Cybersecurity

Cyberattacks by US Intelligence Agencies on Chinese Tech Firms Unveiled by CNCERT Reports

On Friday, the CNCERT released investigative reports detailing recent cyberattacks believed to be orchestrated by US intelligence agencies targeting significant Chinese technology firms. These investigations revealed that since August 2024, an advanced materials research institution in China had faced cyber intrusions that exploited a weakness in its electronic document security management system, allowing attackers to infiltrate and compromise its software upgrade management server.

Through this software upgrade mechanism, cyber attackers were able to deploy control trojans onto more than 270 host machines within the institution, which facilitated the theft of considerable trade secrets and intellectual property. The reports outlined a detailed timeline of activities beginning on August 19, 2024, when attackers took advantage of an injection vulnerability in the electronic document system to gain access and steal administrative account credentials.

By August 21, the attackers logged into the management functions of the compromised system with the stolen credentials, deploying a backdoor and a customized trojan that operated solely in memory to avoid detection. This trojan would receive sensitive files from compromised personal computers, while the backdoor aggregated and transmitted these files abroad. On subsequent dates, notably November 6 and 8, the attackers utilized the software upgrade feature to implant specialized trojans into numerous devices within the organization, specifically designed to scan for and steal sensitive information.

The attackers even disguised their activities using IP proxies located in China, allowing them to repeatedly infiltrate the internal networks of their target while carefully scanning for valuable data. The reports signify that on three notable occasions, different keyword-related trojans were introduced, indicating a methodical approach to the espionage operation that resulted in the theft of nearly 5GB of vital commercial information.

In addition to this case, a high-tech enterprise specializing in smart energy and digital information has been under similar cyber threats since May 2023. Attackers exploited vulnerabilities in Microsoft Exchange, taking control of the company's email server to implant backdoor programs that facilitated continuous data theft from email communications.

one allowed attackers to impersonate users, while the other enabled arbitrary code execution. By planting tools that only operated in memory, attackers could escape detection while stealing sensitive information and infiltrating other devices within the internal network using sophisticated methods like internal network scanning and encrypted tunnels. Ultimately, this led to unauthorized control over more than 30 devices, including email servers and code management systems, culminating in the theft of approximately 1.03GB of confidential data from the compromised firm's assets.

Read-to-Earn opportunity
Time to Read
You earned: None
Date

Post Profit

Post Profit
Earned for Pluses
...
Comment Rewards
...
Likes Own
...
Likes Commenter
...
Likes Author
...
Dislikes Author
...
Profit Subtotal, Twei ...

Post Loss

Post Loss
Spent for Minuses
...
Comment Tributes
...
Dislikes Own
...
Dislikes Commenter
...
Post Publish Tribute
...
PnL Reports
...
Loss Subtotal, Twei ...
Total Twei Earned: ...
Price for report instance: 1 Twei

Comment-to-Earn

5 Comments

Avatar of Bella Ciao

Bella Ciao

Finally! We've known the US has been stealing from us for years. It's good to have concrete evidence. Now we can demand justice.

Avatar of Habibi

Habibi

This report is just the tip of the iceberg. The US is likely engaging in similar cyber attacks against other countries. This needs to stop!

Avatar of Rolihlahla

Rolihlahla

This is a wake-up call for China. We need to become more self-sufficient in technology to avoid dependence on foreign powers.

Avatar of G P Floyd Jr

G P Floyd Jr

The US needs to explain itself! How can they justify stealing trade secrets from Chinese companies? This is a serious betrayal of trust.

Avatar of Comandante

Comandante

Thank you to the CNCERT for exposing these attacks. We need more transparency and accountability for cyber operations.

Available from LVL 13

Add your comment

Your comment avatar