Attacking Air gapped networks

Submitted by: Daryl Haegley, Director, Mission Assurance & Cyber Deterrence at Dod

A threat actor believed to be operating out of China has been targeting physically isolated military networks in Taiwan and the Philippines, Trend Micro reports.

Tracked as Tropic Trooper  < > and KeyBoy, and active since at least 2011, the threat actor is known for the targeting of government, military, healthcare, transportation, and high-tech industries in Taiwan < > , the Philippines, and Hong Kong.

Previously, the group was observed targeting victims with spear-phishing emails containing malicious attachments designed to exploit known vulnerabilities < > , such as CVE-2017-0199

