Showing posts with label Chinese hackers. Show all posts
Showing posts with label Chinese hackers. Show all posts

Tuesday, February 6, 2024

China's Hackers Have Entire Nation In Their Crosshairs, FBI Director Warns

 The FBI released the below:

Chinese government hacking efforts now target the entire American populace, and the escalating urgency of the overall threat that China poses to U.S. national security requires more investment in the FBI’s capabilities, FBI Director Wray warned lawmakers during a January 31 appearance before the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party. 

“I do not want those watching today to think we can’t protect ourselves,” he told legislators. “But I do want the American people to know that we cannot afford to sleep on this danger.” 

China’s quest to steal American intellectual property to gain an economic and militaristic edge over the United States—through nefarious cyber means and traditional espionage, alike—hasn’t let up. But the scope of its malicious cyber activities has expanded to target our nation’s critical infrastructure, Wray told lawmakers during the hearing, which looked to gauge the risks that CCP cyber efforts poses to U.S. national security. 

“There has been far too little public focus on the fact that PRC [People’s Republic of China] hackers are targeting our critical infrastructure—our water treatment plants, our electrical grid, our oil and natural gas pipelines, our transportation systems,” Wray told the committee during his opening remarks. “And the risk that poses to every American requires our attention now.” 

China's state-sponsored hackers are posturing themselves to be able to take down these vital resources at a moment’s notice. That way, if conflict breaks out between the U.S. and China, they can cripple those resources and do direct harm to U.S. citizens, Wray explained. “Low blows against civilians are part of China’s plan,” he said. 

And, Wray stressed, this threat isn’t theoretical. On January 31, it was announced that the Bureau had worked with partners to identify Wi-Fi routers that had been infected with malware originating from a Chinese government-sponsored hacking group. 

“The Volt Typhoon malware enabled China to hide, among other things, pre-operational reconnaissance and network exploitation against critical infrastructure like our communications, energy, transportation, and water sectors—steps China was taking, in other words, to find and prepare to destroy or degrade the civilian critical infrastructure that keeps us safe and prosperous,” Wray said. “So working with our partners, the FBI ran a court-authorized, on-network operation to shut down Volt Typhoon and the access it enabled.” 

This disruption was significant, but it’s not the end of the story when it comes to countering malicious cyber efforts by the Chinese government.  

The FBI is leveraging its expertise in the areas of cybersecurity, criminal investigation, and weapons of mass destruction, as well as private and public sector partnerships and relationships with international allies to tackle this multifaceted threat, he said. And investment is central to sustaining our battle rhythm against this threat. 

The President’s Fiscal Year 2024 Budget Request would help the FBI bolster its 56 field offices’ ability to investigate cyber threats, Wray’s written testimony to the committee stated

“The Fiscal Year 2024 Budget Request includes an additional $63 million for more agents, enhanced response capabilities, and strengthened intelligence collection and analysis capabilities,” he wrote. “These investments reflect the National Cybersecurity Strategy’s emphasis on a whole-of-nation approach to addressing the ongoing cyber threat.” 
Cuts to the Bureau’s budget would hinder the FBI computer intrusion program’s ability to combat CCP threats to U.S. economic and national security “before they can do significant harm,” the written testimony noted. 

“The budgets that emerge from the discussions underway now will dictate what kind of resources we have ready in 2027—a year that, as this committee knows all too well, the CCP has circled on its calendar,” Wray told the committee. 

Wray testified beside witnesses from across the U.S. government’s highest levels of cyber leadership at the hearing about CCP threats to American cybersecurity. Fellow panelists included National Security Agency Director Gen. Paul M. Nakasone (who appeared in his capacity as commander of U.S. Cyber Command); Cybersecurity and Infrastructure Security Agency Director Jen Easterly; and Harry Coker, Jr., who leads the Office of the National Cyber Director. 

“The Select Committee on the Chinese Communist Party is committed to working on a bipartisan basis to build consensus on the threat posed by the Chinese Communist Party and develop a plan of action to defend the American people, our economy, and our values,” the committee’s website states

Thursday, December 20, 2018

Two Chinese Hackers Associated With The Ministry Of State Security Charged With Global Computer Intrusion Campaigns Targeting Intellectual Property And Confidential Business Information


The Justice Department released the below information:
The unsealing of an indictment charging Zhu Hua (), aka Afwar, aka CVNX, aka Alayos, aka Godkiller; and Zhang Shilong (张士龙), aka Baobeilong, aka Zhang Jianguo, aka Atreexp, both nationals of the People’s Republic of China (China), with conspiracy to commit computer intrusions, conspiracy to commit wire fraud, and aggravated identity theft was announced today.
The announcement was made by Deputy Attorney General Rod J. Rosenstein, U.S. Attorney Geoffrey S. Berman for the Southern District of New York, Director Christopher A. Wray of the FBI, Director Dermot F. O’Reilly of the Defense Criminal Investigative Service (DCIS) of the U.S. Department of Defense, and Assistant Attorney General for National Security John C. Demers.
Zhu and Zhang were members of a hacking group operating in China known within the cyber security community as Advanced Persistent Threat 10 (the APT10 Group).  The defendants worked for a company in China called Huaying Haitai Science and Technology Development Company (Huaying Haitai) and acted in association with the Chinese Ministry of State Security’s Tianjin State Security Bureau. 
Through their involvement with the APT10 Group, from at least in or about 2006 up to and including in or about 2018, Zhu and Zhang conducted global campaigns of computer intrusions targeting, among other data, intellectual property and confidential business and technological information at managed service providers (MSPs), which are companies that remotely manage the information technology infrastructure of businesses and governments around the world, more than 45 technology companies in at least a dozen U.S. states, and U.S. government agencies.  The APT10 Group targeted a diverse array of commercial activity, industries and technologies, including aviation, satellite and maritime technology, industrial factory automation, automotive supplies, laboratory instruments, banking and finance, telecommunications and consumer electronics, computer processor technology, information technology services, packaging, consulting, medical equipment, healthcare, biotechnology, pharmaceutical manufacturing, mining, and oil and gas exploration and production.  Among other things, Zhu and Zhang registered IT infrastructure that the APT10 Group used for its intrusions and engaged in illegal hacking operations.
“The indictment alleges that the defendants were part of a group that hacked computers in at least a dozen countries and gave China’s intelligence service access to sensitive business information,” said Deputy Attorney General Rosenstein.  “This is outright cheating and theft, and it gives China an unfair advantage at the expense of law-abiding businesses and countries that follow the international rules in return for the privilege of participating in the global economic system.”
“It is galling that American companies and government agencies spent years of research and countless dollars to develop their intellectual property, while the defendants simply stole it and got it for free” said U.S. Attorney Berman.  “As a nation, we cannot, and will not, allow such brazen thievery to go unchecked.”
“Healthy competition is good for the global economy, but criminal conduct is not.  This is conduct that hurts American businesses, American jobs, and American consumers,” said FBI Director Wray.  “No country should be able to flout the rule of law – so we’re going to keep calling out this behavior for what it is: illegal, unethical, and unfair.  It's going to take all of us working together to protect our economic security and our way of life, because the American people deserve no less."
“The theft of sensitive defense technology and cyber intrusions are major national security concerns and top investigative priorities for the DCIS,” said DCIS Director O’Reilly.  “The indictments unsealed today are the direct result of a joint investigative effort between DCIS and its law enforcement partners to vigorously investigate individuals and groups who illegally access information technology systems of the U.S. Department of Defense and the Defense Industrial Base.  DCIS remains vigilant in our efforts to safeguard the integrity of the Department of Defense and its enterprise of information technology systems.”
According to the allegations in the Indictment unsealed today in Manhattan federal court:
Overview
Zhu Hua (), aka Afwar, aka CVNX, aka Alayos, aka Godkiller, and Zhang Shilong (张士龙), aka Baobeilong, aka Zhang Jianguo, aka Atreexp, the defendants, both nationals of China, were members of a hacking group operating in China known within the cyber security community as the APT10 Group, or alternatively as “Red Apollo,” “CVNX,” “Stone Panda,” “MenuPass,” and “POTASSIUM.”  The defendants worked for Huaying Haitai in Tianjin, China, and acted in association with the Chinese Ministry of State Security’s Tianjin State Security Bureau.  From at least in or about 2006 up to and including in or about 2018, members of the APT10 Group, including Zhu and Zhang, conducted extensive campaigns of intrusions into computer systems around the world.  The APT10 Group used some of the same online facilities to initiate, facilitate and execute its campaigns during the conspiracy.
Most recently, beginning at least in or about 2014, members of the APT10 Group, including Zhu and Zhang, engaged in an intrusion campaign to obtain unauthorized access to the computers and computer networks of MSPs for businesses and governments around the world (the MSP Theft Campaign).  The APT10 Group targeted MSPs in order to leverage the MSPs’ networks to gain unauthorized access to the computers and computer networks of the MSPs’ clients and to steal, among other data, intellectual property and confidential business data on a global scale.  For example, through the MSP Theft Campaign, the APT10 Group obtained unauthorized access to the computers of an MSP that had offices in the Southern District of New York and compromised the data of that MSP and certain of its clients involved in banking and finance, telecommunications and consumer electronics, medical equipment, packaging, manufacturing, consulting, healthcare, biotechnology, automotive, oil and gas exploration, and mining.
Earlier, beginning in or about 2006, members of the APT10 Group, including Zhu and Zhang, engaged in an intrusion campaign to obtain unauthorized access to the computers and computer networks of more than 45 technology companies and U.S. government agencies, in order to steal information and data concerning a number of technologies (the Technology Theft Campaign).  Through the Technology Theft Campaign, the APT10 Group stole hundreds of gigabytes of sensitive data and targeted the computers of victim companies involved in aviation, space and satellite technology, manufacturing technology, pharmaceutical technology, oil and gas exploration and production technology, communications technology, computer processor technology, and maritime technology.
In furtherance of the APT10 Group’s intrusion campaigns, Zhu and Zhang, among other things, worked for Huaying Haitai and registered malicious domains and infrastructure.  In addition, Zhu, a penetration tester, engaged in hacking operations on behalf of the APT10 Group and recruited other individuals to the APT10 Group, and Zhang developed and tested malware for the APT10 Group.
The MSP Theft Campaign
In furtherance of the MSP Theft Campaign, Zhu, Zhang, and their co-conspirators in the APT10 Group engaged in the following criminal conduct:
  • First, after the APT10 Group gained unauthorized access into the computers of an MSP, the APT10 Group installed multiple variants of malware on MSP computers around the world. To avoid antivirus detection, the malware was installed using malicious files that masqueraded as legitimate files associated with the victim computer’s operating system.  Such malware enabled members of the APT10 Group to monitor victims’ computers remotely and steal user credentials. 
  • Second, after stealing administrative credentials from computers of an MSP, the APT10 Group used those stolen credentials to connect to other systems within an MSP and its clients’ networks. This enabled the APT10 Group to move laterally through an MSP’s network and its clients’ networks and to compromise victim computers that were not yet infected with malware. 
  • Third, after identifying data of interest on a compromised computer and packaging it for exfiltration using encrypted archives, the APT10 Group used stolen credentials to move the data of an MSP client to one or more other compromised computers of the MSP or its other clients’ networks before exfiltrating the data to other computers controlled by the APT10 Group.
Over the course of the MSP Theft Campaign, Zhu, Zhang, and their co-conspirators in the APT10 Group successfully obtained unauthorized access to computers providing services to or belonging to victim companies located in at least 12 countries, including Brazil, Canada, Finland, France, Germany, India, Japan, Sweden, Switzerland, the United Arab Emirates, the United Kingdom, and the United States.  The victim companies included at least the following:  a global financial institution, three telecommunications and/or consumer electronics companies; three companies involved in commercial or industrial manufacturing; two consulting companies; a healthcare company; a biotechnology company; a mining company; an automotive supplier company; and a drilling company. 
The Technology Theft Campaign
Over the course of the Technology Theft Campaign, which began in or about 2006, Zhu, Zhang, and their coconspirators in the APT10 Group successfully obtained unauthorized access to the computers of more than 45 technology companies and U.S. Government agencies based in at least 12 states, including Arizona, California, Connecticut, Florida, Maryland, New York, Ohio, Pennsylvania, Texas, Utah, Virginia and Wisconsin.  The APT10 Group stole hundreds of gigabytes of sensitive data and information from the victims’ computer systems, including from at least the following victims: seven companies involved in aviation, space and/or satellite technology; three companies involved in communications technology; three companies involved in manufacturing advanced electronic systems and/or laboratory analytical instruments; a company involved in maritime technology; a company involved in oil and gas drilling, production, and processing; and the NASA Goddard Space Center and Jet Propulsion Laboratory.  In addition to those victims who had information stolen, Zhu, Zhang, and their co-conspirators successfully obtained unauthorized access to computers belonging to more than 25 other technology-related companies involved in, among other things, industrial factory automation, radar technology, oil exploration, information technology services, pharmaceutical manufacturing, and computer processor technology, as well as the U.S. Department of Energy’s Lawrence Berkeley National Laboratory. 
Finally, the APT10 Group compromised more than 40 computers in order to steal sensitive data belonging to the Navy, including the names, Social Security numbers, dates of birth, salary information, personal phone numbers, and email addresses of more than 100,000 Navy personnel.
*                *                *
Zhu and Zhang are each charged with one count of conspiracy to commit computer intrusions, which carries a maximum sentence of five years in prison; one count of conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison; and one count of aggravated identity theft, which carries a mandatory sentence of two years in prison. 
The maximum potential sentences in this case are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendants will be determined by the assigned judge.  The charges contained in the Indictment are merely accusations and the defendants are presumed innocent unless and until proven guilty.
The case was investigated by the FBI, including the New Orleans, New Haven, Houston, New York, Sacramento, and San Antonio Field Offices; DCIS; and the U.S. Naval Criminal Investigative Service (NCIS).  Mr. Rosenstein, Mr. Berman and Mr. Demers praised the outstanding investigative work of, and collaboration among, the FBI, DCIS, and NCIS.  They also thanked the U.S. Attorney’s Office for the District of Connecticut, and the Department of Defense’s Computer Forensic Laboratory for their assistance in the investigation.
Assistant U.S. Attorney Sagar K. Ravi of the Southern District of New York’s Complex Frauds and Cybercrime Unit is in charge of the prosecution, with assistance provided by Trial Attorney Matthew Chang of the National Security Division’s Counterintelligence and Export Control Section.

Tuesday, January 6, 2015

National Oceanic And Atmospheric Administration Employee Charged With Computer Breach Met Senior Chinese Official In Beijing



Veteran national security reporter Bill Gertz at the freebeacon.com offers a piece on a National Oceanic and Atmospheric Administration employee charged with a computer security breach who met with a senior Communist Chinese official in China.

A federal weather service employee charged with stealing sensitive infrastructure data from an Army Corps of Engineers database met a Chinese government official in Beijing, according to court documents that reveal the case to be part of an FBI probe of Chinese economic espionage.

Xiafen “Sherry” Chen, an employee of the National Oceanic and Atmospheric Administration (NOAA) office in Ohio, was arrested in October and charged in a federal grand jury indictment with illegally accessing the Army’s National Inventory of Dams (NID).

The NID is a sensitive database containing information on all U.S. dams. U.S. intelligence officials have said the database was compromised by Chinese hackers in 2013 as part of covert efforts by Beijing to gather sensitive information on critical U.S. infrastructure for possible use in a future conflict.

According to an FBI document in the case made public Dec. 30, Ms. Chen and Jiao Yong, an official of the Ministry of Water Resources in Beijing, exchanged a series of emails in May 2012 indicating that the two met in Beijing that year and that she was searching for, and would provide, dam-related information for him.

You can read the rest of the piece via the below link:

http://freebeacon.com/national-security/noaa-employee-charged-with-computer-breach-met-senior-chinese-official-in-beijing/

You can also read the U.S. Justice Department's October 20, 2014 release on Chen's indictment below:

DAYTON, OHIO –  Xiafen “Sherry” Chen, 59, of Wilmington, Ohio, was indicted in U.S. District Court for allegedly accessing restricted U.S. Government files. Chen is a hydrologist currently employed at the National Oceanic and Atmospheric Administration’s (NOAA) facility located in Wilmington, Ohio.

Carter M. Stewart, United States Attorney for the Southern District of Ohio, Kevin R. Cornelius, Special Agent in Charge for the Federal Bureau of Investigation (FBI) in Cincinnati, Ohio, Dr. Kathryn Sullivan, the NOAA Administrator and George Lee, Special Agent in Charge of the U.S. Department of Commerce’s Investigations and Threat Management Division announced the indictment today. 

The indictment alleges that on various dates in May 2012, Chen illegally accessed restricted areas of a protected U.S. Government computer database and downloaded sensitive files from the National Inventory of Dams.  This database is maintained and controlled by the U.S. Army Corps of Engineers in conjunction with the National Dam Safety Review Board.

The indictment further alleges that on June 11, 2013, Chen provided materially false statements to officials from the Department of Commerce Office of Security who were assigned to investigate her activities. 

The indictment charges Chen with one count of theft of U.S. Government property, a crime punishable by up to 10 years in prison and a $250,000 fine; one count of illegally accessing a U.S. Government computer database, a crime punishable by up to 5 years in prison and a $250,000 fine; and two counts of making materially false statements to federal agents, crimes each punishable by up to 5 years in prison and a $250,000 fine. 

Chen was arrested today by FBI agents at her place of work at the Wilmington, Ohio NOAA facility.
U.S. Attorney Stewart commended FBI and the U.S. Department of Commerce’s Office of Security who are jointly investigating this case.  Assistant United States Attorney Dwight Keller is representing the government in this case.

An indictment merely contains allegations, and the defendant is presumed innocent unless proven guilty in a court of law.