Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel
TT

Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel

A state-sponsored Chinese hacking group has been spying on a wide range of US critical infrastructure organizations, from telecommunications to transportation hubs, Western intelligence agencies and Microsoft said on Wednesday.

The espionage has also targeted the US island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that "mitigating this attack could be challenging."

While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure, Reuters said.

The Chinese embassy in Washington did not immediately respond to a Reuters request for comment.

It was not immediately clear how many organizations were affected, but the US National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the US Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the hackers too.

Microsoft analysts said they had "moderate confidence" this Chinese group, which it dubbed as 'Volt Typhoon', was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

"It means they are preparing for that possibility," added said John Hultquist, who heads threat analysis at Google's Mandiant Intelligence.

The Chinese activity is unique and worrying also because analysts don't yet have enough visibility on what this group might be capable of, he added.

"There is greater interest in this actor because of the geopolitical situation."

As China has stepped up military and diplomatic pressure in its claim to democratically governed Taiwan, US President Joe Biden has said he would be willing to use force to defend Taiwan.

Security analysts expect Chinese hackers could target US military networks and other critical infrastructure if China invades Taiwan.

The NSA and other Western cyber agencies urged companies that operate critical infrastructure to identify malicious activity using the technical guidance they issued.

"It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems," Paul Chichester, director at the UK's National Cyber Security Center said in a joint statement with the NSA.

Microsoft said the Chinese hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.

NSA cybersecurity director Rob Joyce said the Chinese campaign was using "built-in network tools to evade our defenses and leaving no trace behind." Such techniques are harder to detect as they use "capabilities already built into critical infrastructure environments," he added.

As opposed to using traditional hacking techniques, which often involve tricking a victim into downloading malicious files, Microsoft said this group infects a victim's existing systems to find information and extract data.

Guam is home to US military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.

Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam "a logical target for the Chinese government" to seek intelligence.

"There is high vulnerability when cables land on shore," he said.

New Zealand said it would work towards identifying any such malicious cyber activity in its country.

"It's important for the national security of our country that we're transparent and upfront with Australians about the threats that we face," Australia's Minister for Home Affairs and Cyber Security Clare O'Neil said.

Canada's cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. "However, Western economies are deeply interconnected," it added. "Much of our infrastructure is closely integrated and an attack on one can impact the other."



Blinken Meets China’s Wang after Chiding Beijing’s ‘Escalating Actions’ at Sea

US Secretary of State Antony Blinken speaks at the 57th ASEAN Foreign Ministers' Meeting at the National Convention Center, in Vientiane, Laos, July 27, 2024. (Reuters)
US Secretary of State Antony Blinken speaks at the 57th ASEAN Foreign Ministers' Meeting at the National Convention Center, in Vientiane, Laos, July 27, 2024. (Reuters)
TT

Blinken Meets China’s Wang after Chiding Beijing’s ‘Escalating Actions’ at Sea

US Secretary of State Antony Blinken speaks at the 57th ASEAN Foreign Ministers' Meeting at the National Convention Center, in Vientiane, Laos, July 27, 2024. (Reuters)
US Secretary of State Antony Blinken speaks at the 57th ASEAN Foreign Ministers' Meeting at the National Convention Center, in Vientiane, Laos, July 27, 2024. (Reuters)

US Secretary of State Antony Blinken met his Chinese counterpart Wang Yi on Saturday during a regional summit in Laos, hours after criticizing Beijing's "escalating and unlawful actions" in the South China Sea.

Blinken and Wang shook hands and exchanged greetings in front of cameras but made no comments before moving to closed-door talks in what will be their sixth meeting since June 23, when Blinken visited Beijing in a significant sign of improvement for strained relations between the world's two biggest economies.

Though Blinken had singled out China over its actions against US defense ally the Philippines in the South China Sea during a meeting with Southeast Asian counterparts earlier on Saturday, he also lauded the two countries for their diplomacy after Manila completed a resupply mission to troops in an area also claimed by Beijing.

The troop presence has for years angered China, which has clashed repeatedly with the Philippines over Manila's missions to a grounded navy ship at the Second Thomas Shoal, causing regional concern about an escalation.

The two sides this week reached an arrangement over how to conduct those missions.

"We are pleased to take note of the successful resupply today of the Second Thomas shoal, which is the product of an agreement reached between the Philippines and China," Blinken told ASEAN foreign ministers.

"We applaud that and hope and expect to see that it continues going forward."

GAZA SITUATION 'DIRE'

Blinken and Wang attended Saturday's security-focused ASEAN Regional Forum in Laos alongside top diplomats of major powers including Russia, India, Australia, Japan, the European, Britain and others, before heading to their meeting.

Blinken said earlier the United States was "working intensely every single day" to achieve a ceasefire in Gaza and find a path to more enduring peace and security.

His remarks follow those of Indonesian Foreign Minister Retno Marsudi, who said the need for sustainable peace was urgent and international law should be applied to all. The comment from the world's largest Muslim-majority nation, was a veiled reference to recent decisions by two international courts over Israeli's Gaza offensives.

"We cannot continue closing our eyes to see the dire humanitarian situation in Gaza," she said.

More than 39,000 Palestinians have been killed in the fighting in Gaza since Israel launched its incursion, according to Palestinian health authorities, who do not distinguish between fighters and non-combatants.

Israeli officials estimate that some 14,000 fighters from armed groups including Hamas and Islamic Jihad, have been killed or taken prisoner, out of a force they estimated to number more than 25,000 at the start of the war.

The war began when Hamas fighters attacked Israel on Oct. 7, killing 1,200 people and abducting some 250 others, according to Israeli tallies.

Also in Laos, Russia's Foreign Minister Sergei Lavrov said guidelines on the operation of US nuclear assets on the Korean peninsula were certain to add to regional security concerns.

Lavrov, according to South Korean news agency Yonhap, said he had not been briefed on the details of the plan, which was of concern to Russia.

"So far we can't even get an explanation of what this means, but there is no doubt that it causes additional anxiety," Russia's state-run RIA new agency quoted him as saying.

'THIS IS NOT SUSTAINABLE'

Ahead of Saturday's two summits, Australian Foreign Minister Penny Wong urged Myanmar's military rulers to take a different path and end an intensifying civil war, pressing the generals to abide by their commitment to follow ASEAN's five-point consensus peace plan.

The conflict pits Myanmar's well-equipped military against a loose alliance of ethnic minority rebel groups and an armed resistance movement that has been gaining ground and testing the generals' ability to govern.

The junta has largely ignored the ASEAN-promoted peace effort, and the 10-member bloc has hit a wall as all sides refuse to enter into dialogue.

"We see the instability, the insecurity, the deaths, the pain that is being caused by the conflict," Wong told reporters.

"My message from Australia to the regime is, this is not sustainable for you or for your people."

An estimated 2.6 million people have been displaced by fighting. The junta has been condemned for excessive force in its air strikes on civilian areas and accused of atrocities, which it has dismissed as Western disinformation.

ASEAN issued a communique on Saturday, two days after its top diplomats met, stressing it was united behind its peace plan for Myanmar, saying it was confident in its special envoy's resolve to achieve "an inclusive and durable peaceful resolution" to the conflict.

It condemned violence against civilians and urged all sides in Myanmar to cease hostilities.

ASEAN welcomed unspecified practical measures to reduce tension in the South China Sea and prevent accidents and miscalculations, while urging all stakeholders to halt actions that could complicate and escalate disputes.

The ministers described North Korea's missile tests as worrisome developments and urged peaceful resolutions to the conflicts in Ukraine, as well as Gaza, expressing concern over the dire humanitarian situation and "alarming casualties" there.