Berliner Boersenzeitung - US, Microsoft warn Chinese hackers attacking 'critical' infrastructure 

EUR -
AED 4.048549
AFN 75.807487
ALL 98.742523
AMD 426.921756
ANG 1.988036
AOA 1020.683844
ARS 1071.111419
AUD 1.61163
AWG 1.98405
AZN 1.87367
BAM 1.953638
BBD 2.227256
BDT 131.814134
BGN 1.955172
BHD 0.415572
BIF 3200.1458
BMD 1.10225
BND 1.430656
BOB 7.622461
BRL 6.037683
BSD 1.103089
BTN 92.603564
BWP 14.591118
BYN 3.609938
BYR 21604.10478
BZD 2.22346
CAD 1.494833
CDF 3163.457983
CHF 0.939553
CLF 0.036463
CLP 1006.124001
CNY 7.769873
CNH 7.784168
COP 4614.967456
CRC 571.872351
CUC 1.10225
CUP 29.209631
CVE 110.141618
CZK 25.36157
DJF 196.434407
DKK 7.459291
DOP 66.327204
DZD 146.510747
EGP 53.292257
ERN 16.533754
ETB 133.306991
FJD 2.427925
FKP 0.839429
GBP 0.837876
GEL 3.009035
GGP 0.839429
GHS 17.472427
GIP 0.839429
GMD 76.055118
GNF 9523.547591
GTQ 8.532442
GYD 230.771487
HKD 8.559717
HNL 27.521794
HRK 7.494212
HTG 145.551573
HUF 401.715376
IDR 17106.923785
ILS 4.209571
IMP 0.839429
INR 92.544986
IQD 1445.000954
IRR 46390.949806
ISK 149.300013
JEP 0.839429
JMD 174.128888
JOD 0.78106
JPY 161.337452
KES 142.190275
KGS 93.096332
KHR 4477.08625
KMF 492.136649
KPW 992.024595
KRW 1476.871593
KWD 0.337245
KYD 0.919283
KZT 532.440798
LAK 24357.04636
LBP 98780.485148
LKR 324.191248
LRD 220.612866
LSL 19.287756
LTL 3.254659
LVL 0.66674
LYD 5.245243
MAD 10.775429
MDL 19.303813
MGA 5005.551653
MKD 61.61725
MMK 3580.065796
MNT 3745.446279
MOP 8.824735
MRU 43.577173
MUR 51.243893
MVR 16.930703
MWK 1912.718081
MXN 21.372798
MYR 4.649297
MZN 70.406232
NAD 19.287756
NGN 1827.078732
NIO 40.596181
NOK 11.693585
NPR 148.169379
NZD 1.777472
OMR 0.424406
PAB 1.103079
PEN 4.108953
PGK 4.39122
PHP 62.138225
PKR 306.272035
PLN 4.31311
PYG 8600.5606
QAR 4.020596
RON 4.976992
RSD 117.023758
RUB 104.602115
RWF 1494.573216
SAR 4.139507
SBD 9.193632
SCR 15.013437
SDG 663.023658
SEK 11.348779
SGD 1.429176
SHP 0.839429
SLE 25.183445
SLL 23113.630821
SOS 630.408106
SRD 33.955363
STD 22814.354614
SVC 9.652319
SYP 2769.436735
SZL 19.279016
THB 36.407268
TJS 11.736453
TMT 3.857876
TND 3.378715
TOP 2.581577
TRY 37.757968
TTD 7.481721
TWD 35.333511
TZS 3005.425288
UAH 45.430651
UGX 4040.473805
USD 1.10225
UYU 46.208237
UZS 14072.427375
VEF 3992959.414523
VES 40.716573
VND 27305.494166
VUV 130.861363
WST 3.083504
XAF 655.243793
XAG 0.034423
XAU 0.000414
XCD 2.978887
XDR 0.814114
XOF 655.237855
XPF 119.331742
YER 275.94847
ZAR 19.258461
ZMK 9921.571006
ZMW 29.094068
ZWL 354.924129
  • CMSC

    -0.0400

    24.74

    -0.16%

  • RBGPF

    58.9300

    58.93

    +100%

  • SCS

    -0.2500

    12.62

    -1.98%

  • AZN

    -1.6500

    77.93

    -2.12%

  • NGG

    -1.8100

    66.97

    -2.7%

  • GSK

    -1.0800

    38.37

    -2.81%

  • CMSD

    -0.0400

    24.89

    -0.16%

  • RELX

    -0.6800

    46.61

    -1.46%

  • RYCEF

    0.0800

    6.98

    +1.15%

  • RIO

    -0.9900

    69.83

    -1.42%

  • BTI

    -0.8600

    35.11

    -2.45%

  • BCC

    -1.2400

    138.29

    -0.9%

  • BCE

    -0.6000

    33.84

    -1.77%

  • JRI

    -0.0800

    13.3

    -0.6%

  • BP

    0.0900

    32.46

    +0.28%

  • VOD

    -0.0500

    9.69

    -0.52%

US, Microsoft warn Chinese hackers attacking 'critical' infrastructure 
US, Microsoft warn Chinese hackers attacking 'critical' infrastructure  / Photo: Josep LAGO - AFP/File

US, Microsoft warn Chinese hackers attacking 'critical' infrastructure 

State-sponsored Chinese hackers have infiltrated critical US infrastructure networks, the United States, its Western allies and Microsoft said Wednesday while warning that similar espionage attacks could be occurring globally.

Text size:

Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets, but said "malicious" activity had also been detected elsewhere in the United States.

It said the hacking, dubbed "Volt Typhoon", had started in mid-2021 and was likely aimed at hampering the United States if there was conflict in the region.

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the statement said.

"In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors.

"Observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible."

Microsoft's statement coincided with an advisory released by US, Australian, Canadian, New Zealand and UK authorities.

They said a "state-sponsored cyber actor" from China was behind Volt Typhoon and that the hacking was likely occurring globally.

"This activity affects networks across US critical infrastructure sectors, and the authoring agencies believe the actor could apply the same techniques against these and other sectors worldwide," the advisory said.

The United States and its allies said the activities involved "living off the land" tactics, which take advantage of built-in network tools to blend in with normal Windows systems.

It warned that the hacking could then incorporate legitimate system administration commands that appear "benign".

-'Highly sophisticated'-

Microsoft said Volt Typhoon tried to blend into normal network activity by routing traffic through compromised small office and home office network equipment, including routers, firewalls and VPN hardware.

"They have also been observed using custom versions of open-source tools," Microsoft said.

Microsoft and the security agencies released guidelines for organisations to try and detect and counter the hacking.

The director of the US Cybersecurity and Infrastructure Security Agency, Jen Easterly, also released a warning related to Volt Typhoon.

"For years, China has conducted operations worldwide to steal intellectual property and sensitive data from critical infrastructure organizations around the globe," Easterly said.

"Today's advisory, put out in conjunction with our US and international partners, reflects how China is using highly sophisticated means to target our nation's critical infrastructure.

"This joint advisory will give network defenders more insights into how to detect and mitigate this malicious activity."

China offered no immediate response to the allegations. But it routinely denies carrying out state-sponsored cyber attacks.

China in turn regularly accuses the United States of cyber espionage.

While China and Russia have long targeted critical infrastructure, Volt Typhoon offered new insights into Chinese hacking, according to John Hultquist, chief analyst at US cybersecurity company Mandiant.

"Chinese cyberthreat actors are unique among their peers in that they have not regularly resorted to destructive and disruptive cyberattacks," he said.

"As a result, their capability is quite opaque.This disclosure is a rare opportunity to investigate and prepare for this threat."

(A.Lehmann--BBZ)