Beijing denies US claims it backed hacking operation | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


  • AFP and Reuters,
    BEIJING and WASHINGTON

China yesterday warned the US against “smearing” Beijing with hacking allegations after US law enforcement disrupted Internet domains it said were used by Chinese state-sponsored groups.

The US on Wednesday said it had disrupted a Chinese hacking operation responsible for break-ins and attempts on the US Department of Justice, NASA, the US Federal Reserve, the US Senate and other sensitive government agencies.

In a statement, the justice department said it had seized domains used by two hacking platforms, dubbed “QScan” and “QTRouter,” which it said had been used as part of the campaign.

Photo: Reuters

An affidavit identified the US Department of Energy, Department of Health and Human Services (HHS), the National Institutes of Health (NIH), and four unnamed companies in the US and South Korea as being among the hackers’ targets.

The Chinese Ministry of Foreign Affairs called the allegations “false information,” accusing the US of “distorting right and wrong.”

The justice department said the platforms were run by a China-based firm, the Nanjing Xinjiuwei Network Technology Co, whose clients it said included the Chinese Ministry of State Security and the Chinese People’s Liberation Army.

The affidavit said the hackers used tools they developed to compromise critical infrastructure and other sensitive networks in the US and worldwide since at least 2018.

Not all their attempts to gain access were successful, as the hackers failed to gain access to NASA networks in August 2019 by targeting a virtual private network vulnerability, it added.

In September 2024, the hackers carried out intrusions at three unnamed energy department laboratories, the NIH, an unnamed HHS agency and a US security device manufacturer, the affidavit said.

A joint cybersecurity advisory issued by the FBI, NSA and the US Cyber Command’s Cyber National Mission Force detailed multiple hacking efforts over the years.

These included data theft from unnamed defense contractors, financial institutions and universities in May 2024.

The hackers also scanned for vulnerabilities and made unsuccessful attempts to access networks of the US Senate and a US hospital in March.

Chinese-linked hacking campaigns have compromised a string of sensitive US government and private networks in the past few years. In March, the FBI notified the US Congress that hackers had penetrated certain agency networks related to people under FBI investigation, with public reporting later attributing the compromise to China.

Chinese-linked hackers have also been tied to a compromise of certain US House of Representatives committee networks, as well as multiple major telecommunications companies.

Experts who follow Chinese cyberactivity say private contractors routinely carry out high-profile intrusions on behalf of Chinese government agencies.

“Over the last decade, the number of companies offering niche offensive services has exploded,” said Dakota Cary, a China analyst with cybersecurity company SentinelOne.



Click Here For The Original Source.

——————————————————–

..........

.

.