Espionage

U.S. Cyber Espionage Targets Chinese Defense Sector, Poses National Security Threat

U.S. intelligence organizations have markedly increased their cyber espionage efforts directed at China's defense and military-industrial sectors, presenting critical threats to national security, as indicated by the China Cyberspace Security Association's announcement on Friday. The National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT) noted that American cyber operatives have executed various attacks on Chinese military-affiliated universities, research institutions, and companies. These operations primarily focus on extracting sensitive information regarding defense research, design, and manufacturing processes.

Two specific incidents were highlighted to illustrate the escalating dangers to critical infrastructure. The first incident, which took place from July 2022 to July 2023, involved U.S. hackers utilizing a zero-day vulnerability in Microsoft Exchange to breach a significant Chinese defense enterprise. The intruders managed to compromise the firm’s domain controller, taking control of over 50 internal devices while implementing tools to maintain long-term access and harvest classified data. Reports reveal that more than 40 attacks were funneled through proxy servers situated in countries such as Germany, Finland, South Korea, and Singapore, affecting sensitive communications of 11 individuals, including top executives.

In the second case, occurring between July and November 2024, another Chinese defense firm focusing on satellite and telecommunications was similarly compromised. Attackers took advantage of vulnerabilities in the firm's document system to introduce backdoors and trojans. By manipulating the software upgrade function, they deployed spyware that allowed them to seize control of over 300 devices and capture classified information concerning military networks.

Analysis indicates that these cyberattacks were executed by state-sponsored groups with specific strategic objectives, utilizing advanced methodologies to avoid detection and erase their digital traces. In 2024 alone, China documented over 600 cyber incidents attributed to foreign APT (Advanced Persistent Threat) groups, with the defense sector emerging as the primary target.

Read-to-Earn opportunity
Time to Read
You earned: None
Date

Post Profit

Post Profit
Earned for Pluses
...
Comment Rewards
...
Likes Own
...
Likes Commenter
...
Likes Author
...
Dislikes Author
...
Profit Subtotal, Twei ...

Post Loss

Post Loss
Spent for Minuses
...
Comment Tributes
...
Dislikes Own
...
Dislikes Commenter
...
Post Publish Tribute
...
PnL Reports
...
Loss Subtotal, Twei ...
Total Twei Earned: ...
Price for report instance: 1 Twei

Comment-to-Earn

6 Comments

Avatar of Fuerza

Fuerza

CNCERT is probably exaggerating to justify their own cyber operations. This is a classic deflection tactic.

Avatar of Ongania

Ongania

What kind of proof do we have that these incidents actually happened? Sounds like a fishy story to me.

Avatar of Manolo Noriega

Manolo Noriega

Every country engages in cyber espionage. Why single out the U.S.? It’s a global issue and a common practice.

Avatar of Fuerza

Fuerza

Are we sure these so-called 'cyberattacks' are not just failed attempts by the Chinese to cover for their internal security flaws?

Avatar of Manolo Noriega

Manolo Noriega

If sensitive information is being targeted, maybe China's defense systems just need to be improved instead of blaming the U.S.

Avatar of Eugene Alta

Eugene Alta

This just seems like propaganda! How can we trust any report coming from organizations like CNCERT?

Available from LVL 13

Add your comment

Your comment avatar