World

Chinese cyber spies on US hacking spree: report

30,000 organisations, including local govts, hacked in recent days

Updated 5 years ago · Published on 06 Mar 2021 5:00PM

Chinese cyber spies on US hacking spree: report
Microsoft says the China hacking group, which it has named ‘Hafnium’, is a ‘highly skilled and sophisticated actor’. – The Vibes file pic, March 6, 2021

SAN FRANCISCO – At least 30,000 US organisations including local governments have been hacked in recent days by an “unusually aggressive” Chinese cyber-espionage campaign, according to a computer security specialist.

The campaign has exploited recently discovered flaws in Microsoft Exchange software, stealing email and infecting computer servers with tools that let attackers take control remotely, Brian Krebs said in a post at his cybersecurity news website.

“This is an active threat,” White House spokesman Jennifer Psaki said when asked about the situation during a press briefing.

“Everyone running these servers needs to act now to patch them. We are concerned that there are a large number of victims,” she added.

After Microsoft released patches for the vulnerabilities on Tuesday, attacks “dramatically stepped up” on servers not yet updated with security fixes, said Krebs, who cited unnamed sources familiar with the situation.

“At least 30,000 organisations across the United States – including a significant number of small businesses, towns, cities and local governments – have over the past few days been hacked by an unusually aggressive Chinese cyber-espionage unit that’s focused on stealing email from victim organisations,” Krebs wrote in the post.

He reported that insiders said hackers have “seized control” of thousands of computer systems around the world using password-protected software tools slipped into systems.

Microsoft said early this week that a state-sponsored hacking group operating out of China is exploiting previously unknown security flaws in its Exchange email services to steal data from business users.

The company said the hacking group, which it has named “Hafnium”, is a “highly skilled and sophisticated actor”.

Hafnium has in the past targeted US-based companies, including infectious disease researchers, law firms, universities, defence contractors, think-tanks, and NGOs.

In a blog post on Tuesday, Microsoft executive Tom Burt said the company had released updates to fix the security flaws, which apply to on-premises versions of the software rather than cloud-based versions, and urged customers to apply them.

“We know that many nation-state actors and criminal groups will move quickly to take advantage of any unpatched systems,” he added at the time.

Microsoft said the group was based in China but operated through leased virtual private servers in the United States, and that it had briefed the US government. 

Beijing has previously hit back at US accusations of state-sponsored cyber theft. Last year, it accused Washington of smears following allegations that Chinese hackers were attempting to steal coronavirus research.

In January, US intelligence and law enforcement agencies said Russia was probably behind the massive SolarWinds hack that shook the government and corporate security, contradicting then-president Donald Trump, who had suggested China could be to blame.

Microsoft said Tuesday the Hafnium attacks “were in no way connected to the separate SolarWinds-related attacks”. – AFP, March 6, 2021

Related News

Malaysia / 2w

PM Anwar loses beloved elder brother; Idrus Ibrahim passes away

Malaysia / 2w

Anwar asks Loke to reconsider resignation over Najib pardon

Opinion / 1mth

Foreign influence, covert activities within Malaysian politics and society

Malaysia / 1mth

Jokowi calls on global institutions to meet  needs growing, interconnected world

Malaysia / 1mth

Billionaire numbers reach record high as wealth remains concentrated

Malaysia / 1mth

Anwar backs One China policy, says Beijing can pursue reunification

Spotlight

Malaysia

JPJ temporarily suspends VTA and registration for Chery Omoda 5

Malaysia

Eligibility for PTPTN repayment deferment to be verified with LHDN

Malaysia

Budget allocates two rounds of cash aid to millions of Malaysians in 70th Merdeka year

Malaysia

No Malaysians killed or injured in Riyadh airport attack, says Wisma Putra

Malaysia

JAIS probes viral religious ritual footage, says AI manipulation not ruled out

Malaysia

10-tonne truck ploughs into 11 vehicles: Police probe possible brake failure

World

Trump weighs joining Saudi strikes after deadly Houthi attack on Riyadh airport

You may be interested

World

Trump lifts sanctions on Russian diesel as US fuel prices soar ahead of midterms

World

Anak Krakatau raised to second-highest alert after 13 eruptions

World

Man dies after entering tiger enclosure at UK wildlife park

World

Trump calls for Zelenskiy’s removal after deadly Russian strike kills 20 in Ukraine

World

Trump attacks Norway after Nobel Peace Prize goes to Navi Pillay

World

Gaza ceasefire leaves 2.1 million Palestinians squeezed into 35% of territory as attacks continue

World

Trump weighs joining Saudi strikes after deadly Houthi attack on Riyadh airport

World

India releases youth protest leaders after detention as voter-list row deepens