← Home
Darknet Diaries #103 · November 9, 2021 · 58m

Cloud Hopper

Chinese hackers compromised managed IT service providers to gain access to their clients — including NASA, IBM, and the US Navy. By hacking one company, they accessed hundreds.

Canon

•
Rhysider observes that the same trust relationships that make business partnerships valuable also make them exploitable. Every trusted partner is a potential attack vector.

Highlights

•
Supply chain attacks exploit the trust relationships between organizations — the weakest link isn't in your company
Rhysider shows that Cloud Hopper attackers didn't hack their targets directly. They hacked the IT service providers those targets trusted — exploiting the relationship to gain access.