Mathieu Feuillet · @MathieuFeuillet
16 followers · 17 posts · Server infosec.exchange

just published a report in English about spyware inside untrusted software.

The report contains an analysis of past situations and recomendations on how to protect your network from those mandatory but untrusted softwares.

cert.ssi.gouv.fr/cti/CERTFR-20

#certfr #GoldenSpy

Last updated 2 years ago

Mathieu Feuillet · @MathieuFeuillet
35 followers · 22 posts · Server infosec.exchange

just published a report in English about spyware inside untrusted software.

The report contains an analysis of past situations and recomendations on how to protect your network from those mandatory but untrusted softwares.

cert.ssi.gouv.fr/cti/CERTFR-20

#certfr #GoldenSpy

Last updated 2 years ago

· @h51un6
0 followers · 16 posts · Server infosec.exchange

The French national cybersecurity agency publishes recommendations on how to integrate untrusted (but mandatory) software into a computer network. Focus on

cert.ssi.gouv.fr/uploads/CERTF

#GoldenSpy #threatintel

Last updated 2 years ago

· @redfrog
3235 followers · 58637 posts · Server mamot.fr

CERT-FR has just published a report on the integration of untrusted software. Recommendations are available at the end of the report.
cert.ssi.gouv.fr/cti/CERTFR-20

#GoldenSpy #notpetya

Last updated 2 years ago

Mathieu Feuillet · @MathieuFeuillet
12 followers · 8 posts · Server infosec.exchange

Under some regulations, it is mandatory to use specific softwares. In some cases, spywares can be embedded inside. This was the case with that has been detected in the software "Golden Tax", mandatory under Chinese regulation. More recently, the software "Beijing One Pass" has been found to contain suspicious functionalities.

For more details, you can check the report published recently by /#CERT_FR :
cert.ssi.gouv.fr/cti/CERTFR-20

Only in French for now, the document contains recommendations to protect you IT system against those threats.

#GoldenSpy #anssi

Last updated 2 years ago

Mathieu Feuillet · @MathieuFeuillet
35 followers · 22 posts · Server infosec.exchange

Under some regulations, it is mandatory to use specific softwares. In some cases, spywares can be embedded inside. This was the case with that has been detected in the software "Golden Tax", mandatory under Chinese regulation. More recently, the software "Beijing One Pass" has been found to contain suspicious functionalities.

For more details, you can check the report published recently by /#CERT_FR :
cert.ssi.gouv.fr/cti/CERTFR-20

Only in French for now, the document contains recommendations to protect you IT system against those threats.

#GoldenSpy #anssi

Last updated 2 years ago

Mathieu Feuillet · @MathieuFeuillet
12 followers · 7 posts · Server infosec.exchange

De nombreux cadres réglementaires étrangers imposent l’utilisation de logiciels spécifiques aux entreprises présentes sur leur territoire. Ces logiciels peuvent être utilisés par des attaquants comme point d’entrée sur un réseau informatique. Cela a notamment été le cas avec dans le logiciel "Golden Tax", imposé par la réglementation chinoise. Plus récemment, c'est arrivé avec le logiciel "Beijing One Pass".

Plus de détails dans le document publié par l'ANSSI. Il contient des recommandations pour se protéger contre ce type de menace.

cert.ssi.gouv.fr/cti/CERTFR-20

#GoldenSpy

Last updated 2 years ago

Mathieu Feuillet · @MathieuFeuillet
35 followers · 22 posts · Server infosec.exchange

De nombreux cadres réglementaires étrangers imposent l’utilisation de logiciels spécifiques aux entreprises présentes sur leur territoire. Ces logiciels peuvent être utilisés par des attaquants comme point d’entrée sur un réseau informatique. Cela a notamment été le cas avec dans le logiciel "Golden Tax", imposé par la réglementation chinoise. Plus récemment, c'est arrivé avec le logiciel "Beijing One Pass".

Plus de détails dans le document publié par le . Il contient des recommandations pour se protéger contre ce type de menace.

cert.ssi.gouv.fr/cti/CERTFR-20

#GoldenSpy #cert_fr

Last updated 2 years ago

6beer · @6beer
7 followers · 41 posts · Server infosec.exchange

```
For the digital processing of value-added tax (VAT) returns, the Chinese government has implemented the Golden Tax the Chinese government has implemented the Golden Tax program. Companies operating in China are required to use the software to file their VAT returns. However, the Golden Tax software is not directly distributed by the distributed by the government, but by two companies, Baiwang and Aisino, which integrate it into their products. It seems that
that the selection of either of these vendors is decided by the companies' Chinese banks.

On June 25, 2020, Singaporean cybersecurity firm published a report [3] revealing that the installation of Chinese VAT management software Aisino Intelligent Tax led to the deployment of what amounts to a backdoor, dubbed "" by the vendor. Two hours after the installation of the VAT management software, codes are downloaded and then silently executed. They have persistence mechanisms, communicate at a random frequency with a remote server and allow the execution of arbitrary codes with system administrator privileges without user interaction.
```
cert.ssi.gouv.fr/uploads/CERTF

#goldentax #trustwave #GoldenSpy #anssi #infosec

Last updated 2 years ago

6beer · @6beer
20 followers · 138 posts · Server infosec.exchange

```
For the digital processing of value-added tax (VAT) returns, the Chinese government has implemented the Golden Tax program. Companies operating in China are required to use the software to file their VAT returns. However, the Golden Tax software is not directly distributed by the distributed by the government, but by two companies, Baiwang and Aisino, which integrate it into their products. It seems that
that the selection of either of these vendors is decided by the companies' Chinese banks.

On June 25, 2020, Singaporean cybersecurity firm published a report [3] revealing that the installation of Chinese VAT management software Aisino Intelligent Tax led to the deployment of what amounts to a backdoor, dubbed "" by the vendor. Two hours after the installation of the VAT management software, codes are downloaded and then silently executed. They have persistence mechanisms, communicate at a random frequency with a remote server and allow the execution of arbitrary codes with system administrator privileges without user interaction.
```
cert.ssi.gouv.fr/uploads/CERTF

#goldentax #trustwave #GoldenSpy #anssi #infosec

Last updated 2 years ago