Government

US Disrupted Chinese Hacking Operation Aimed at Critical Infrastructure: Report 

US government reportedly disabled parts of a botnet-powered cyber campaign conducted by the Chinese threat actor Volt Typhoon.

China

The United States government has disrupted parts of a major hacking campaign attributed to a threat actor linked to China, according to Reuters.

The news giant learned from unnamed Western security officials and one person familiar with the matter that the FBI and the Justice Department have been authorized to remotely disable some aspects of a Chinese cyber operation named Volt Typhoon, which has been known to target critical infrastructure.

The disruption attempt reportedly took place in recent months, but no details are available on exactly what was targeted or what actions were taken. 

Volt Typhoon came to light in May 2023, when Microsoft warned that Chinese government hackers had been stealing data from critical infrastructure in the US territory of Guam. 

In December, the hacking operation was linked to what was described as an ‘unkillable’ botnet powered by many routers and other IoT devices, predominantly easy-to-hack products that had reached end of life.

Cybersecurity firm SecurityScorecard reported earlier this month that it had found evidence suggesting that the UK and Australian governments have also been targeted by Volt Typhoon. 

SecurityScorecard’s research found that the hackers had compromised many vulnerable Cisco routers between late-November and early January. The fact that these router hijacking attacks are very recent indicates that the hackers are likely still active even after the US’s disruption attempt. 

The threat actor has been around since at least mid-2021, targeting organizations in the  communications, manufacturing, utility, transportation, construction, maritime, government, IT, and education sectors. 

Advertisement. Scroll to continue reading.

Reuters reported that the White House has asked the private sector for assistance in tracking Volt Typhoon. National security experts told the news service that attacks such as the ones conducted by this group could enable China to “remotely disrupt important facilities in the Indo-Pacific region that in some form support or service US military operations”. 

Some of Reuters’ sources raised concerns that the hackers’ goal may be to disrupt the readiness of the United States in case China invades Taiwan. 

“This actor is not doing the quiet intelligence collection and theft of secrets that has been the norm in the US. They are probing sensitive critical infrastructure so they can disrupt major services if, and when, the order comes down,” John Hultquist, chief analyst at Mandiant Intelligence, which is part of Google Cloud, told SecurityWeek.

Hultquist previously discussed the activities of Volt Typhoon and the threat posed by the hacker group at SecurityWeek’s 2023 ICS Cybersecurity Conference.

Related: Elusive Chinese Cyberspy Group Hijacks Software Updates to Deliver Malware

Related: Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021

Related: Government, Military Targeted as Widespread Exploitation of Ivanti Zero-Days Begins 

Related Content

Artificial Intelligence

China’s official Xinhua news agency said the two sides would take up issues including the technological risks of AI and global governance.

Vulnerabilities

The Chinese hacking contest Matrix Cup is offering big rewards for exploits targeting OSs, smartphones, enterprise software, browsers, and security products.

Data Breaches

The UK Ministry of Defense said a breach at a third-party payroll system exposed as many as 272,000 armed forces personnel and veterans.

ICS/OT

As cyber threats grow more sophisticated, America cannot afford complacency. The time for decisive action and enhanced cyber resilience is now.

Nation-State

MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities.

Government

The White House has published a national security memorandum focusing on critical infrastructure security and resilience.

Network Security

While China-linked Muddling Meerkat’s operations look like DNS DDoS attacks, it seems unlikely that denial of service is their goal, at least in the...

Artificial Intelligence

CEOs of major tech companies are joining a new artificial intelligence safety board to advise the federal government on how to protect the nation’s...

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version