1 MONGOLIA INVESTMENT FORUM TAKES PLACE IN NEW YORK CITY WWW.MONTSAME.MN PUBLISHED:2025/04/30      2 MONGOLIA’S LENDMN SECURES $20M DEBT FINANCING FROM LENDABLE WWW.FINTECHFUTURES.COM  PUBLISHED:2025/04/30      3 JADE GAS CONFIRMS SIGNIFICANT GAS POTENTIAL IN MONGOLIA WWW.TIPRANKS.COM  PUBLISHED:2025/04/30      4 TRANSFORMING REMOTE MINING: HOW IPCC TECHNOLOGY CAN REDEFINE OPEN-PIT OPERATIONS IN MONGOLIA’S GOBI DESERT WWW.UBPOST.MN PUBLISHED:2025/04/30      5 MONGOLIA REMAINS UNDEFEATED AT THE ICE HOCKEY WORLD CHAMPIONSHIP 2025 DIVISION III WWW.MONTSAME.MN PUBLISHED:2025/04/30      6 PRIME MINISTER OYUN-ERDENE VISITS EGIIN GOL HYDROPOWER PLANT PROJECT SITE WWW.MONTSAME.MN PUBLISHED:2025/04/30      7 ‘I FELT CAUGHT BETWEEN CULTURES’: MONGOLIAN MUSICIAN ENJI ON HER BEGUILING, BORDER-CROSSING MUSIC WWW.THEGUARDIAN.COM PUBLISHED:2025/04/30      8 POWER OF SIBERIA 2: ECONOMIC OPPORTUNITY OR GEOPOLITICAL RISK FOR MONGOLIA? WWW.THEDIPLOMAT.COM PUBLISHED:2025/04/29      9 UNITED AIRLINES TO LAUNCH FLIGHTS TO MONGOLIA IN MAY WWW.MONTSAME.MN PUBLISHED:2025/04/29      10 SIGNATURE OF OIL SALES AGREEMENT FOR BLOCK XX PRODUCTION WWW.RESEARCH-TREE.COM  PUBLISHED:2025/04/29      ДӨРВӨН УЛИРЛЫН АЯЛАЛ ЖУУЛЧЛАЛЫН ҮЙЛ АЖИЛЛАГАА ЭРХЛЭГЧДЭД ХӨНГӨЛӨЛТТЭЙ ЗЭЭЛ ОЛГОНО WWW.MONTSAME.MN НИЙТЭЛСЭН:2025/04/30     Н.УЧРАЛ: НЭЭЛТТЭЙ СОНГОН ШАЛГАРУУЛАЛТ ЗАРЛАЖ ҮҮСМЭЛ ОРДУУДЫГ АШИГЛУУЛДАГ БОЛНО WWW.EAGLE.MN НИЙТЭЛСЭН:2025/04/30     849 ТЭРБУМЫН ӨРТӨГТЭЙ "ГАШУУНСУХАЙТ-ГАНЦМОД" БООМТЫН ТЭЗҮ-Д ТУРШЛАГАГҮЙ, МОНГОЛ 2 КОМПАНИ ҮНИЙН САНАЛ ИРҮҮЛЭВ WWW.EGUUR.MN НИЙТЭЛСЭН:2025/04/30     ХУУЛЬ БУСААР АШИГЛАЖ БАЙСАН "БОГД УУЛ" СУВИЛЛЫГ НИЙСЛЭЛ ӨМЧЛӨЛДӨӨ БУЦААВ WWW.NEWS.MN НИЙТЭЛСЭН:2025/04/30     МЕТРО БАРИХ ТӨСЛИЙГ ГҮЙЦЭТГЭХЭЭР САНАЛАА ӨГСӨН МОНГОЛЫН ГУРВАН КОМПАНИ WWW.EAGLE.MN НИЙТЭЛСЭН:2025/04/30     "UPC RENEWABLES" КОМПАНИТАЙ ХАМТРАН 2400 МВТ-ЫН ХҮЧИН ЧАДАЛТАЙ САЛХИН ЦАХИЛГААН СТАНЦ БАРИХААР БОЛОВ WWW.EAGLE.MN НИЙТЭЛСЭН:2025/04/30     ОРОСЫН МОНГОЛ УЛС ДАХЬ ТОМООХОН ТӨСЛҮҮД ДЭЭР “ГАР БАРИХ” СОНИРХОЛ БА АМБИЦ WWW.EGUUR.MN НИЙТЭЛСЭН:2025/04/30     МОНГОЛ, АНУ-ЫН ХООРОНД ТАВДУГААР САРЫН 1-НЭЭС НИСЛЭГ ҮЙЛДЭНЭ WWW.MONTSAME.MN НИЙТЭЛСЭН:2025/04/29     ЕРӨНХИЙ САЙД Л.ОЮУН-ЭРДЭНЭ ЭГИЙН ГОЛЫН УЦС-ЫН ТӨСЛИЙН ТАЛБАЙД АЖИЛЛАЖ БАЙНА WWW.MONTSAME.MN НИЙТЭЛСЭН:2025/04/29     Ц.ТОД-ЭРДЭНЭ: БИЧИГТ БООМТЫН ЕРӨНХИЙ ТӨЛӨВЛӨГӨӨ БАТЛАГДВАЛ БУСАД БҮТЭЭН БАЙГУУЛАЛТЫН АЖЛУУД ЭХЛЭХ БОЛОМЖ БҮРДЭНЭ WWW.MONTSAME.MN НИЙТЭЛСЭН:2025/04/29    

Chinese Hackers Are Using The Coronavirus To Go After Mongolia www.buzzfeednews.com

A group of hackers based in China has leveraged the coronavirus crisis to attack the public and telecom sectors in Mongolia by impersonating the country’s foreign ministry, according to cybersecurity firm Check Point.

The attack, which researchers at Check Point dubbed "Panda-19," faked two documents from the Mongolian minister of foreign affairs. The documents were disguised as updates on the prevalence of the coronavirus cases in Mongolia, but opening them would infect the target’s computer with a tool called RoyalRoad, which would take over the devices without users' knowledge.

The hackers, who have not been identified, have been in operation since 2016 — and the outbreak of the virus has not slowed them down.

“It seems like the situation in China hasn't been affecting this group,” Lotem Finkelstein, Check Point's head of threat intelligence, told BuzzFeed News.

“It is still unclear why they were targeting these specific organizations,” Finkelstein said. “But we know that they were trying to steal documents and to remote control these systems.”

Once the attachment in the email was opened and downloaded, malware would control the infected computer, allowing the attackers to take screenshots and steal information. According to Finkelstein, gaining remote access is a “very advanced capability.”

As a result of the Panda-19 attack, Finkelstein said they were able to fingerprint the group, meaning they can now track it further and help thwart future attacks. The Chinese hackers, previously known for their operations in the Eastern Hemisphere, frequently go after high-profile targets like Russian telecom companies and targets in Ukraine and Belarus.

The coronavirus hacking attacks are going to get worse before they get better, Finkelstein said. “We have seen them active for four years with no intention to stop,” he said. “So we believe that they will use the coronavirus situation [because] it is very effective.”

Check Point has also been tracking malicious domain registrations using COVID-19 keywords. Another firm, Reason Cybersecurity, has tracked fake coronavirus tracking websites set up by hackers attempting to infect users with malware. The data is genuine, Hacker News reported — but if users were to download the app, their passwords would be stolen.

Other researchers have also pointed to a high amount of phishing emails using the coronavirus as lures. These attackers have impersonated the CDC, the World Health Organization, and executives or members of HR departments.

“Coronavirus has been exhausting for us,” Sherrod DeGrippo, senior director of the threat research and detection team at Proofpoint, previously told BuzzFeed News.



Published Date:2020-03-13