The US Department of Justice (DOJ) is charging four Chinese state hackers with participating in attacks on “companies, universities , and government agencies in the United States and abroad between 2011 and 2018.”

The indictment states that Ding Xiaoyang, Cheng Qingmin and Zhu Yunmin were members of the Hainan Ministry of Security and secretly worked at a company called Hainan Xiandun Technology Development Co., Ltd.
See also: Chinese hackers carry out attacks against Asian government agencies
The goal of the operation, according to the Justice Department, was to steal information from companies that would help businesses in China. The DOJ said the Chinese hackers were looking for “information that would allow them to bypass long-term and resource-intensive research and development.”
In addition to the charges common to Chinese hackers, a fourth man, Wu Shurong, is also accused of creating malware that helped others compromise computer systems.

The Justice Department noted that the hacking group attacked companies in the United States, Indonesia, Malaysia, Norway, Saudi Arabia, South Africa, Switzerland, the United Kingdom, Austria, Cambodia, Canada and Germany. Most of the victim companies were active in the defense, healthcare, education, aviation and biopharmaceutical sectors.
The Ministry said that the hackers stole trade secrets and confidential business information, such as data on technologies used for underwater and autonomous vehicles, special chemical formulas, data on commercial aircraft maintenance, etc. The hackers' goal was to steal data so that Chinese companies could use it for their own benefit.
See also: Chinese hackers target Afghan government by impersonating President Ashraf Ghani
“At research institutes and universities, hackers wanted to gain access to research on infectious diseases, such as Ebola, MERS, HIV/AIDS, Marburg“.
The indictment also targets some teachers at universities in Hainan and across China, accusing them of collaborating with the country's Ministry of State Security and aiding in the attacks.
Deputy Attorney General Lisa Monaco said the charges show that China continues to use cyberattacks to steal trade and other secrets from other countries.
“The scope and duration of China’s hacking campaigns, including these efforts that targeted multiple countries in a variety of sectors, from healthcare and biomedical research to aviation and defense, remind us that no country or industry is safe,” Monaco said.

The DOJ noted that many cybersecurity firms have reported on these Chinese hackers and their activities and have given them various names such as Advanced Persistent Threat (APT) 40, BRONZE, MOHAWK, FEVERDREAM, G0065, Gadolinium, GreenCrash, Hellsing, Kryptonite Panda, Leviathan, Mudcarp, Periscope, Temp.Piscisc, and Temp.Jumper.
See also: Chinese hackers exploit SolarWinds bug to target defense companies
The group used a variety of hacking methods to compromise systems (stolen credentials, spear phishing , etc.), as well as many sophisticated malware to gain access to systems, remain there, and steal credentials and admin passwords.
The indictment notes that the hackers used anonymizer services, Dropbox Application Programming Interface (API) keys, and GitHub during their attacks.
The DOJ is charging the Chinese hackers with wire fraud and economic espionage. Combined, the two charges carry a maximum sentence of 20 years in prison.
These days, dozens of countries are also blaming China for the widespread Microsoft Exchange hack.
Source: ZDNet
