Microsoft says it took over servers being used by China-based hacking group Nickel


The Microsoft Digital Crimes Unit (DCU) has seized 42 websites that the China-based hacking group Nickel used to attack organizations in the US, as well as around the world, according to a report on Microsoft’s blog (via Bleeping Computer). Microsoft says that the attacks were likely carried out to gather intelligence from government agencies, think tanks, and human rights groups.
A US District Court in Virginia gave Microsoft permission to take control of the comprised websites on December 2nd, as outlined in the court document (PDF), allowing Microsoft to redirect traffic from those sites to Microsoft’s servers. While this won’t stop Nickel’s attacks completely, Microsoft says it should help “protect existing and future victims while learning more about Nickel’s activities.” You can view the full list of seized websites in this PDF.
Just after the DCU’s move to block Nickel, Google announced a lawsuit against two Russian individuals believed to be responsible for operating the Glupteba botnet. The botnet was reportedly used to infect one million Windows devices. Meanwhile, Google’s CyberCrime Investigation Group and Threat Analysis Group said they teamed up to delete “around 63M Google Docs observed to have distributed Glupteba, 1,183 Google Accounts, 908 Cloud Projects, and 870 Google Ads accounts associated with their distribution.”
In Microsoft’s initial complaint (PDF), the company says that Nickel uses a “variety of techniques” to install malware on victims’ computers, including compromising third-party virtual private networks and spear phishing. Due to the nature of Nickel’s attacks, the group is able to exfiltrate sensitive information from the device unbeknownst to the user.
“During the infection of a victim’s computer, Nickel deploys malware designed to make changes at the deepest and most sensitive levels of the computer’s Windows operating system,” Microsoft’s complaint reads. “The consequences of these changes are that the user’s version of Windows is essentially adulterated, and unknown to the user, has been converted into a tool to steal credentials and sensitive information from the user.”
Microsoft says that it’s been tracking Nickel since 2016, noting that the group is also referred to as APT15, KE3CHANG, Vixen Panda, Royal APT, and Playful Dragon. Nickel has targeted diplomatic organizations and ministries of foreign affairs across the world, including countries in North America, South America, Central America, the Caribbean, Europe, and Africa. It also reportedly strikes targets that align with China’s “geopolitical interests.”
With the 24 lawsuits that it has filed so far, Microsoft says that the DCU has shut down a total of over 10,000 compromised websites and blocked the registration of 600,000 potentially malicious sites.
In July, the US (along with several other nations) blamed the Chinese government for the Microsoft Exchange attack that compromised the emails of over 30,000 organizations in the US. Google and Microsoft have since pledged to help the US government bolster its cybersecurity.
The Microsoft Digital Crimes Unit (DCU) has seized 42 websites that the China-based hacking group Nickel used to attack organizations in the US, as well as around the world, according to a report on Microsoft’s blog (via Bleeping Computer). Microsoft says that the attacks were likely carried out to gather…
Recent Posts
- Apple TV+ releases a gritty new crime drama trailer for Dope Thief that looks like a stylish version of The Wire
- The women who made America’s microchips and the children who paid for it
- Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc
- Your Earbuds Are Gross. Here’s How to Clean Them Properly
- This smart video lock unlocks with a wave of your hand
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010