Chinese Government Is Behind a Decade of Hacks On Software Companies, Says Report (arstechnica.com)
An anonymous reader quotes a report from Ars Technica: Researchers said Chinese intelligence officers are behind almost a decade's worth of network intrusions that use advanced malware to penetrate software and gaming companies in the US, Europe, Russia, and elsewhere. The hackers have struck as recently as March in a campaign that used phishing emails in an attempt to access corporate-sensitive Office 365 and Gmail accounts. In the process, they made serious operational security errors that revealed key information about their targets and possible location. Researchers from various security organizations have used a variety of names to assign responsibility for the hacks, including LEAD, BARIUM, Wicked Panda, GREF, PassCV, Axiom, and Winnti. In many cases, the researchers assumed the groups were distinct and unaffiliated. According to a 49-page report published Thursday, all of the attacks are the work of Chinese government's intelligence apparatus, which the report's authors dub the Winnti Umbrella. Researchers from 401TRG, the threat research and analysis team at security company ProtectWise, based the attribution on common network infrastructure, tactics, techniques, and procedures used in the attacks as well as operational security mistakes that revealed the possible location of individual members.
This is not surprising. Anybody who is surprised by this is either an idiot, or one of those that work for these gov and are simply lying about it.
Yes, they are hitting the west VERY HARD. The amount of spying going on here is incredible.
Trump has it right in finally addressing CHina's economic war on America. Sadly, he is speaking about it, but really doing very little.
BUT, when he goes after allies at the same time, esp when they are NOT dumping on us, that is just insane.
It is time for the gov to start putting up real national security (i.e. go back to FBI doing the background checks), do decent checks on sub-contractors. etc.
I prefer the "u" in honour as it seems to be missing these days.