NATIONAL NEWS

Security firm: Chinese hackers broke into email security appliance in spying campaign

Jun 15, 2023, 6:02 AM | Updated: 6:14 am

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

“This is the broadest cyber espionage campaign known to be conducted by a China-nexus threat actor since the mass exploitation of Microsoft Exchange in early 2021,” Charles Carmakal, Mandiant’s chief technical officler, said in a emailed statement. That hack compromised tens of thousands of computers globally.

In a blog post Thursday, Google-owned Mandiant expressed “high confidence” that the group exploiting a software vulnerability in Barracuda Networks’ Email Security Gateway was engaged in “espionage activity in support of the People’s Republic of China.” It said the activivity began as early as October.

The hackers sent emails containing malicious file attachments to gain access to targeted organizations’ devices and data, Mandiant said. Of those organizations, 55% were from the Americas, 22% from Asia Pacific and 24% from Europe, the Middle East and Africa and they included foreign ministries in Southeast Asia, foreign trade offices and academic organizations in Taiwan and Hong Kong. the company said.

Mandiant said the majority impact in the Americas may partially reflect the geography of Barracuda’s customer base.

Barracuda announced on June 6 that some of its its email security appliances had been hacked as early as October, giving the intruders a back door into compromised networks. The hack was so severe the California company recommended fully replacing the appliances.

After discovering it in mid-May, Barracuda released containment and remediation patches but the hacking group, which Mandiant identifies as UNC4841, altered their malware to try to maintain access, Mandiant said. The group then “countered with high frequency operations targeting a number of victims located in at least 16 different countries.”

Mandiant said the targeting at both the organizational and individual account levels, focused on issues that are high policy priorities for China, particularly in the Asia Pacific region. It said the hackers searched for email accounts of people working for governments of political or strategic interest to China at the time they were participating in diplomatic meetings with other countries.

The U.S. government has accused Beijing of being its principal cyberespionage threat, with state-backed Chinese hackers stealing data from both the private and public sector.

China says the U.S. also engages in cyberespionage against it, hacking into computers of its universities and companies.

——

AP Business Writer Zen Soo contributed from Hong Kong.

National News

President Joe Biden meets with Israeli Prime Minister Benjamin Netanyahu in New York, Wednesday, Se...

Associated Press

US allows Israeli citizens to travel to US visa-free as Israel joins a select group of countries

WASHINGTON (AP) — The Biden administration is admitting Israel into a select group of countries whose citizens are allowed to travel to the United States without getting a visa in advance. The decision announced Wednesday comes despite Washington’s concerns about the Israeli government’s treatment of Palestinian Americans and marks a major accomplishment for Israeli Prime […]

24 minutes ago

In this photo provided by the Morgan & Morgan law firm, utility contractors remove a charred Hawaii...

Associated Press

Takeaways from AP report on Maui fire investigation

Investigators are trying to solve a mystery about the origin of last month’s deadly Maui wildfire: How did a small, wind-whipped fire sparked by downed power lines and declared extinguished flare up again hours later into a devastating inferno that killed at least 97 people? Here are the key takeaways of an Associated Press investigation […]

7 hours ago

This photo provided by the Morgan & Morgan law firm shows a charred Hawaiian Electric utility pole ...

Associated Press

How did the Maui fire spread so quickly? Overgrown gully, stubborn embers may be key to probe

Melted remains of an old car tire. Heavily burned trees. A charred stump of an abandoned utility pole. Investigators are examining these and other pieces of evidence as they seek to solve the mystery of last month’s deadly Maui wildfire: How did a small, wind-whipped fire sparked by downed power lines and declared extinguished flare […]

8 hours ago

FILE - Damarra Atkins pays respect to George Floyd at a mural at George Floyd Square, Friday, April...

Associated Press

Black Americans express concerns about racist depictions in news media, lack of coverage efforts

NEW YORK (AP) — In a new study, Black Americans expressed broad concerns about how they are depicted in the news media, with majorities saying they see racist or negative depictions and a lack of effort to cover broad segments of their community. Four in five Black adults say they see racist or racially insensitive […]

8 hours ago

FILE - Ahmad Al Aliwi Alissa, accused of killing 10 people at a Colorado supermarket in March 2021,...

Associated Press

Expert ruling that Colorado supermarket shooting suspect is competent for trial set to be debated

BOULDER, Colo. (AP) — A hearing begins Wednesday to determine if the man accused of killing 10 people at a Colorado supermarket in 2021 is mentally competent to stand trial. Ahmad Al Aliwi Alissa, 24, was found mentally competent by experts at the state mental hospital in August, but his defense attorney Kathryn Herold asked […]

9 hours ago

FILE-Sen. Mitt Romney, R-Utah, speaks with Strider Technologies, an AI-powered strategic intelligen...

Associated Press

Race to replace Mitt Romney heats up as Republican Utah House speaker readies to enter

Republican Utah House Speaker Brad Wilson is poised to formally announce at a Wednesday night rally that he is running for the U.S. Senate seat being vacated by Mitt Romney, who recently announced he won’t run for reelection. Romney announced earlier this month that he won’t seek a second term, saying younger people needed to […]

9 hours ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

Security firm: Chinese hackers broke into email security appliance in spying campaign