AP

Suspected Chinese hackers spied on US, European targets

Apr 20, 2021, 1:58 AM | Updated: Apr 21, 2021, 10:36 am

Suspected state-backed Chinese hackers exploited widely used networking devices to spy for months on dozens of high-value government, defense industry and financial sector targets in the U.S. and Europe, according to FireEye, a prominent cybersecurity firm.

FireEye said Tuesday that it believes two hacking groups linked to China broke into several targets through Pulse Connect Secure devices, which numerous companies and governments use for secure remote access to their networks.

After FireEye released a blog post detailing its findings Tuesday, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an alert saying it was aware of “ongoing exploitation” of Pulse Connect Secure that is “compromising U.S. government agencies, critical infrastructure entities, and private sector organizations.” The agency did not provide additional details about which organizations were breached.

Ivanti, the Utah-based owner of Pulse Connect Secure, said a limited number of customers “experienced evidence of exploit behavior.” The company said the hackers used three known exploits and a previously unknown one.

The company says it will release a patch in early May.

Charles Carmakal, the chief technology officer at FireEye, said it is still trying to piece together details about the hack but that available evidence suggests the hackers are aligned with the Chinese government.

Carmakal, whose company discovered in December the monthslong SolarWinds hacking campaign attributed to Russian cyberspies, said the Pulse Connect Secure hack had several notable aspects: The hackers were highly skilled, were able to evade multifactor authentication and could stay hidden on a penetrated network even if software was reset or upgraded.

“Their tradecraft is really good,” he said.

Neither FireEye nor Ivanti would specify who was targeted. But Carmakal said those hacked were government agencies in both the U.S. and Europe as well as U.S-based defense companies “you would anticipate the Chinese government being interested in.”

“They’re very high-profile victims,” he said.

A spokesman for the Chinese Embassy, Liu Pengyu, said “it is irresponsible and ill-intentioned to accuse a particular party when there is no sufficient evidence around.”

The new disclosure comes at a time of heightened interest in U.S. cybersecurity defenses. U.S. officials are still grappling with the aftereffects of the SolarWinds intrusion, which struck agencies including the Treasury, Justice and Homeland Security departments.

The breach exposed vulnerabilities in the supply chain as well as weaknesses in the federal government’s own cyber defenses.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Image: Former President Donald Trump speaks to the press in Manhattan state court in New York City ...

Associated Press

Trump’s hush money trial gets underway; 1st day ends without any jurors selected

The historic hush money trial of Donald Trump got underway Monday with the arduous process of selecting a jury to hear the case.

8 hours ago

Photo: Israeli Iron Dome air defense system launches to intercept missiles fired from Iran, in cent...

Tia Goldenberg and Josef Federman, The Associated Press

Israel is quiet on next steps against Iran — and on which partners helped shoot down missiles

On Sunday, Israel's leaders credited an international military coalition with helping thwart a direct attack from Iran.

1 day ago

Early phases of Iran's drone attack against Israel. (Photo: Getty Images)...

Associated Press

The Latest | Iran launches its first direct military attack against Israel

Iran launched its first full-scale military attack against Israel on Saturday, sending drones toward Israel.

2 days ago

Early phases of Iran's drone attack against Israel. (Photo: Getty Images)...

Associated Press

BREAKING: White House confirms Iran drone attacks towards Israel

JERUSALEM (AP) — The White House says it will provide unspecified support for Israel’s defense against an ongoing airborne attack from Iran. National Security Council spokesperson Adrienne Watson said in a Saturday statement that “Iran has begun an airborne attack against Israel.” She added: “The United States will stand with the people of Israel and […]

2 days ago

Image: O.J. Simpson attends his parole hearing at Lovelock Correctional Center July 20, 2017 in Lov...

Associated Press

O.J. Simpson, fallen football hero acquitted of murder in ‘trial of the century,’ dies at 76

O.J. Simpson, the former NFL star and Hollywood actor who was acquitted of charges he killed his ex-wife and her friend has died at 76.

5 days ago

Southwest Airlines boeing...

Associated Press

An engine cover on a Southwest Airlines plane rips off, forcing the flight to return to Denver

A Southwest Airlines jet, a Boeing 737, returned to Denver Sunday morning after the engine cover fell off and struck the wing flap during takeoff.

8 days ago

Suspected Chinese hackers spied on US, European targets