Chinese hackers are behind a new series of breaches that have hit key U.S. government targets, critical infrastructure and private companies, according to Mandiant. According to reports published by FireEye and Pulse Secure, Chinese hackers have exploited a new zero-day vulnerability in Pulse Secure VPN equipmentto penetrate the networks of U.S. defense contractors and government agencies around the world.
The attacks were discovered by cybersecurity firm FireEye earlier this year, when Mandiant investigated multiple security breaches at defense, government, and financial organizations around the world. In all of the breaches, the attackers targeted Pulse Secure VPN devices on the compromised networks.
Read also: University of Colorado: Hackers demand ransom to prevent the leak of over 300,000 files

“In many cases, we were unable to determine how the hackers gained administrator-level access to the devices. However, based on an analysis by Ivanti, we estimate that some of the intrusions were due to the exploitation of previously disclosed vulnerabilities from 2019 and 2020, while other intrusions were due to the exploitation of CVE-2021-22893,” the report published by FireEye states.
This malicious campaign is the third separate and serious cyber operation against the United States to be made public in recent months. The US government accused Russia in January of breaching nine of the country’s government agencies through SolarWinds – a Texas-based software company whose services are heavily used by US businesses and government agencies. In March, Microsoft accused China of launching a free-for-all, in which dozens of separate hacking groups broke into organizations around the world via Microsoft Exchange.
See also: US: Officially accuses SVR of SolarWinds hack – Sanctions and expulsion of Russian diplomats

In all three campaigns, hackers first used these programs to infiltrate victims' computer networks and then created backdoors to spy on them for months, if not longer.
CISA said in a warning issued on the afternoon of April 20 that the latest malicious campaign is “currently affecting U.S. government agencies, critical entities, and other private sector organizations.”
CISA activated its strictest emergency powers on the afternoon of April 20, requiring every government agency to scan to see if it was affected by the hack and take action to fix it. It is the second time in seven weeksthat CISA has issued an emergency advisory following the Exchange breach.
Proposal: FBI: Removes web shells from compromised Exchange servers without notifying owners

Matt Hartman, deputy executive assistant director for cybersecurity, said: “We’ve issued a number of emergency advisories over the last few months, which is certainly concerning and not something we take lightly. We at CISA are very concerned.”
Unlike the SolarWinds and Exchange hacks, which both had at least tens of thousands of potential victims, there is no indication that China used Pulse to compromise a large number of targets. However, the hack is particularly significantbecause it allowed China to gain access to multiple federal agencies and major U.S. companies for months, said Charles Carmakal, chief technology officer at Mandiant.
Additionally, Carmakal added the following: “We are starting to see a resurgence of espionage activity by the Chinese government. None of the victims have been made public yet, although that will likely change. In the coming weeks and months, we will have a better picture of how significant this hack is from a national security perspective.”
As with the Exchange hack, China did not deny responsibility. In an emailed statement, Liu Pengyu, a spokesman for the Chinese embassy in the US, said that China is a “strong advocate of cybersecurity” and “firmly opposes and suppresses all forms of cyberattacks.”.
