Counterterrorism magazine published my piece on the American takedown of Russian and Chinese hackers.
You can read the pages above and below or the following text:
The U.S. intelligence community often warns Americans about foreign computer system hackers. Some of the hackers are criminals, corrupting computer systems for fun and profit, and some are state-sponsored hackers looking to undermine American government and business institutions.
Russia and China are the usual suspects when state-sponsored
computer intrusions are noted. Thankfully, the U.S. had some success in
thwarting them.
Back in April, the National Security Agency (NSA) and other
federal agencies co-sealed an FBI public service announcement, “Russian GRU
Exploiting Vulnerable Routers to Steal Sensitive Information.”
The public service announcement accompanied an announcement from U. S. Attorney
David Metcalf in Philadelphia, the Department of Justice, and the FBI that a
court-authorized technical operation to neutralize the U.S. portion of a
network of small office/home office (SOHO) routers compromised by a unit within
Russia’s Main Intelligence Directorate of the General Staff (GRU: Glavnoye
Razvedyvatelnoe Upravlenis) Military Unit 26165, also known as APT28,
Sofacy Group, Forest Blizzard, Pawn Storm, Fancy Bear, and Sednit.
The
GRU is the Russian military intelligence agency that operates worldwide
alongside the Russian foreign intelligence agency the SVR, which is essentially
the old First Main Directorate of the old KGB.
The
GRU, the military group that includes the Spetsnaz special operations forces
and the “wet work” unit that murdered a Russians defector with radiation
poisoned tea, also employs full-time hackers.
According
to Metcalf, the hacker unit used the routers to facilitate malicious Domain
Name System (DNS) hijacking operations against worldwide targets of
intelligence interest to the Russian government, including individuals in the
military, government, and critical infrastructure sectors.
“Since at least 2024, GRU actors have exploited known
vulnerabilities to steal credentials for thousands of TP-Link routers
worldwide. The actors then accessed many of these compromised routers without
authorization and manipulated their settings to redirect DNS requests to
GRU-controlled servers - i.e., malicious DNS resolvers. GRU actors were
indiscriminate in their initial targeting and manipulation of routers. The
actors then implemented an automated filtering process to determine which DNS
requests were of interest and warranted interception. For select targets, the
GRU’s DNS resolvers provided fraudulent DNS records for specific domains that
mimicked legitimate services — including Microsoft Outlook Web Access — to
facilitate Actor-in-the-Middle attacks against encrypted victim network
traffic. In doing so, the GRU actors harvested unencrypted passwords,
authentication tokens, emails, and other sensitive information from devices on
the same network as the compromised TP-Link routers,” the announcement stated.
“Russian military intelligence once again hijacked Americans’
hardware to commandeer critical data,” said Metcalf. “In the face of continued
aggression by our nation-state adversaries, the U.S. government will respond
just as aggressively. Working with the FBI — and our partners around the world
— we are committed to disrupting and exposing such threats to our nation’s
cybersecurity.”
Assistant Attorney General for National Security John A.
Eisenberg added. “The GRU’s predatory use of networks in American homes and
businesses for its malicious cyber operations remains a serious and persistent
threat,” said “NSD will continue to use every tool at our disposal to detect
such intrusions and expel hostile foreign actors from our Nation’s networks.”
“Operation Masquerade — led by FBI Boston — is the latest
example of how we’re defending our homeland from Russia’s GRU, which weaponized
routers owned by unsuspecting Americans in more than 23 states to steal
sensitive government, military, and critical infrastructure information,” said
Special Agent in Charge Ted E. Docks, of the FBI’s Boston Field Office. “The FBI
utilized cutting edge technology and leveraged our private sector and
international partners to unmask this malicious activity and remediate routers.
Now we’re asking everyone who has a router to secure it, update its firmware,
and replace it if needed. By working together, we can guard against nefarious
nation state actors trying to compromise our national security.”
“Operation Masquerade demonstrates the FBI’s commitment to
identifying, exposing, and disrupting the Russian government's efforts to
compromise American devices, steal sensitive information, and target critical
infrastructure,” said Assistant Director Brett Leatherman of FBI’s Cyber
Division. “GRU actors compromised routers in the US and around the world,
hijacking them to conduct espionage. Given the scale of this threat, sounding
the alarm wasn't enough. The FBI conducted a court-authorized operation to
harden compromised routers across the United States. We urge all router owners
to take the remediation steps outlined today, because defending our networks
requires all of us. The FBI will continue to use its authorities to identify
and impose costs on state-sponsored actors who target the American people.”
According to court documents unsealed in Philadelphia, the FBI
developed a series of commands to send to compromised routers in the United
States, designed to collect evidence regarding the GRU actors’ activity, reset
DNS settings (i.e., remove GRU DNS resolvers and force routers to obtain
legitimate DNS resolvers from their Internet Service Providers (ISPs)), and to
otherwise prevent the GRU actors from exploiting the original means of
unauthorized access.
As described in court documents, the government extensively
tested the operation on firmware and hardware for affected TP-Link routers.
Other than stymieing the GRU’s ability to access the routers, the operation did
not impact the routers’ normal functionality or collect the legitimate users’
content information.
The court-authorized steps to remediate compromised routers can
be reversed by legitimate users at any time through factory resets with
hardware reset buttons. Legitimate users can also reverse changes by logging
into web management pages and restoring desired settings (e.g., factory default
settings).
Another case in point is when the U.S. Justice Department released information on the extradition of a Chinese hacker on April 27th.
The
Justice Department announced that Xu Zewei, 34, of the People’s Republic of
China was extradited to the United States and appeared in U.S. District Court
in Houston on a nine-count indictment related to his involvement in
computer intrusions between February 2020 and June 2021.
Certain
of those computer intrusions allegedly are part of the HAFNIUM computer
intrusion campaign that compromised thousands of computers worldwide, including
in the United States. Other intrusions targeted U.S. COVID-19 research during
the height of the pandemic. Xu is charged along with Zhang Yu, 44, who is also
a PRC national.
According
to court documents, officers of the PRC’s Ministry of State Security’s (MSS)
Shanghai State Security Bureau (SSSB) directed Xu to conduct this hacking. The
MSS and SSSB are PRC intelligence services responsible for PRC’s domestic
counterintelligence, non-military foreign intelligence, and aspects of the
PRC’s political and domestic security. When Xu conducted the computer
intrusions, he allegedly worked for a company named Shanghai Powerock Network
Co. Ltd. (Powerock). Powerock was one of many “enabling” companies in the PRC
that conducted hacking for the PRC government.
“The
United States is committed to pursuing hackers who steal information from U.S.
businesses and universities and threaten our cybersecurity,” said Assistant
Attorney General Eisenberg. “I commend the prosecutors and investigators who
have worked hard and sought justice for years in this investigation, and we
look forward to proving our case in court.”
“Xu
Zewei will stand in a federal courtroom to answer for crimes that struck at the
heart of American science and security — allegedly stealing COVID-19 research
from our universities when the world needed it most,” said Acting U.S. Attorney
John G.E. Marck for the Southern District of Texas. “We have pursued this
moment across years and continents, and the message this office sends today is
the same one we sent when we first unsealed this indictment: we will work to
protect the American people.”
“The
extradition of Xu Zewei demonstrates the FBI's reach extends well beyond U.S.
borders,” said FBI Assistant Director Leatherman. “Xu will now answer for his
alleged role in HAFNIUM, a group responsible for a vast intrusion campaign
directed by China's Ministry of State Security that compromised more than
12,700 U.S. organizations. He is one of many contractors the Chinese government
uses to obscure its hand in cyber operations, and others who do the same face
the same risk. The FBI thanks our Italian law enforcement colleagues,
especially the Polizia Postale, whose partnership led to Xu's arrest in Milan
and his extradition to the United States.”
According
to court documents, in early 2020, Xu and his co-conspirators hacked and
otherwise targeted U.S.-based universities, immunologists, and virologists
conducting research into COVID‑19 vaccines, treatment, and testing. Xu and
others reported their activities to officers in the SSSB who were supervising
and directing the hacking activities. For example, on or about Feb. 19, 2020,
Xu provided an SSSB officer with confirmation that he had compromised the
network of a research university located in the Southern District of Texas.
On or
about Feb. 22, 2020, the SSSB officer directed Xu to target and access specific
email accounts (mailboxes) belonging to virologists and immunologists engaged
in COVID-19 research for the university. Xu later confirmed for the SSSB
officer that he acquired the contents of the researchers’ mailboxes.
The
charges further allege that beginning in late 2020, Xu and his co-conspirators
exploited certain vulnerabilities in Microsoft Exchange Server, a widely used
Microsoft product for sending, receiving, and storing email messages. Their
exploitation of Microsoft Exchange Server was at the forefront of a massive
campaign targeting thousands of computers worldwide and known publicly as
“HAFNIUM.” In March 2021, Microsoft publicly disclosed the intrusion campaign
by state-sponsored hackers operating out of China. Throughout March 2021,
Microsoft and other industry partners released detection tools, patches, and
other information to assist victim entities in identifying and mitigating
this cyber incident. Additionally, the FBI and the Cybersecurity and
Infrastructure Security Agency released a Joint Advisory on Compromise of
Microsoft Exchange Server on March 10, 2021. However, by the end of March 2021,
hundreds of web shells remained on certain U.S.-based computers running
Microsoft Exchange Server software.
In
April 2021, the Justice Department announced a court-authorized operation
to remediate hundreds of computers in the United States made vulnerable by
HAFNIUM actors. On July 21, 2021, the United States and foreign partners
attributed the HAFNIUM campaign to the PRC’s MSS.
Among
the victims of Xu’s alleged exploitation of Microsoft Exchange Server were
another university located in the Southern District of Texas and a law firm
with offices worldwide, including in Washington, D.C. After exploiting
computers running Microsoft Exchange Server, Xu and his co-conspirators
installed web shells on them to enable their remote administration. The
indictment alleges that these web shells were specific to HAFNIUM actors at the
time. As with the earlier COVID-19 research intrusions, Xu and Zhang worked
together on the HAFNIUM intrusions, under the supervision and direction of SSSB
officers. For example, on or about Jan. 30, 2021, Xu confirmed to Zhang that he
had compromised the other university’s network. Later, on or about Feb. 28,
2021, Xu updated a SSSB officer on his successful intrusions. This SSSB officer
then directed Xu to obtain a list of other, successful intrusions from a second
SSSB officer. Unauthorized access to the law firm’s network allowed Xu and his
co-conspirators to steal information from mailboxes and search them for
information regarding specific U.S. policy makers and government agencies.
Their search terms included “Chinese sources,” “MSS,” and “HongKong.”
As
described in the July 2025 announcement of charges against Xu, the PRC
uses an extensive network of private companies and contractors in China to hack
and steal information in a manner that obscured the PRC government’s
involvement. Operating from their safe haven and motivated by profit, this
network of private companies and contractors in China cast a wide net to
identify vulnerable computers, exploit those computers, and then identify
information that it could sell directly or indirectly to the PRC government.
This largely indiscriminate approach results in more victims in the United
States and elsewhere, more systems worldwide left vulnerable to future
exploitation by third parties, and more stolen information, often of no
interest to the PRC government and, therefore, sold to other third parties.
“Xu is
charged with conspiracy to commit wire fraud and two counts of wire fraud,
which carries a maximum penalty of 20 years in prison for each count;
conspiracy to cause damage to and obtain information by unauthorized access to
protected computers, to commit wire fraud, and to commit identity theft, which
carries a maximum penalty of five years in prison; two counts of obtaining
information by unauthorized access to protected computers, which carries a
maximum penalty of five years in prison; two counts of intentional damage to a
protected computer, which carries a maximum penalty of 10 years in prison; and
aggravated identity theft, which carries a maximum penalty of two years in
prison,” the Justice Department stated.
Zhang Yu, remains at large.
Paul Davis, a longtime contributor to the Journal, also writes the online Threatcon column.
No comments:
Post a Comment