Saturday, December 21, 2024
HomeData BreachBMW Hacked - OceanLotus APT Hackers Group Penetrate The BMW Networks

BMW Hacked – OceanLotus APT Hackers Group Penetrate The BMW Networks

Published on

SIEM as a Service

A well-known APT Hackers group “OceanLotus” breach the automobile giant BMW network, and successfully installed a hacking tool called “Cobalt Strike” which help them to spy and remotely control the system.

Security experts from BMW spotted that hackers penetrate the company network system and remain stayed active since March 2019.

The OceanLotus APT group believed to be active on behalf of the State of Vietnam, and they mainly focus on the automobile industry.

- Advertisement - SIEM as a Service

GBHackers previously reported various high profile malware attacks involved by the OceanLotus APT group around the globe since 2014, and the threat group targets private sectors across multiple industries, foreign governments.

Last weekend, security experts from BMW take down the hacked computers and blocked the path that was used by hackers to penetrate the network.

According to Bayerischer Rundfunk’s reports. ” The automobile company from Munich finally took the computers concerned off the grid. , the group’s IT security experts had been monitoring the hackers for months. This is the result of research by the Bayerischer Rundfunk. Also on the South Korean car manufacturer Hyundai, the hackers had it apart.

An anonymous source reported this incident to BR and states that the hackers didn’t access any sensitive information during the attack period.

BMW refused to comment further about the security incidents, but in general, they said: “We have implemented structures and processes that minimize the risk of unauthorized external access to our systems and allow us to quickly detect, reconstruct, and recover in the event of an incident.”

Based on the expert source report OceanLotus hackers also targeted the Hyundai network, and they left several requests unanswered also there is no specific technical details revealed about the incident.

Andreas Rohr of the IT security firm Deutsche Cybersecurity organization (DCSO) said “If hackers have penetrated a corporate network , they usually try to look around as inconspicuously as possible. Once a company has discovered the attackers, it’s important to find out how far hackers have spread. They are watched for this, sometimes for months. “Typically, you benefit from having discovered someone to see where further compromises exist,” 

Experts believe that the same groups may have been involved with previous automobile security breaches such as Toyota hack, in which cybercriminals accessed the server and they may have been leaked 3.1 million customer personal data online.

Also Read:

Adobe Hacked – Hackers Exploit The Bug in Magento Marketplace & Gained Access To The Users Data

OnePlus Hacked – Customers’ Personal Information Accessed by Hackers

T-Mobile Hacked – Hackers Gained Access to Prepaid Customers Data

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Selling Nunu Stealer On Hacker Forums

A new malware variant called Nunu Stealer is making headlines after being advertised on underground hacker...

Siemens UMC Vulnerability Allows Arbitrary Remote Code Execution

A critical vulnerability has been identified in Siemens' User Management Component (UMC), which could...

Foxit PDF Editor Vulnerabilities Allows Remote Code Execution

Foxit Software has issued critical security updates for its widely used PDF solutions, Foxit...

Windows 11 Privilege Escalation Vulnerability Lets Attackers Execute Code to Gain Access

Microsoft has swiftly addressed a critical security vulnerability affecting Windows 11 (version 23H2), which...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Texas Tech Systems Breach, Hackers Accessed System Folders & Files

The Texas Tech University Health Sciences Center (TTUHSC) and Texas Tech University Health Sciences...

ConnectOnCall Data Breach, 900,000 Customers Data Exposed

 The healthcare communication platform ConnectOnCall, operated by ConnectOnCall.com, LLC, has confirmed a significant data...

BadRAM Attack Breaches AMD Secure VMs with $10 Device

Researchers have uncovered a vulnerability that allows attackers to compromise AMD's Secure Encrypted Virtualization...