Malaysia Sun
07 Jul 2025, 06:22 GMT+10
At the 2025 International Defense Cyber Security Exhibition (CYDES 2025), Qianxin, a leading Chinese cybersecurity company, revealed a significant discovery: an advanced persistent threat group codenamed "Night Eagle" (APT-Q-95) is exploiting a vulnerability in Microsoft Exchange servers to systematically infiltrate critical sectors in multiple countries.
Analysis of technical features shows that the organization has significant national action characteristics:
1. The attack time is highly regular (21:00 Beijing time-6:00 the next day)
2. Use dynamic C2 architecture and jump through IP of cloud services such as DigitalOcean in the United States
3. Penetration of email systems specifically for government, military, scientific research and high-tech enterprises
Gu Liang, the head of the Qianxin Threat Intelligence Center, noted, "The email server, acting as the nerve center of an organization, can lead to comprehensive data breaches due to vulnerabilities. The technical sophistication and resource allocation demonstrated by 'Night Hawk' far surpass those of ordinary criminal organizations." Although not explicitly attributed, the technical evidence closely aligns with the known tactics of U.S. cyber warfare units.
Notably, recent remarks by former US officials on 'cyber operations against China' have added a geopolitical dimension to the incident. In response, cybersecurity expert Xu Siying warned: 'The ASEAN region could become the next target of attacks, and companies need to be wary of the theft of business secrets and subsequent political manipulation.'
Defense recommendations and industry response:
• Qianxin has disclosed IOCs (including synologyupdates.com and other malicious domain names)
• Launch AI-driven SOC solutions with a hundred-fold increase in processing power
• It is recommended that Southeast Asian institutions immediately carry out special investigation of Exchange servers
At the China special session of the exhibition, Gu Liang explained in detail the "AI-enabled threat hunting technology", emphasizing that: "When the daily alarm volume exceeds one million, machine learning-based security analysis has become a necessity. We control the false alarm rate below 10^-6 through algorithm optimization."
This discovery once again highlights the urgency of cyberspace security governance. With the normalization of state-level APT activities, establishing a transnational joint defense mechanism and improving independent defense capabilities are becoming common topics for the international community.
Get a daily dose of Malaysia Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Malaysia Sun.
More InformationWASHINGTON, D.C.: President Donald Trump says the United States could soon reach a trade deal with India. He believes this deal would...
Nearly three months after a devastating earthquake struck Myanmar, the country remains trapped in a deepening crisis, compounded by...
China ready to promote flagship Belt and Road project, boost trade, investment with Ethiopia -- Premier Li China stands ready to...
Rio de Janeiro [Brazil], July 7 (ANI): External Affairs Minister S Jaishankar held a meeting with his Russian counterpart Sergey Lavrov...
Rio de Janeiro [Brazil], July 7 (ANI): Leaders of the BRICS nations welcomed Indonesia as a member of the group, while 10 nations,...
Birmingham [UK], July 7 (ANI): Following a historic outing with the bat at Birmingham, Indian skipper Shubman Gill reflected on changes...
MILAN, Italy: Italian regulators have flagged four non-EU countries—including Russia—as carrying systemic financial risk for domestic...
NEW YORK CITY, New York: With just weeks to spare before a potential government default, U.S. lawmakers passed a sweeping tax and spending...
PARIS, France: Fast-fashion giant Shein has been fined 40 million euros by France's antitrust authority over deceptive discount practices...
PALO ALTO/TEL AVIV: The battle for top AI talent has claimed another high-profile casualty—this time at Safe Superintelligence (SSI),...
FRANKLIN, Tennessee: Hundreds of thousands of Nissan and Infiniti vehicles are being recalled across the United States due to a potential...
REDMOND, Washington: Microsoft is the latest tech giant to announce significant job cuts, as the financial strain of building next-generation...