ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Security

New Group Calling themselves the Hidden Lynx Revealed

Paul by Paul
September 24, 2013 - Updated on September 28, 2013
in Security
Reading Time: 2 mins read
17569v4 max
Share on FacebookShare on Twitter

Investigators at Symantec articulate the group, which measures between 50 and 100, has been deployed since 2009 and has been involved not only in the notorious Operation Aurora, but also an attack on Bit9 in 2012 and a grand campaign of watering hole attacks that affected thousands of machines earlier this year.

A campaign dubbed the VOHO combined some regional and industry-specific attacks and centered on organizations primarily operating in the United States.

“In a rapidly spreading two-phase attack, which started on June 25 and finished July 18, nearly 4,000 machines had downloaded a malicious payload,” according to a whitepaper Symantec released on the group. “These payloads were being delivered to unsuspecting victims from legitimate websites that were strategically compromised.”

Image representing Bit9 as depicted in CrunchBase

Many of the victims being targeted were U.S. defense contractors protected by Bit9’s whitelisting software.

“The attackers installed Backdoor.Hikit, a Trojan that provides extremely stealthy remote access to compromised systems,” according to the whitepaper. “This highly customized Trojan is typically installed onto servers in the victims’ DMZ, which was the case at Bit9. Credentials for another virtual machine were then stolen. These were used to access the virtual machine that contained one of Bit9’s digital code-signing certificates. The attackers used this code-signing infrastructure to sign thirty-two malicious files, some of which were then retrieved to be used in subsequent attacks on select organizations in the United States defense industrial base.”

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

It is said that this group is using tools that originate from network infrastructure based in China.

One team within the group applies throwaway tools along with basic techniques to attack different targets.  This squad was dubbedTeam Moudoor after the trojan horse they utilize which also acts as an intelligence collector.

A second squad acts as an elite group and penetrates valuable targets, and referred to as Team Naid by Symantec after the Trojan they use.

Symantec security researcher Vikram Thakur speculates that they are state sponsored as group is an uncommon size.

“Hidden Lynx is unique because it is one of the most organized, sophisticated groups using cutting edge hacking techniques to access information from organizations in some of the most technically advanced countries in the world,” said Thakur.

“The group’s goal is to gain access to information within organizations in some of the wealthiest and most technologically advanced countries across the globe,” according to Symantec’s research paper. “It is unlikely that they can use this information for direct financial gain, and the diversity of the information and number of distinguishable campaigns would suggest that they are contracted by multiple clients. This leads us to believe that this is a professional organization that offers a “hackers for hire” service.”

Tags: Bit9chinaLynxOperation AurorasymantecTeam Naid
Previous Post

DEFCAD – 3D Printing Torrent Site

Next Post

IE Zero-Day Attacks Linked to Hidden Lynx

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

Ransomware Attack Cripples PIH Health Whittier Hospital

December 6, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.