HomeSecurityVolt Typhoon: Chinese hacker network deactivated

Volt Typhoon: Chinese hacker network deactivated

The U.S. government recently conducted an operation to counter a growing Chinese hacking network (Volt Typhoon) that successfully compromised thousands of internet -connected devices , according to two security officials and a person familiar with the matter. The sources said the Justice Department and the Federal Bureau of Investigation sought and received legal authority to remotely disable parts of the Chinese cyberattack , Reuters reports.

See also: Chinese hackers target semiconductor companies

Volt Typhoon

The Biden administration is increasingly focused on hacking, not only because of fears that hostile governments might try to disrupt the US election in November, but also because ransomware wreaked havoc on corporate America in 2023. The hacking group at the center of the recent activity, Volt Typhoon, is of particular concern to intelligence officials, who say it is part of a larger effort to compromise critical infrastructure, including shipping ports, internet service providers and infrastructure services.

While the Volt Typhoon campaign first came to light in May 2023, the hackers expanded the scope of their operations in the past year and changed some of their techniques, according to three people familiar with the matter. The widespread nature of the breaches led to a series of meetings between the White House and the private technology industry, including several telecommunications and cloud, where the United States government requested help in monitoring the activity.

Such breaches, national security experts say, could allow China to remotely disrupt key facilities in the Indo-Pacific region that support or otherwise serve U.S. military operations. According to sources, U.S. officials are concerned that the hackers could seek to undermine U.S. preparedness in the event of a Chinese invasion of Taiwan. China, which claims democratically-ruled Taiwan as its own territory, has increased its military presence near the island in recent years in response to what Beijing calls a “conspiracy” between Taiwan and the United States.

See also: Chinese hackers APT15 use new Graphican backdoor

The Justice Department and the FBI declined to comment. China’s embassy in Washington did not immediately respond to a request for comment. When Western countries first issued warnings about the Volt Typhoon in May, Chinese Foreign Ministry spokesman Mao Ning said the hacking allegations were a “collective disinformation campaign” by the Five Eyes countries, a reference to the intelligence-sharing group of countries that includes the United States, Canada, New Zealand, Australia and the United Kingdom.

Chinese hacker network

Volt Typhoon operates by taking control of vulnerable digital devices worldwide — such as routers, modems and even internet-connected security cameras — to conceal subsequent attacks on more sensitive targets, security researchers told Reuters. This cluster of remotely controlled systems, known as a botnet, is a primary concern for security officials because it limits the visibility of cyberdefenders monitoring their networks for foreign traces.

The use of so-called botnets by both government and criminal hackers to hide their cyberattacks is not new. This approach is often used when the attacker wants to attack multiple victims or when they want to hide their origin.

See also: Chinese hackers accidentally infected a European hospital with malware

Chinese hackers use a variety of techniques to achieve their goals. One of them is phishing, a technique that aims to extract sensitive information, such as passwords and credit card numbers, through deceptive emails or websites. They also use spear phishing, which is a more targeted form of phishing. In this case, hackers create messages that appear to come from a person or company that the target knows and trusts.

Another technique they use is the watering hole attack, where hackers attack a specific website that their target visits regularly, with the aim of installing malware on device . Finally, Chinese hackers use the zero-day. This means that they exploit weaknesses in software that have not yet been discovered by manufacturers, giving them the ability to bypass security systems and carry out attacks that are difficult to detect.

Source: Reuters

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS