan as the COVID-19 outbreak first spread.

Also read | Criminals getting smarter in use of digital currencies to launder money

Facebook said it had found links between cyberattacks previously attributed to OceanLotus and a Vietnamese company called CyberOne Group, which lists an address on a sidestreet in a commercial district of Ho Chi Minh city.

CyberOne Group denied being connected to the hackers.

“We are NOT Ocean Lotus,” a person operating the company's now-suspended Facebook page said when contacted by Reuters. ”It's a mistake.”

Vietnam's foreign ministry, which handles enquiries from international media, did not immediately respond to a request for comment. The ministry has previously denied connections to OceanLotus attacks.

Facebook said the hackers had used its platforms to carry out a range of cyberattacks, some of which employed fake accounts to trick targets by posing as activists, businesses and possible love interests.

Nathaniel Gleicher, Facebook's head of cybersecurity policy, said his team had found technical evidence that linked CyberOne's Facebook page to accounts used in the hacking campaign, as well as to other OceanLotus attacks.

Also read | Cybercrime could cost the world almost $1 trillion in 2020, McAfee says

He declined to detail the exact evidence, saying to do so would make the group more difficult to track in the future. But he said it included online infrastructure, malicious code, and other hacking tools and techniques.

“The actors in this space use some very defined techniques and if we are too public about how we observe those, it really does harm our ability to catch more of this,” Gleicher said.

Movie Theatre and Yoga

Although OceanLotus has not gained the level of notoriety in the West as some suspected Chinese and Russian state-backed hacking operations, it has been prolific in southeast Asia.

Ben Read, a senior manager at U.S. cybersecurity firm FireEye, and Marc-ķtienne Lşveillş, a researcher at Slovakian software security group ESET, said the hacking activity uncovered by Facebook matched operations attributed to OceanLotus.

Read said OceanLotus had been active since at least 2013 and had “all the hallmarks of a substantial state-backed organisation acting in support of Vietnamese government”.

Facebook said it did not have sufficient evidence to attribute OceanLotus beyond CyberOne Group, which it said has also used the names CyberOne Security, CyberOne Technologies, HŔnh Tinh Company Limited, Planet and Diacauso.

CyberOne reveals little information about itself on its website, saying only that it has around 200 employees providing a range of “essential security technologies”.

A careers page that was removed shortly after Reuters contacted the company advertised positions for people with hacking skills and experience in malware analysis. Recruiters boasted of a generous benefits package, including free meals, a mini movie theatre and after-work yoga.

In Vietnam, Facebook is navigating a standoff with government officials who have threatened to ban it if it does not agree to censorship demands. Reuters reported in April that Facebook had complied with a government request to increase its censorship of “anti-state” posts after its servers in Vietnam were taken offline, slowing traffic there to a crawl.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.