'Cloudhopper' linked to China govt on hacking spree to steal data, warns US

Chinese authorities have repeatedly denied claims by Western cyber security firms that it supports hacking

ATM hackers
Cybercriminals are targeting US cash machines with tools that force them to spit out cash, known as “jackpotting”
Reuters
Last Updated : Oct 04 2018 | 7:27 AM IST
The US government on Wednesday warned that a hacking group widely known as cloudhopper, which Western cybersecurity firms have linked to the Chinese government, has launched attacks on technology service providers in a campaign to steal data from their clients.

The Department of Homeland issued a technical alert for cloudhopper, which it said was engaged in cyber espionage and theft of intellectual property, after experts with two prominent US cybersecurity companies warned earlier this week that Chinese hacking activity has surged amid the escalating trade war between Washington and Beijing.

Chinese authorities have repeatedly denied claims by Western cyber security firms that it supports hacking.

Homeland Security released the information to support US companies in responding to attacks by the group, which is targeting information technology, energy, healthcare, communications and manufacturing firms.

"These cyber threat actors are still active and we strongly encourage our partners in government and industry to work together to defend against this threat," DHS official Christopher Krebs said in a statement.

The reported increase in Chinese hacking follows what cybersecurity firms have described as a lull in such attacks prompted by a 2015 agreement between Chinese President Xi Jinping and former US President Barrack Obama to curb cyber-enabled economic theft.

I can tell you now, unfortunately, the Chinese are back," Dmitri Alperovitch, chief technology officer of US cybersecurity firm CrowdStrike, said Tuesday at a security conference in Washington, DC.

"We've seen a huge pickup in activity over the past year and a half. Nowadays they are the most predominant threat actors we see threatening institutions all over this country and western Europe, he said.

Analysts with FireEye, another US cybersecurity firm, said that some of the Chinese hacking groups it tracks have become more active in recent months.

Wednesday's alert provided advice on how US firms can prevent, identify and remediate attacks by cloudhopper, which is also known as Red Leaves and APT10.

The hacking group has largely targeted firms known as managed service providers, which supply telecommunications, technology and other services to business around the globe.

Managed service providers, or MSPs, are attractive targets because their networks provide routes for hackers to access sensitive systems of their many clients, said Ben Read, a senior intelligence manager with FireEye.

"We've seen this group route malware through an MSP network to other targets," Read said.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Next Story