US authorities have uncovered a large-scale Chinese hackers’ espionage campaign.
The hackers breached the networks of many federal agencies, including NASA, the Federal Reserve System, the Department of Justice, the Department of Energy and the US Senate, CNN reports.
According to the US Department of Justice, the hackers—linked to China’s military and intelligence services—also targeted military networks, hospitals, energy companies and defence contractors. To cover their tracks, gain access to internal systems and increase the effectiveness of their attacks, the hackers used the Chinese technology company Nanjing Xinjiuwei Network Technology Company.
To stop the ongoing threat, the US Department of Justice seized three internet domains linked to the firm. In addition, federal agencies plan to publish guidance describing the hackers’ methods so that other affected companies can identify and remove the intruders from their systems.
The precise consequences of this espionage operation remain unknown. For security reasons, US counterintelligence assessments of the damage are unlikely to be made public.
The US side believes this is another escalation in a long-running series of Chinese cyberattacks on key elements of US infrastructure, such as power stations and banks.
According to the investigation, the FBI and the US National Security Agency spent months unpicking a high-tech concealment scheme. The hackers used the services of a private Chinese firm to blend in with ordinary internet traffic and hide their actions by posing as regular users. Specialists at the US company Lumen Technologies noted that using such a commercial firm helped the spies stay hidden, but also left a digital trail that enabled investigators to expose the operation.
- The day before, Politico reported that a July EU cyber-defence report revealed how foreign states hire hackers to attack senior EU officials on messaging apps.
- To break in, the hackers used targeted phishing and social engineering. They sent senior officials personalised messages containing malicious links or files, and also posed as Signal support in order to trick them into handing over access codes and to read private and group chats.