US Warns of New Hacking Spree From Group Linked to China

US Warns of New Hacking Spree From Group Linked to China
A man types on a computer keyboard in Warsaw on Feb. 28, 2013. (Kacper Pempel/Reuters)
Reuters
10/4/2018
Updated:
10/4/2018

WASHINGTON—The U.S. government on Oct. 3 warned that a hacking group widely known as cloudhopper, which Western cybersecurity firms have linked to the Chinese government, has launched attacks on technology service providers in a campaign to steal data from their clients.

The Department of Homeland Security (DHS) issued a technical alert for cloudhopper, which it said was engaged in cyber espionage and theft of intellectual property, after experts with two prominent U.S. cybersecurity companies warned earlier this week that Chinese hacking activity has surged amid the escalating trade war between Washington and Beijing.

Homeland Security released the information to support U.S. companies in responding to attacks by the group, which is targeting information technology, energy, healthcare, communications, and manufacturing firms.

“These cyber threat actors are still active and we strongly encourage our partners in government and industry to work together to defend against this threat,” DHS official Christopher Krebs said in a statement.

The reported increase in Chinese hacking follows what cybersecurity firms have described as a lull in such attacks after a 2015 agreement between Chinese leader Xi Jinping and former U.S. President Barack Obama to curb cyber-enabled economic theft.

“I can tell you now unfortunately the Chinese are back,” Dmitri Alperovitch, chief technology officer of U.S. cybersecurity firm CrowdStrike, said on Oct. 2 at a security conference in Washington.

“We’ve seen a huge pickup in activity over the past year and a half. Nowadays they are the most predominant threat actors we see threatening institutions all over this country and western Europe,” he said.

Analysts with FireEye, another U.S. cybersecurity firm, said that some of the Chinese hacking groups it tracks have become more active in recent months.

The alert from Oct. 3 provided advice on how U.S. firms can prevent, identify, and remediate attacks by cloudhopper, which is also known as Red Leaves and APT10.

The hacking group has largely targeted firms known as managed service providers, which supply telecommunications, technology and other services to business around the globe. Managed service providers (MSPs) are attractive targets because their networks provide routes for hackers to access sensitive systems of their many clients, said Ben Read, a senior intelligence manager with FireEye.

“We’ve seen this group route malware through an MSP network to other targets,” Read said.

Earlier in August, a blog run by anonymous cyber analysts specializing in investigating Chinese hacker groups that steal intellectual property from private firms, exposed the identities of three alleged APT10 hackers.

The Intrusion Truth blog—which had accurately identified two Chinese hackers who were later charged by the U.S. Department of Justice for cyber crimes and theft of trade secrets from Trimble, a U.S. software developer, and German manufacturing giant Siemens—alleged that the APT10 hackers were working directly for China’s intelligence agency, Ministry of State Security (MSS).

The anonymous analysts received copies of Uber receipts that showed an alleged APT10 hacker making trips to the Tianjin City office of MSS, making a definitive connection between the hacker group and the Chinese regime.

By Christopher Bing. Epoch Times staff member Annie Wu contributed to this report.