Feb 29 2012
APT
Three of the IP addresses used by the servers that controlled the compromised systems observed by SecureWorks also overlapped with addresses that hosted servers used in attacks last year on RSA. The attackers used their access to RSA’s systems to steal highly sensitive data related to the company’s two-factor SecurID authentication tokens that 40 million employees use to access corporate and government networks. The IP addresses belong to the China Beijing Province Network’s autonomous system 4808, which researchers say has long been a hotbed for espionage-related malware.»
arstechnica‘s Dan Goodin coments on this report from DELL SecureWorks.
See also this, this, and this.
APT.

