Biden Administration Blames Hackers Tied to China for Microsoft Cyberattack 
Spree
By Dustin Volz and Aruna Viswanatha
Updated July 19, 2021 8:08 am ET

WASHINGTON—The Biden administration Monday publicly blamed hackers affiliated 
with China’s main intelligence service for a far-reaching cyberattack on 
Microsoft Corp. email software this year, senior administration officials said, 
part of a global effort to condemn Beijing’s malicious cyber activities.

In addition, four Chinese nationals, including three intelligence officers, 
were indicted over separate hacking activity.

The U.S. government has “high confidence” that hackers tied to the Ministry of 
State Security, or MSS, carried out the unusually indiscriminate hack of 
Microsoft Exchange Server software that emerged in March, senior officials said.

“The United States and countries around the world are holding the People’s 
Republic of China (PRC) accountable for its pattern of irresponsible, 
disruptive, and destabilizing behavior in cyberspace, which poses a major 
threat to our economic and national security,” Secretary of State Antony 
Blinken said. The MSS, he added, had “fostered an ecosystem of criminal 
contract hackers who carry out both state-sponsored activities and cybercrime 
for their own financial gain.”

The U.K. and European Union joined in the attribution of the hacking activity, 
which rendered an estimated hundreds of thousands of mostly small businesses 
and organizations vulnerable to cyber intrusion.

The U.S.-led announcement is the most significant action from the Biden 
administration to date concerning China’s yearslong campaign of cyberattacks 
against the U.S. government and American companies, often involving routine 
nation-state espionage and the theft of valuable intellectual property such as 
naval technology and coronavirus-vaccine data.

The Justice Department made public Monday a grand jury indictment from May that 
charged four Chinese nationals and residents working with the Ministry of State 
Security of being engaged in a hacking campaign from 2011 to 2018 intended to 
benefit China’s companies and commercial sectors by stealing intellectual 
property and business information. The indictment didn’t appear directly 
related to the Microsoft Exchange Server breach, but accused the hackers of 
stealing information from companies and universities about Ebola virus research 
and other topics to benefit the Chinese government and Chinese companies.

Attributing the Microsoft hack to China will be part of a broader global 
censure of Beijing’s cyberattacks by the U.S., the European Union, the U.K., 
Canada, Australia, New Zealand, Japan and the North Atlantic Treaty 
Organization, or NATO. They will accuse the MSS of using criminal contractors 
to “conduct unsanctioned cyber operations globally, including for their own 
personal profit,” such as cyber-enabled extortion and theft, the official said.

U.S. authorities have accused China of widespread hacking targeting American 
businesses and government agencies for years. China has historically denied the 
allegations. A spokesman for the Chinese Embassy in Washington didn’t 
immediately respond to a request for comment.

The Exchange Server hack was disclosed by Microsoft in March alongside a 
software patch to fix the bugs being exploited in the attack. Microsoft at the 
time identified the culprits as a Chinese cyber-espionage group with state ties 
that it refers to as Hafnium, an assessment that was supported by other 
cybersecurity researchers. The Biden administration hadn’t offered attribution 
until now, and is essentially agreeing with the conclusions of the private 
sector and providing a more detailed identification.

The attack on the Exchange Server systems began slowly and stealthily in early 
January by hackers who in the past had targeted infectious-disease researchers, 
law firms and universities, according to cybersecurity officials and analysts. 
But the operational tempo appeared to intensify as other China-linked hacking 
groups became involved, infecting thousands of servers as Microsoft worked to 
send its customers a software patch in early March.

Also on Monday, the National Security Agency, Federal Bureau of Investigation 
and Cybersecurity and Infrastructure Security Agency jointly published 
technical details of more than 50 tactics and techniques favored by hackers 
linked to the Chinese government, the official said. The release of such lists 
is common when the U.S. exposes or highlights malicious hacking campaigns and 
is intended to help businesses and critical infrastructure operators better 
protect their computer systems.

< - >

https://www.wsj.com/articles/biden-administration-to-blame-hackers-tied-to-china-for-microsoft-cyberattack-spree-11626692401?mod=hp_lead_pos3

-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to