Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

U.S. cybersecurity experts see recent spike in Chinese digital espionage

Published 03/25/2020, 08:05 AM
Updated 03/25/2020, 11:05 AM
© Reuters. Hooded man holds laptop computer as cyber code is projected on him in this illustration picture

By Christopher Bing and Raphael Satter

(Reuters) - A U.S. cybersecurity firm said Wednesday it has detected a surge in new cyberspying by a suspected Chinese group dating back to late January, when coronavirus was starting to spread outside China.

FireEye Inc. (O:FEYE) said in a report it had spotted a spike in activity from a hacking group it dubs "APT41" that began on Jan. 20 and targeted more than 75 of its customers, from manufacturers and media companies to healthcare organizations and nonprofits.

There were "multiple possible explanations" for the spike in activity, said FireEye Security Architect Christopher Glyer, pointing to long-simmering tensions between Washington and Beijing over trade and more recent clashes over the coronavirus outbreak, which has killed more than 17,000 people since late last year.

The report said it was "one of the broadest campaigns by a Chinese cyber espionage actor we have observed in recent years."

FireEye declined to identify the affected customers. The Chinese Foreign Ministry did not directly address FireEye's allegations but said in a statement that China was "a victim of cybercrime and cyberattack." The U.S. Office of the Director of National Intelligence declined comment.

FireEye said in its report that APT41 abused recently disclosed flaws in software developed by Cisco (O:CSCO), Citrix (O:CTXS) and others to try to break into scores of companies' networks in the United States, Canada, Britain, Mexico, Saudi Arabia, Singapore and more than a dozen other countries.

Cisco said in an email it had fixed the vulnerability and it was aware of attempts to exploit it, a sentiment echoed by Citrix, which said it had worked with FireEye to help identify "potential compromises."

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Others have also spotted a recent uptick in cyber-espionage activity linked to Beijing.

Matt Webster, a researcher with Secureworks – Dell Technologies' (N:DELL) cybersecurity arm – said in an email that his team had also seen evidence of increased activity from Chinese hacking groups "over the last few weeks."

In particular, he said his team had recently spotted new digital infrastructure associated with APT41 – which Secureworks dubs "Bronze Atlas."

Tying hacking campaigns to any specific country or entity is often fraught with uncertainty, but FireEye said it had assessed "with moderate confidence" that APT41 was composed of Chinese government contractors.

FireEye's head of analysis, John Hultquist, said the surge was surprising because hacking activity attributed to China has generally become more focused.

"This broad action is a departure from that norm," he said.

Latest comments

Please investigate as well if there is a Cover up of information about the Covid19 virus. The whole world except China caught off guard. If this group or the mobile companies  like Oppo, Huawie and Vivo responsible in blocking the information.
Of cou China does that. they want to be number one while keeping everyone in the dark about what's really going on right. is anyone surprised?
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.