State-sponsored Chinese hackers have infiltrated critical US infrastructure networks, the US, its Western allies and Microsoft said on Wednesday, adding that similar espionage attacks could be occurring globally.
Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets, but said “malicious” activity had also been detected elsewhere in the US.
The stealthy attack — carried out by a China-sponsored actor dubbed “Volt Typhoon” since mid-2021 — enabled long-term espionage and was likely aimed at hampering the US if there was conflict in the region, it said.
Photo: AP
“Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises,” the statement said.
“In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology and education sectors,” it said.
Microsoft’s statement coincided with an advisory released by US, Australian, Canadian, New Zealand and British authorities.
They said a “state-sponsored cyber actor” from China was behind Volt Typhoon, and that the hacking was likely occurring globally.
“This activity affects networks across US critical infrastructure sectors, and the authoring agencies believe the actor could apply the same techniques against these and other sectors worldwide,” the advisory said.
The US and its allies said the activities involved “living off the land” tactics, which take advantage of built-in network tools to blend in with normal Windows systems.
It warned that the hacking could incorporate legitimate system administration commands that appear “benign.”
Volt Typhoon tried to blend into normal network activity by routing traffic through compromised small office and home office network equipment, including routers, firewalls and virtual private network hardware, Microsoft said.
“They have also been observed using custom versions of open-source tools,” Microsoft said.
Microsoft and the security agencies released guidelines for organizations to detect and counter the hacking.
“It’s what I would term a low and slow cyberactivity,” said Alastair McGibbon, chief strategy officer at Australia’s CyberCX and a former head of the Australian Cyber Security Centre.
“When you think about something that can really cause catastrophic harm, it is someone with intent who takes time to get into systems,” he said.
Once inside, the cyberattackers can steal information, he said.
While China and Russia have long targeted critical infrastructure, Volt Typhoon offered new insights into Chinese hacking, said John Hultquist, chief analyst at US cybersecurity company Mandiant.
“Chinese cyberthreat actors are unique among their peers in that they have not regularly resorted to destructive and disruptive cyberattacks,” he said.
“As a result, their capability is quite opaque. This disclosure is a rare opportunity to investigate and prepare for this threat,” he said.
Taiwan last night blanked world No. 1 Japan 4-0 to win the World Baseball Softball Confederation’s (WBSC) Premier12 for the first time. Taiwanese ace Lin Yu-min (林昱珉) held defending champions Japan to just one hit and no runs in the first four innings, before catcher Lin Chia-cheng (林家正) opened the fifth inning with a solo home run. That was soon followed by a three-run homer from Taiwanese captain Chen Chieh-hsien (陳傑憲) to put Taiwan ahead in the prestigious tournament of the world’s top 12 baseball teams. In addition to a superb performance from 21-year-old Arizona Diamondbacks prospect Lin, three more Taiwanese pitchers
SUPPORT: Arms sales to NATO Plus countries such as Japan, South Korea and Israel only have to be approved by the US Congress if they exceed US$25m The US should amend a law to add Taiwan to the list of “NATO Plus” allies and streamline future arms sales, a US commission said on Tuesday in its annual report to the US Congress. The recommendation was made in the annual report by the US-China Economic and Security Review Commission (USCC), which contained chapters on US-China economic and trade ties, security relations, and Taiwan and Hong Kong. In the chapter on Taiwan, the commission urged the US Congress to “amend the Arms Export Control Act of 1976 to include Taiwan on the list of ‘NATO Plus’ recipients,” referring to
Taiwan yesterday advanced to the gold medal match of the World Baseball Softball Confederation’s (WBSC) Premier12 for the first time in history, despite last night losing 9-6 to Japan. Taiwan advanced after the US defeated Venezuela in the first game on the last day of the Super Round. However, the US had no chance of advancing to the championship game unless it defeated Venezuela by at least nine points. The US won 6-5. As a result, the two teams — who both had one win and two losses in the Super Round — are to face off again in the
Minister of Labor Ho Pei-shan (何佩珊) said she would tender her resignation following criticism of her handling of alleged bullying by Ministry of Labor Workforce Development Agency branch director Hsieh Yi-jung (謝宜容) resulting in the death of an employee. The ministry yesterday gave Hsieh two demerits and said she is subject to review by the Disciplinary Court. The severest possible punishment would be her removal from office and being barred from government jobs indefinitely. Workforce Development Agency Director-General Tsai Meng-liang (蔡孟良) also received a major demerit and was transferred to another position. Premier Cho Jung-tai (卓榮泰) issued a formal apology