A China-based hacking group has been using Microsoft’s TechNet website as part of its attack infrastructure. The group is well-known for attacks against defense contractors, U.S. government agencies and technology and mining companies. APT17 — nicknamed DeputyDog — created accounts on TechNet and then left comments on certain pages. Those comments contained the name of an encoded domain, which computers infected by the group’s malware were instructed to contact. The encoded domain then referred the victim’s computer to a command-and-control server.”]

