The US has reported a Chinese cyber-espionage campaign targeting NASA

The US Department of Justice has seized three domains linked to a Nanjing-based company whose services, according to the authorities, were used by hackers.

0

US officials have stated that a cyber-espionage campaign linked to China has compromised a number of US federal agencies and networks in critical sectors. According to the authorities, Chinese military and intelligence organisations may have been involved in the operation, acting through a technology company based in Nanjing. The US Department of Justice has seized three internet domains linked to the company.

Briefly about the main points

  • The US has named NASA, the Federal Reserve, the Senate and two ministries among the organisations that have been compromised.
  • Other targets included military networks, hospitals, the energy sector and defence contractors.
  • Washington links the operation to Chinese military and intelligence agencies.
  • The hackers disguised their activities as ordinary internet traffic and used botnets.
  • The Ministry of Justice has seized three domains, and the relevant authorities are drawing up technical guidelines.

NASA, the Senate and the energy sector were cited as targets

US officials have reported a security breach NASA, the Federal Reserve System, the US Senate, and the Departments of Justice and Energy. The Department of Justice also listed military networks, hospitals, energy companies and defence contractors among the targets.

The full extent of the consequences of the espionage operation has not yet been established. Assessments of the damage being carried out by US counter-intelligence agencies may not be made public for security reasons.

The US authorities have described a front organisation operating through a company based in Nanjing

According to the US, hackers linked to the Chinese military and intelligence services used the services of Nanjing Xinjiuwei Network Technology Company. US officials believe that the company helped to conceal the origin of the attacks, infiltrate the targets’ networks and enhance the effectiveness of the operation.

According to the authorities, the cybercriminals masked their activities amongst ordinary consumer internet traffic and controlled botnets from compromised devices. The company was founded in 2018; Chinese business registers indicated that 17 people were employed there last year.

Senior Safety Engineer at Black Lotus Labs, a division of Lumen Technologies Damon Rose, who had been investigating this activity for several months, described this cover-up scheme as the most sophisticated he had ever seen. In his view, operating through a commercial company could have left a paper trail for investigators to follow.

The US has seized the domains and is drawing up recommendations for those affected

To limit further damage, the US Department of Justice has seized three internet domains linked to the Chinese company. Federal agencies also plan to issue guidance on the techniques used by the attackers so that victim organisations can remove them from their systems.

US Attorney General Blanche He told Fox News that Washington has been raising this issue for many years in its dealings with Chinese officials, and stressed that such activities must cease. The Chinese authorities usually reject US accusations of hacking attacks and accuse the US of conducting its own cyber operations.

WRITE A REPLY

enter your comment!
enter your name here