Skip to main content

Command Palette

Search for a command to run...

Chinese Hackers Preparing 'Destructive Attacks,' CISA Warns

Updated
3 min readView as Markdown
Chinese Hackers Preparing 'Destructive Attacks,' CISA Warns
C
酷愛計算機技術Ardently Love Computer Technology 長期關註反洗錢反欺詐Long-term Focus on Anti-Money Laundering and Anti-Fraud 精通支付結算的技術、系統、流程和製度Proficient in the Technology, System, Process and Institution of Payment and Settlement

February 7, 2024


A Chinese hacking group known as Volt Typhoon has maintained access and footholds in some victim information technology environments "for at least five years," the Cybersecurity and Infrastructure Security Agency said Wednesday in a joint cybersecurity advisory. The report, which details how Volt Typhoon has managed to gain persistent access to IT networks while avoiding detection, was published in collaboration with the FBI, the National Security Agency and multiple international partners, including cybersecurity agencies from the United Kingdom, Canada, Australia and New Zealand - the countries that form the Five Eyes intelligence-sharing alliance.

Eric Goldstein, CISA's executive assistant director, said during a Wednesday phone call with reporters that evidence "strongly suggests" the Chinese hacking group is positioning itself on U.S. critical infrastructure networks to launch destructive cyberattacks that would be harmful to national security, economic security and public health.

The report says that Chinese hackers have exfiltrated diagrams and documentation related to operational technology, including SCADA systems, relays and switchgear - data "crucial for understanding and potentially impacting critical infrastructure systems," CISA said. Volt Typhoon actors in some cases had the capability to access camera surveillance systems at critical infrastructure facilities, it also said.

The U.S. government and the Five Eyes intelligence-sharing alliance first publicly disclosed the existence of Volt Typhoon in May after cyber defenders had detected activity in Guam and the United States. The Pacific island is just hours away from Taiwan via airplane and is the site of two major American military bases.

Microsoft, which also divulged the existence of Volt Typhoon in May, said the group has been active since mid-2021. CISA's report says "strong operational security" has allowed the threat actor to penetrate networks that have remained undetected for years.

Cybersecurity experts have observed growing sophistication in Chinese state hackers - a possible effect of a Beijing law that requires mandatory disclosure to the government of vulnerability reports.

Appliances located on network edges, such as VPNs, have been a particular target of Chinese hackers, and the Dutch government warned yesterday that Chinese threat actors perform wide and opportunistic scanning campaigns for vulnerable devices and use zero-days and recently patched vulnerabilities to gain surreptitious access.

"The information that we are releasing with this advisory is reflecting a strategic shift in PRC malicious cyber activity," Goldstein said. CISA has observed Chinese hacking groups moving away from espionage campaigns toward "prepositioning for future disruptive or destructive attacks," he added.

Volt Typhoon typically attacks victim environments through known or zero-day vulnerabilities in public-facing networks, the report says. It then conducts extensive reconnaissance operations to learn about the organization's staff, security practices and overall network structure. Its goal is often to gain admin credentials and eventually achieve full domain compromise. The hackers can then carry out "meticulous post-exploitation intelligence collection" operations and further disrupt the victim networks, according to the advisory.

More from this blog

Penetration Test、Python、Weaponization

721 posts

微信 smartcat9999 反欺詐Anti-Fraud 反洗錢Anti-Money Laundering 反逃稅Anti-Tax Evasion 滲透測試Penetration Test 武器化Weaponization