{"id":16236,"date":"2024-03-26T14:23:01","date_gmt":"2024-03-26T13:23:01","guid":{"rendered":"https:\/\/telecomkh.info\/?p=16236"},"modified":"2024-03-26T14:23:01","modified_gmt":"2024-03-26T13:23:01","slug":"seven-hackers-associated-with-chinese-government-charged-with-computer-intrusions-targeting-perceived-critics-of-china-and-u-s-businesses-and-politicians","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=16236","title":{"rendered":"Seven hackers associated with Chinese Government charged with computer intrusions targeting perceived critics of China and U.S. businesses and politicians"},"content":{"rendered":"<p><strong>Defendants operated as part of the APT31 hacking group in support of China\u2019s Ministry of State security\u2019s transnational repression, economic espionage and foreign intelligence objectives<\/strong><\/p>\n<p>An indictment was unsealed yesterday charging seven nationals of the People\u2019s Republic of China (PRC) with conspiracy to commit computer intrusions and conspiracy to commit wire fraud for their involvement in a PRC-based hacking group that spent approximately 14 years targeting U.S. and foreign critics, businesses, and political officials in furtherance of the PRC\u2019s economic espionage and foreign intelligence objectives.<br \/>\nThe defendants are Ni Gaobin (\u502a\u9ad8\u5f6c), 38; Weng Ming (\u7fc1\u660e), 37; Cheng Feng (\u7a0b\u950b), 34; Peng Yaowen (\u5f6d\u8000\u6587), 38; Sun Xiaohui (\u5b59\u5c0f\u8f89), 38; Xiong Wang (\u718a\u65fa), 35; and Zhao Guangzong (\u8d75\u5149\u5b97), 38. All are believed to reside in the PRC.<br \/>\n\u201cThe Justice Department will not tolerate efforts by the Chinese government to intimidate Americans who serve the public, silence the dissidents who are protected by American laws, or steal from American businesses,\u201d said Attorney General Merrick B. Garland. \u201cThis case serves as a reminder of the ends to which the Chinese government is willing to go to target and intimidate its critics, including launching malicious cyber operations aimed at threatening the national security of the United States and our allies.\u201d<br \/>\n\u201cOver 10,000 malicious emails, impacting thousands of victims, across multiple continents. As alleged in today\u2019s indictment, this prolific global hacking operation \u2013 backed by the PRC government \u2013 targeted journalists, political officials, and companies to repress critics of the Chinese regime, compromise government institutions, and steal trade secrets,\u201d said Deputy Attorney General Lisa Monaco. \u201cThe Department of Justice will relentlessly pursue, expose, and hold accountable cyber criminals who would undermine democracies and threaten our national security.\u201d<br \/>\n\u00abToday&#8217;s announcement exposes China&#8217;s continuous and brash efforts to undermine our nation&#8217;s cybersecurity and target Americans and our innovation,\u201d said FBI Director Christopher Wray. \u00abAs long as China continues to target the US and our partners, the FBI will continue to send a clear message that cyber espionage will not be tolerated, and we will tirelessly pursue those who threaten our nation\u2019s security and prosperity. This indictment underscores our unwavering commitment to disrupt and deter malicious cyber activity, and safeguard our citizens, businesses, and critical infrastructure from threats in cyberspace.\u00bb<br \/>\n\u201cThe indictment unsealed today, together with statements from our foreign partners regarding related activity, shed further light on the PRC Ministry of State Security\u2019s aggressive cyber espionage and transnational repression activities worldwide,\u201d said Assistant Attorney General Matthew G. Olsen of the Justice Department\u2019s National Security Division. \u201cToday\u2019s announcements underscore the need to remain vigilant to cybersecurity threats and the potential for cyber-enabled foreign malign influence efforts, especially as we approach the 2024 election cycle. The Department of Justice will continue to leverage all tools to disrupt malicious cyber actors who threaten our national security and aim to repress fundamental freedoms worldwide.\u201d<br \/>\n\u201cThese allegations pull back the curtain on China\u2019s vast illegal hacking operation that targeted sensitive data from U.S. elected and government officials, journalists, and academics; valuable information from American companies; and political dissidents in America and abroad. Their sinister scheme victimized thousands of people and entities across the world, and lasted for well over a decade,\u201d said U.S. Attorney Breon Peace for the Eastern District of New York. \u201cAmerica\u2019s sovereignty extends to its cyberspace. Today\u2019s charges demonstrate my office\u2019s commitment to upholding and protecting that jurisdiction, and to putting an end to malicious nation state cyber activity.\u201d<br \/>\n\u201cThe recent indictments against the Chinese actors reaffirm the FBI\u2019s relentless dedication to combating cyber threats,\u201d said Assistant Director Bryan Vorndran of the FBI Cyber Division. \u201cThey serve as a reminder that cyber adversaries who seek to compromise our nation\u2019s systems and target US officials cannot rely on the cloak of anonymity and will face consequences for their actions.\u201d<br \/>\n\u201cAPT31 Group\u2019s practices further demonstrate the size and scope of the PRC\u2019s state-sponsored hacking apparatus,\u201d said Special Agent in Charge Robert W. \u201cWes\u201d Wheeler Jr. of the FBI Chicago Field Office. \u201cFBI Chicago worked tirelessly to uncover this complex web of alleged foreign intelligence and economic espionage crimes. Thanks to these efforts, as well as our partnerships with the U.S. Attorneys\u2019 Offices and fellow Field Offices, the FBI continues to be successful in holding groups accountable and protecting national security.\u201d<\/p>\n<p><strong>Overview<\/strong><br \/>\nAs alleged in the indictment and court filings, the defendants, along with dozens of identified PRC Ministry of State Security (MSS) intelligence officers, contractor hackers, and support personnel, were members of a hacking group operating in the PRC and known within the cybersecurity community as Advanced Persistent Threat 31 (the APT31 Group). The APT31 Group was part of a cyberespionage program run by the MSS\u2019s Hubei State Security Department, located in the city of Wuhan. Through their involvement with the APT31 Group, since at least 2010, the defendants conducted global campaigns of computer hacking targeting political dissidents and perceived supporters located inside and outside of China, government and political officials, candidates, and campaign personnel in the United States and elsewhere and American companies.<br \/>\nThe defendants and others in the APT31 Group targeted thousands of U.S. and foreign individuals and companies. Some of this activity resulted in successful compromises of the targets\u2019 networks, email accounts, cloud storage accounts, and telephone call records, with some surveillance of compromised email accounts lasting many years.<\/p>\n<p><strong>Hacking Scheme<\/strong><br \/>\nThe more than 10,000 malicious emails that the defendants and others in the APT31 Group sent to these targets often appeared to be from prominent news outlets or journalists and appeared to contain legitimate news articles. The malicious emails contained hidden tracking links, such that if the recipient simply opened the email, information about the recipient, including the recipient\u2019s location, internet protocol (IP) addresses, network schematics, and specific devices used to access the pertinent email accounts, was transmitted to a server controlled by the defendants and those working with them. The defendants and others in the APT31 Group then used this information to enable more direct and sophisticated targeted hacking, such as compromising the recipients\u2019 home routers and other electronic devices.<br \/>\nThe defendants and others in the APT31 Group also sent malicious tracking-link emails to government officials across the world who expressed criticism of the PRC government. For example, in or about 2021, the conspirators targeted the email accounts of various foreign government individuals who were part of the Inter-Parliamentary Alliance on China (IPAC), a group founded in 2020 on the anniversary of the 1989 Tiananmen Square protests whose stated purpose was to counter the threats posed by the Chinese Communist Party to the international order and democratic principles. The targets included every European Union member of IPAC, and 43 United Kingdom parliamentary accounts, most of whom were members of IPAC or had been outspoken on topics relating to the PRC government.<br \/>\nTo gain and maintain access to the victim computer networks, the defendants and others in the APT31 Group employed sophisticated hacking techniques including zero-day exploits, which are exploits that the hackers became aware of before the manufacturer, or the victim were able to patch or fix the vulnerability. These activities resulted in the confirmed and potential compromise of economic plans, intellectual property, and trade secrets belonging to American businesses, and contributed to the estimated billions of dollars lost every year as a result of the PRC\u2019s state-sponsored apparatus to transfer U.S. technology to the PRC.<\/p>\n<p><strong>Targeting of U.S. Government Officials and U.S. and Foreign Politicians and Campaigns<\/strong><br \/>\nThe targeted U.S. government officials included individuals working in the White House, at the Departments of Justice, Commerce, Treasury, and State, and U.S. Senators and Representatives of both political parties. The defendants and others in the APT31 Group targeted these individuals at both professional and personal email addresses. Additionally in some cases, the defendants also targeted victims\u2019 spouses, including the spouses of a high-ranking Department of Justice official, high-ranking White House officials, and multiple U.S. Senators. Targets also included election campaign staff from both major U.S. political parties in advance of the 2020 election.<br \/>\nThe allegations in the indictment regarding the malicious cyber activity targeting political officials, candidates, and campaign personnel are consistent with the March 2021 Joint Report of the Department of Justice and the Department of Homeland Security on Foreign Interference Targeting Election Infrastructure or Political Organization, Campaign, or Candidate Infrastructure Related to the 2020 US Federal Elections. That report cited incidents when Chinese government-affiliated actors \u201cmaterially impacted the security of networks associated with or pertaining to U.S. political organizations, candidates, and campaigns during the 2020 federal elections.\u201d That report also concluded that \u201csuch actors gathered at least some information they could have released in influence operations,\u201d but which the Chinese actors did not ultimately deploy in such a manner. Consistent with that conclusion, the indictment does not allege that the hacking furthered any Chinese government influence operations against the United States. The indictment\u2019s allegations nonetheless serve to underscore the need for U.S. (and allied) political organizations, candidates, and campaigns to remain vigilant in their cybersecurity posture and in otherwise protecting their sensitive information from foreign intelligence services, particularly in light of the U.S. Intelligence Community\u2019s recent assessment that \u201c[t]he PRC may attempt to influence the U.S. elections in 2024 at some level because of its desire to sideline critics of China and magnify U.S. societal divisions.\u201d<\/p>\n<p><strong>Targeting of U.S. Companies<\/strong><br \/>\nThe defendants and others in the APT31 Group also targeted individuals and dozens of companies operating in areas of national economic importance, including the defense, information technology, telecommunications, manufacturing and trade, finance, consulting, legal, and research industries. The defendants and others in the APT31 Group hacked and attempted to hack dozens of companies or entities operating in these industries, including multiple cleared defense contractors who provide products and services to the U.S. military, multiple managed service providers who managed the computer networks and security for other companies, a leading provider of 5G network equipment, and a leading global provider of wireless technology, among many others.<\/p>\n<p><strong>Targeting for Transnational Repression of Dissidents<\/strong><br \/>\nThe defendants and the APT31 Group also targeted individual dissidents around the world and other individuals who were perceived as supporting such dissidents. For example, in 2018, after several activists who spearheaded Hong Kong\u2019s Umbrella Movement were nominated for the Nobel Peace Prize, the defendants and the APT31 Group targeted Norwegian government officials and a Norwegian managed service provider. The conspirators also successfully compromised Hong Kong pro-democracy activists and their associates located in Hong Kong, the United States, and other foreign locations with identical malware.<\/p>\n<p>The charged defendants\u2019 roles in the conspiracy consisted of testing and exploiting the malware used to conduct these intrusions, managing infrastructure associated with these intrusions, and conducting surveillance and intrusions against specific U.S. entities. For example:<br \/>\n\u2022 Cheng Feng, Sun Xiaohui, Weng Ming, Xiong Wang, and Zhao Guangzong were involved in testing and exploiting malware, including malware used in some of these intrusions.<br \/>\n\u2022 Cheng and Ni Gaobin managed infrastructure associated with some of these intrusions, including the domain name for a command-and-control server that accessed at least 59 unique victim computers, including a telecommunications company that was a leading provider of 5G network equipment in the United States, an Alabama-based research corporation in the aerospace and defense industries, and a Maryland-based professional support services company.<br \/>\n\u2022 Sun and Weng operated the infrastructure used in an intrusion into a U.S. company known for its public opinion polls. Sun and Peng Yaowen conducted research and reconnaissance on several additional U.S. entities that were later the victims of the APT31 Group\u2019s intrusion campaigns.<br \/>\n\u2022 Ni and Zhao sent emails with links to files containing malware to PRC dissidents, specifically Hong Kong legislators and democracy advocates, as well as targeting U.S. entities focusing on PRC-related issues.<\/p>\n<p>Assistant U.S. Attorneys Douglas M. Pravda, Saritha Komatireddy, and Jessica Weigel for the Eastern District of New York are prosecuting the case, with valuable assistance from Matthew Anzaldi and Matthew Chang of the National Security Division\u2019s National Security Cyber Section.<\/p>\n<p><span style=\"color: #999999;\"><em>Above, photo by Christian Lue on unsplash<\/em><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Defendants operated as part of the APT31 hacking group in support of China\u2019s Ministry of State security\u2019s transnational repression, economic espionage and foreign intelligence objectives An indictment was unsealed yesterday charging seven nationals of the People\u2019s Republic of China (PRC) with conspiracy to commit computer intrusions and conspiracy to commit wire fraud for their involvement &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=16236\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abSeven hackers associated with Chinese Government charged with computer intrusions targeting perceived critics of China and U.S. businesses and politicians\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":16237,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16236"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16236"}],"version-history":[{"count":1,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16236\/revisions"}],"predecessor-version":[{"id":16238,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/16236\/revisions\/16238"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/16237"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}