State-sponsored Chinese hackers have infiltrated critical US infrastructure networks, the US, its Western allies and Microsoft said on Wednesday, adding that similar espionage attacks could be occurring globally.
Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets, but said “malicious” activity had also been detected elsewhere in the US.
The stealthy attack — carried out by a China-sponsored actor dubbed “Volt Typhoon” since mid-2021 — enabled long-term espionage and was likely aimed at hampering the US if there was conflict in the region, it said.
Photo: AP
“Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises,” the statement said.
“In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology and education sectors,” it said.
Microsoft’s statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities.
They said a “state-sponsored cyber actor” from China was behind Volt Typhoon, and that the hacking was likely occurring globally.
“This activity affects networks across US critical infrastructure sectors, and the authoring agencies believe the actor could apply the same techniques against these and other sectors worldwide,” the advisory said.
The US and its allies said the activities involved “living off the land” tactics, which take advantage of built-in network tools to blend in with normal Windows systems.
It warned that the hacking could incorporate legitimate system administration commands that appear “benign.”
Volt Typhoon tried to blend into normal network activity by routing traffic through compromised small office and home office network equipment, including routers, firewalls and virtual private network hardware, Microsoft said.
“They have also been observed using custom versions of open-source tools,” Microsoft said.
Microsoft and the security agencies released guidelines for organizations to detect and counter the hacking.
“It’s what I would term a low and slow cyberactivity,” said Alastair McGibbon, chief strategy officer at Australia’s CyberCX and a former head of the Australian Cyber Security Centre.
“When you think about something that can really cause catastrophic harm, it is someone with intent who takes time to get into systems,” he said.
Once inside, the cyberattackers can steal information, he said.
While China and Russia have long targeted critical infrastructure, Volt Typhoon offered new insights into Chinese hacking, said John Hultquist, chief analyst at US cybersecurity company Mandiant.
“Chinese cyberthreat actors are unique among their peers in that they have not regularly resorted to destructive and disruptive cyberattacks,” he said.
“As a result, their capability is quite opaque. This disclosure is a rare opportunity to investigate and prepare for this threat,” he said.
‘CORRECT IDENTIFICATION’: Beginning in May, Taiwanese married to Japanese can register their home country as Taiwan in their spouse’s family record, ‘Nikkei Asia’ said The government yesterday thanked Japan for revising rules that would allow Taiwanese nationals married to Japanese citizens to list their home country as “Taiwan” in the official family record database. At present, Taiwanese have to select “China.” Minister of Foreign Affairs Lin Chia-lung (林佳龍) said the new rule, set to be implemented in May, would now “correctly” identify Taiwanese in Japan and help protect their rights, the Ministry of Foreign Affairs said in a statement. The statement was released after Nikkei Asia reported the new policy earlier yesterday. The name and nationality of a non-Japanese person marrying a Japanese national is added to the
AT RISK: The council reiterated that people should seriously consider the necessity of visiting China, after Beijing passed 22 guidelines to punish ‘die-hard’ separatists The Mainland Affairs Council (MAC) has since Jan. 1 last year received 65 petitions regarding Taiwanese who were interrogated or detained in China, MAC Minister Chiu Chui-cheng (邱垂正) said yesterday. Fifty-two either went missing or had their personal freedoms restricted, with some put in criminal detention, while 13 were interrogated and temporarily detained, he said in a radio interview. On June 21 last year, China announced 22 guidelines to punish “die-hard Taiwanese independence separatists,” allowing Chinese courts to try people in absentia. The guidelines are uncivilized and inhumane, allowing Beijing to seize assets and issue the death penalty, with no regard for potential
‘UNITED FRONT’ FRONTS: Barring contact with Huaqiao and Jinan universities is needed to stop China targeting Taiwanese students, the education minister said Taiwan has blacklisted two Chinese universities from conducting academic exchange programs in the nation after reports that the institutes are arms of Beijing’s United Front Work Department, Minister of Education Cheng Ying-yao (鄭英耀) said in an exclusive interview with the Chinese-language Liberty Times (the Taipei Times’ sister paper) published yesterday. China’s Huaqiao University in Xiamen and Quanzhou, as well as Jinan University in Guangzhou, which have 600 and 1,500 Taiwanese on their rolls respectively, are under direct control of the Chinese government’s political warfare branch, Cheng said, citing reports by national security officials. A comprehensive ban on Taiwanese institutions collaborating or
STILL COMMITTED: The US opposes any forced change to the ‘status quo’ in the Strait, but also does not seek conflict, US Secretary of State Marco Rubio said US President Donald Trump’s administration released US$5.3 billion in previously frozen foreign aid, including US$870 million in security exemptions for programs in Taiwan, a list of exemptions reviewed by Reuters showed. Trump ordered a 90-day pause on foreign aid shortly after taking office on Jan. 20, halting funding for everything from programs that fight starvation and deadly diseases to providing shelters for millions of displaced people across the globe. US Secretary of State Marco Rubio, who has said that all foreign assistance must align with Trump’s “America First” priorities, issued waivers late last month on military aid to Israel and Egypt, the