HomeSecurityQihoo: Chinese cybersecurity firm accuses CIA of hacking

Qihoo: Chinese cybersecurity firm accuses CIA of hacking

QihooQihoo 360, China's largest cybersecurity , released a report today accusing the CIA of hacking operations against Chinese companies and government agencies for more than 11 years. Specifically, it claims that the targets of the CIA's hacking operations were the aviation industry, scientific research institutions, the oil industry, Internet companies and government agencies in China. According to Qihoo researchers, the CIA's hacking operations took place between September 2008 and June 2019, with most of the targets located in Beijing, Guangdong and Zhejiang.

Qihoo notes that a large portion of the CIA's hacking operations focused on the civil aviation industry, both in China and other countries. The Chinese security firm says the purpose of this campaign was to collect information about all flights worldwide, passengers, cargo carried, and other relevant information over a long period of time .cia hacking attacks

The reason Qihoo links the hacks it receives to the CIA is due to the malware used in the attacks, namely Fluxwire (1, 2, 3) and Grasshopper (1, 2). Both of these types of malware were revealed in early 2017 when Wikileaks published Vault 7, a collection of files describing the CIA's electronic weapons equipment.

WikiLeaks claimed to have obtained the files from a CIA employee and a whistleblower, later identified as Joshua Schultz, who is currently on trial in the US. Shortly after the WikiLeaks Vault 7 revelations, Symantec confirmed that Fluxwire was the Corentry malware they had been tracking for years. Qihoo 360's analysis found that the technical details of most of the samples matched those in the Vault 7 document, such as control commands, PDB paths, and encryption programs. Chinese researchers also claim to have found versions of Fluxwire that were developed long before the Vault 7 leaks were published, with detection times matching Fluxwire's now-public changelog.

Additionally, Qihoo researchers claim that the malware correspond to US time zones. This is a common technique that American researchers have used many times in the past to link malware samples to Chinese hackers.cia hacking attacks

The Qihoo report, however, reveals essentially nothing new. Most of the information in the report was already known three years ago. The only new information included in the Qihoo report is the specific targets that were supposedly destroyed by the CIA in China, information that was not previously known before today 's Qihoo blog post

In its report, Qihoo referred to the CIA hacking operations as the codename APT-C-39. The CIA hacking operations are also identified as Longhorn (Symantec) and Lamberts ( Kaspersky). Qihoo 360 now becomes the second Chinese security vendor in the past six months to publicly accuse the CIA of employing deceptive tactics against China.

In late September 2019, cybersecurity firm Qi An Xin published a similar report accusing the CIA of malicious activities against Chinese aviation targets between 2012 and 2017. Emerging researchers, however, did not link the group behind these activities to any specific country, but instead called the hackers “Rattlesnake,” taking their name from a snake native to the southeastern United States and parts of Mexico.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS