Critical Infrastructure Security
,
Cyberwarfare / Nation-State Attacks
,
Fraud Management & Cybercrime
The Edge Device Hacking Wave Hasn’t Spared French Companies

France playing host to the Olympics resulted in a surge of cyberattacks requiring intervention of the state cybersecurity agency, it said in an annual report also flagging an uptick in attacks levied against network edge devices.
The French National Agency for Information Systems Security – ANSSI for its French acronym – said Tuesday its responded with varying levels of engagement to more than 4,300 incidents during 2024, a 15% increase in incidents over the previous year.
It attributes the bump to the Paris Summer Olympics, games that went smoothly despite attempts by cyber actors to disrupt them. Attacks came from self-proclaimed hacktivist distributed denial of service attacks from pro-Russian and pro-Palestinian groups, a couple of ransomware attacks that didn’t disrupt competition and a likely Chinese cyber espionage operation.
It also reported that French companies haven’t been immune from the wave of mostly nation-state driven attacks on edge devices (see: Chinese Cyberespionage Group Tied to Juniper MX Router Hacks).
Hackers in one case used a vulnerability in Palo Alto firewalls tracked as CVE-2024-3400 to penetrate a telecom firm and launch a ransomware attack. A list of edge device vulnerabilities addressed by ANSSI last year shows the most frequency flaw it responded to stemmed from zero days exploited in Ivanti gateways. The agency also witnessed hackers popping devices made by Fortinet, Check Point, and other Ivanti devices.
A hacker deploying similar tactics to a Chinese state threat group tracked as UNC5174 by security firm Google Mandiant exploited zero day in Ivanti’s Cloud Service Appliance.
A substantial number of attacks were launched against French telecom companies, mainly for espionage, the agency said. Over the past two years, ANSSI has responded to the compromise of a mobile telecom operator’s core network and an operator of satellite communications that 3experienced an “in-depth compromise for several years.” Cybver defenders discovered another telecom operator that has been infiltrated by a malicious actor in December 2022 that obtained “significant lateralization, espionage, and sabotage capabilities.”
Hackers took steps to obfuscate their origin – as they do – through operational relay box networks, aka ORBs (see: Chinese Cyberespionage Groups Tied to ORB Network Attacks).
“These networks raise the cost of defense against cyberattacks. The use of legitimate network devices also make detection and blocking complex, as it can be difficult to identify malicious traffic,” ANSSI said.