Chinese spies spent months inside aerospace engineering firm’s network using legacy IT
Chinese spies spent months inside aerospace engineering firm’s network using legacy IT#### Chinese state-sponsored spies infiltrated the network of a global engineering company for four months using the default credentials of an admin portal to a legacy IBM AIX server.

The company, which has not been named for privacy reasons, manufactures components for public and private aerospace organisations, as well as critical sectors such as oil and gas.
The intrusion, suspected to be espionage and blueprint theft, was discovered in August by the company’s threat detection tools. The Chinese agents were removed immediately upon discovery, but attempted another attack within 24 hours.
These intrusions exposed the vulnerability of legacy technologies that are not retired or abandoned, but are not easily replaced and persist in a digital landscape dominated by Linux and Windows systems.
The intruders compromised three unprotected AIX servers belonging to the company and uploaded a web shell project that allowed full remote access to the company’s internal network. They also established persistent access, putting them in a prime position for potential intellectual property theft and supply chain manipulation.
According to Binary Defense, the AIX servers were unprotected and exposed to the open Internet, one of which was running an Apache Axis admin portal with default administrator credentials. This allowed the intruders full access to the system and highlights a problem with newer security tools that are not backward compatible with older machines that are critical to multiple systems. Following the breach, the intruders installed an AxisInvoker web shell, which allowed them to harvest Kerberos data, remotely control the box and add SSH keys for secure external logins.
This event highlights the importance for companies to maintain up-to-date security measures across all parts of their IT infrastructure, but particularly their supply chain systems, to prevent similar attacks.