UNITED STATES NEWS

Security firm: Chinese hackers broke into email security appliance in spying campaign

Jun 15, 2023, 6:02 AM | Updated: 6:14 am

Suspected state-backed Chinese hackers used a security hole in a popular email security appliance to break into the networks of hundreds of public and private sector organizations globally, nearly a third of them government agencies including foreign ministries, the cybersecurity firm Mandiant said Thursday.

“This is the broadest cyber espionage campaign known to be conducted by a China-nexus threat actor since the mass exploitation of Microsoft Exchange in early 2021,” Charles Carmakal, Mandiant’s chief technical officler, said in a emailed statement. That hack compromised tens of thousands of computers globally.

In a blog post Thursday, Google-owned Mandiant expressed “high confidence” that the group exploiting a software vulnerability in Barracuda Networks’ Email Security Gateway was engaged in “espionage activity in support of the People’s Republic of China.” It said the activivity began as early as October.

The hackers sent emails containing malicious file attachments to gain access to targeted organizations’ devices and data, Mandiant said. Of those organizations, 55% were from the Americas, 22% from Asia Pacific and 24% from Europe, the Middle East and Africa and they included foreign ministries in Southeast Asia, foreign trade offices and academic organizations in Taiwan and Hong Kong. the company said.

Mandiant said the majority impact in the Americas may partially reflect the geography of Barracuda’s customer base.

Barracuda announced on June 6 that some of its its email security appliances had been hacked as early as October, giving the intruders a back door into compromised networks. The hack was so severe the California company recommended fully replacing the appliances.

After discovering it in mid-May, Barracuda released containment and remediation patches but the hacking group, which Mandiant identifies as UNC4841, altered their malware to try to maintain access, Mandiant said. The group then “countered with high frequency operations targeting a number of victims located in at least 16 different countries.”

Mandiant said the targeting at both the organizational and individual account levels, focused on issues that are high policy priorities for China, particularly in the Asia Pacific region. It said the hackers searched for email accounts of people working for governments of political or strategic interest to China at the time they were participating in diplomatic meetings with other countries.

The U.S. government has accused Beijing of being its principal cyberespionage threat, with state-backed Chinese hackers stealing data from both the private and public sector.

China says the U.S. also engages in cyberespionage against it, hacking into computers of its universities and companies.

——

AP Business Writer Zen Soo contributed from Hong Kong.

United States News

Associated Press

Navy to start random testing of SEALs, special warfare troops for performance-enhancing drugs

WASHINGTON (AP) — The Navy will begin randomly testing its special operations forces for steroids and other performance-enhancing drugs beginning in November, taking a groundbreaking step that military leaders have long resisted. Rear Adm. Keith Davids, commander of Naval Special Warfare Command, announced the new program Friday in a message to his force, calling it […]

2 hours ago

Associated Press

Iowa book ban prompts disclaimers on Little Free Library exchanges

WEST DES MOINES, Iowa (AP) — State restrictions on books that can be made available to Iowa students have prompted some Des Moines-area school districts to post disclaimers on Little Free Libraries. Earlier this year the Iowa Legislature approved a law that bans books that describe sex acts from libraries and classrooms, forcing school districts […]

2 hours ago

Associated Press

New York man who served 18 years for murder acquitted at 2nd trial

MINEOLA, N.Y. (AP) — A New York man who spent 18 years in prison for a murder he said he did not commit was found not guilty at a second trial. Paul Scrimo, 66, was acquitted on Thursday in Nassau County Court in the strangulation death of Ruth Williams in 2000, Newsday reported. Scrimo was […]

2 hours ago

Associated Press

Judge says she is ending conservatorship between former NFL player Michael Oher and Memphis couple

MEMPHIS, Tenn. (AP) — A Tennessee judge said Friday she is ending a conservatorship agreement between former NFL player Michael Oher and a Memphis couple who took him in when he was in high school. Shelby County Probate Court Judge Kathleen Gomes said she is terminating the agreement reached in 2004 that allowed Sean and […]

2 hours ago

FILE - Wisconsin's Republican Assembly Speaker Robin Vos talks to reporters at the state Capitol, F...

Associated Press

Former Wisconsin Supreme Court justice refuses to disclose names of others looking at impeachment

MADISON, Wis. (AP) — One of three former Wisconsin Supreme Court justices asked to review possible impeachment of a current justice refused to tell a judge Friday who else was looking into that question. Former Justice David Prosser called a lawsuit alleging violations of the state open meetings law “frivolous,” saying those looking into impeachment […]

2 hours ago

FILE - Violent insurrectionists loyal to President Donald Trump breach the U.S. Capitol in Washingt...

Associated Press

Proud Boy who disappeared ahead of his Jan. 6 sentencing was found unconscious by agents at his home

A member of the Proud Boys extremist group who disappeared days before he was supposed to be sentenced for his role in the U.S. Capitol riot was found unconscious by federal agents after he tried to “covertly return” to his home, the FBI said on Friday. Christopher Worrell, of Naples, Florida, was taken to a […]

3 hours ago

Sponsored Articles

Home moving relocation in Arizona 2023...

BMS Moving

Tips for making your move in Arizona easier

If you're moving to a new home in Arizona, use this to-do list to alleviate some stress and ensure a smoother transition to your new home.

...

Ignite Digital

How to unlock the power of digital marketing for Phoenix businesses

All businesses around the Valley hopes to maximize their ROI with current customers and secure a greater market share in the digital sphere.

...

Mayo Clinic

Game on! Expert sports physicals focused on you

With tryouts quickly approaching, now is the time for parents to schedule physicals for their student-athlete. The Arizona Interscholastic Association requires that all student-athletes must have a physical exam completed before participating in team practices or competition.

Security firm: Chinese hackers broke into email security appliance in spying campaign