Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel
TT

Chinese Hackers Spying on US Critical Infrastructure, Western Intelligence Says

REUTERS/Kacper Pempel
REUTERS/Kacper Pempel

A state-sponsored Chinese hacking group has been spying on a wide range of US critical infrastructure organizations, from telecommunications to transportation hubs, Western intelligence agencies and Microsoft said on Wednesday.

The espionage has also targeted the US island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that "mitigating this attack could be challenging."

While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure, Reuters said.

The Chinese embassy in Washington did not immediately respond to a Reuters request for comment.

It was not immediately clear how many organizations were affected, but the US National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the US Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the hackers too.

Microsoft analysts said they had "moderate confidence" this Chinese group, which it dubbed as 'Volt Typhoon', was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

"It means they are preparing for that possibility," added said John Hultquist, who heads threat analysis at Google's Mandiant Intelligence.

The Chinese activity is unique and worrying also because analysts don't yet have enough visibility on what this group might be capable of, he added.

"There is greater interest in this actor because of the geopolitical situation."

As China has stepped up military and diplomatic pressure in its claim to democratically governed Taiwan, US President Joe Biden has said he would be willing to use force to defend Taiwan.

Security analysts expect Chinese hackers could target US military networks and other critical infrastructure if China invades Taiwan.

The NSA and other Western cyber agencies urged companies that operate critical infrastructure to identify malicious activity using the technical guidance they issued.

"It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems," Paul Chichester, director at the UK's National Cyber Security Center said in a joint statement with the NSA.

Microsoft said the Chinese hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.

NSA cybersecurity director Rob Joyce said the Chinese campaign was using "built-in network tools to evade our defenses and leaving no trace behind." Such techniques are harder to detect as they use "capabilities already built into critical infrastructure environments," he added.

As opposed to using traditional hacking techniques, which often involve tricking a victim into downloading malicious files, Microsoft said this group infects a victim's existing systems to find information and extract data.

Guam is home to US military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.

Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam "a logical target for the Chinese government" to seek intelligence.

"There is high vulnerability when cables land on shore," he said.

New Zealand said it would work towards identifying any such malicious cyber activity in its country.

"It's important for the national security of our country that we're transparent and upfront with Australians about the threats that we face," Australia's Minister for Home Affairs and Cyber Security Clare O'Neil said.

Canada's cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. "However, Western economies are deeply interconnected," it added. "Much of our infrastructure is closely integrated and an attack on one can impact the other."



Typhoon Gaemi Weakens to Tropical Storm as It Moves Inland Carrying Rain toward Central China

 In this photo released by the Taiwan Ministry of National Defense, Taiwanese soldiers clear debris in the aftermath of Typhoon Gaemi in Kaohsiung county in southwestern Taiwan, Friday, July 26, 2024. (Taiwan Ministry of National Defense via AP)
In this photo released by the Taiwan Ministry of National Defense, Taiwanese soldiers clear debris in the aftermath of Typhoon Gaemi in Kaohsiung county in southwestern Taiwan, Friday, July 26, 2024. (Taiwan Ministry of National Defense via AP)
TT

Typhoon Gaemi Weakens to Tropical Storm as It Moves Inland Carrying Rain toward Central China

 In this photo released by the Taiwan Ministry of National Defense, Taiwanese soldiers clear debris in the aftermath of Typhoon Gaemi in Kaohsiung county in southwestern Taiwan, Friday, July 26, 2024. (Taiwan Ministry of National Defense via AP)
In this photo released by the Taiwan Ministry of National Defense, Taiwanese soldiers clear debris in the aftermath of Typhoon Gaemi in Kaohsiung county in southwestern Taiwan, Friday, July 26, 2024. (Taiwan Ministry of National Defense via AP)

Tropical storm Gaemi brought rain to central China on Saturday as it moved inland after making landfall at typhoon strength on the country's east coast Thursday night.

The storm felled trees, flooded streets and damaged crops in China but there were no reports of casualties or major damage. Eight people died in Taiwan, which Gaemi crossed at typhoon strength before heading over open waters to China.

The worst loss of life, however, was in a country that Gaemi earlier passed by but didn't strike directly: the Philippines. A steadily climbing death toll has reached 34, authorities there said Friday. The typhoon exacerbated seasonal monsoon rains in the Southeast Asian country, causing landslides and severe flooding that stranded people on rooftops as waters rose around them.

China Gaemi weakened to a tropical storm since coming ashore Thursday evening in coastal Fujian province, but it is still expected to bring heavy rains in the coming days as it moves northwest to Jiangxi, Hubei and Henan provinces.

About 85 hectares (210 acres) of crops were damaged in Fujian province and economic losses were estimated at 11.5 million yuan ($1.6 million), according to Chinese media reports. More than 290,000 people were relocated because of the storm.

Elsewhere in China, several days of heavy rains this week in Gansu province left one dead and three missing in the country's northwest, the official Xinhua News Agency said.

Taiwan Residents and business owners swept out mud and mopped up water Friday after serious flooding that sent cars and scooters floating down streets in parts of southern and central Taiwan. Some towns remained inundated with waist-deep water.

Eight people died, several of them struck by falling trees and one by a landslide hitting their house. More than 850 people were injured and one person was missing, the emergency operations center said.

Visiting hard-hit Kaohsiung in the south Friday, President Lai Ching-te commended the city's efforts to improve flood control since a 2009 typhoon that brought a similar amount of rain and killed 681 people, Taiwan's Central News Agency reported.

Lai announced that cash payments of $20,000 New Taiwan Dollars ($610) would be given to households in severely flooded areas.

A cargo ship sank off the coast near Kaohsiung Harbor during the typhoon, and the captain's body was later pulled from the water, the Central News Agency said. A handful of other ships were beached by the storm.

Philippines At least 34 people died in the Philippines, mostly because of flooding and landslides triggered by days of monsoon rains that intensified when the typhoon — called Carina in the Philippines — passed by the archipelago’s east coast.

The victims included 11 people in the Manila metro area, where widespread flooding trapped people on the roofs and upper floors of their houses, police said. Some drowned or were electrocuted in their flooded communities.

Earlier in the week, Philippine President Ferdinand Marcos Jr. ordered authorities to speed up efforts in delivering food and other aid to isolated rural villages, saying people may not have eaten for days.

The bodies of a pregnant woman and three children were dug out Wednesday after a landslide buried a shanty in the rural mountainside town of Agoncillo in Batangas province.