Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

China Says Washington Hack Claims ‘Fabricated’, Condemns US Allies

China on Tuesday said the US had “fabricated” allegations it carried out a massive Microsoft hack, countering that Washington was the “world champion” of cyber attacks while raging at American allies for signing up to a rare joint statement of condemnation.

China on Tuesday said the US had “fabricated” allegations it carried out a massive Microsoft hack, countering that Washington was the “world champion” of cyber attacks while raging at American allies for signing up to a rare joint statement of condemnation.

The United States on Monday accused Beijing of carrying out the March cyber attack on Microsoft Exchange, a top email server for corporations around the world, and charged four Chinese nationals over the “malicious” hack.

US Secretary of State Antony Blinken said the attack was part of a “pattern of irresponsible, disruptive and destabilizing behavior in cyberspace”.

China’s Ministry of State Security, or MSS, “has fostered an ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain”, Blinken said in a statement.

In a simultaneous announcement, the US Department of Justice said four Chinese nationals had been charged with hacking the computers of dozens of companies, universities and government bodies in the United States and abroad between 2011 and 2018.

President Joe Biden told reporters the United States was still completing an investigation before taking any countermeasures, and drew parallels with the murky but prolific cybercrime attributed by Western officials to Russia.

“The Chinese government, not unlike the Russian government, is not doing this themselves, but are protecting those who are doing it, and maybe even accommodating them being able to do it,” Biden told reporters.

In an effort to put the diplomatic squeeze on Beijing, the United States coordinated its statement Monday with allies — the European Union, Britain, Australia, Canada, New Zealand, Japan and NATO.

Advertisement. Scroll to continue reading.

China hit back, calling the allegations of a Beijing-supported cyber-attack campaign “fabricated”.

“The US has mustered its allies to carry out unreasonable criticisms against China on the issue of cybersecurity,” foreign ministry spokesman Zhao Lijian told reporters in Beijing.

“This move is fabricated out of nothing.”

Earlier, China’s diplomatic missions around the world rattled out rebuttals, as Beijing made its own coordinated defence.

The Chinese embassy in New Zealand called the allegations “totally groundless and irresponsible” while the embassy in Australia accused Canberra of “parroting the rhetoric of the US”.

“It is well known that the US has engaged in unscrupulous, massive and indiscriminate eavesdropping on many countries including its allies,” the embassy said in a statement.

“It is the world champion of malicious cyber attacks.”

– NATO solidarity –

Biden, like his predecessor Donald Trump, has ramped up pressure on China, seeing the rising Asian power’s increasingly assertive moves at home and abroad as the main long-term threat to the United States.

Allies backed up the castigation of China, with British Foreign Secretary Dominic Raab describing the cyberattack as “reckless”.

NATO offered “solidarity” over the Microsoft hacking without directly assigning blame.

State Department spokesman Ned Price said it was the first time that NATO — the Western military alliance whose members include Hungary and Turkey, which have comparatively cordial relations with Beijing — has condemned cyber activity from China.

“We know we’ll be stronger, we know we’ll be more effective when we act collectively,” Price said, saying the United States was not ruling out further action.

Biden has promised a strategy driven by alliances to face Beijing, drawing a contrast with Trump’s predilection for harsh rhetoric.

– Billions seen lost –

The Microsoft hack, which exploited flaws in the Microsoft Exchange service, affected at least 30,000 US organisations including local governments as well as organizations worldwide.

“Responsible states do not indiscriminately compromise global network security nor knowingly harbor cyber criminals — let alone sponsor or collaborate with them,” Blinken said in his statement.

“These contract hackers cost governments and businesses billions of dollars in stolen intellectual property, ransom payments, and cybersecurity mitigation efforts, all while the MSS had them on its payroll.”

Accusations of cyberattacks against the United States have recently focused on Russia, rather than China.

US officials say that many of the attacks originate in Russia, although they have debated to what extent there is state involvement. Russia denies responsibility.

Related: ‘Five Eyes’ Nations Blame China for APT10 Attacks

Related: More Countries Officially Blame Russia for SolarWinds Attack

Related: UK, US, Canada Accuse Russia of Hacking Virus Vaccine Trials

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cyberwarfare

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...