theDocumentId => 748463 Justice Department Ties 2 Chinese Nationals to ...

Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

12/21/2018
07:00 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Justice Department Ties 2 Chinese Nationals to Notorious APT10 Group

In another indictment aimed at China's cyberespionage infrastructure, the Justice Department has charged two Chinese nationals with belonging to the notorious APT10 group, which targeted industries in the US, Japan and other countries.

The Justice Department has fired another warning shot at China's elaborate cyberespionage infrastructure, with a new indictment this week that charges two Chinese nationals with belonging to the APT10 group, which is responsible for a series of attacks against facilities and businesses in the US, Japan and dozens of other countries.

The indictment, unsealed December 20, charges Zhu Hua, who also goes by the name "Godkiller," and Zhang Shilong, who is also known as "Atreexp," with belonging to China's Ministry of State Security's Tianjin State Security Bureau, which is believed to be responsible for cyber espionage, as well as various cyber attacks.

The two face charges of conspiracy to commit computer intrusions, conspiracy to commit wire fraud and aggravated identity theft. The hackers are not currently in custody.

APT10 has been in operation since at least 2006, and spies working for the group have targeted at least 45 different US technology companies since that time in attempt to steal intellectual property, personal data and other trade secrets. The group also goes by the names "Red Apollo," "CVNX," "Stone Panda," "MenuPass" and "POTASSIUM," according to Thursday's indictment.

Late on Thursday, Reuters reported that two of the technology companies involved in the APT10 hacking include stalwarts IBM and Hewlett Packard Enterprise.

(Source: iStock)
(Source: iStock)

In an email statement, Ben Read, the senior manager for Cyber Espionage Analysis at FireEye noted:

APT10 has been tracked by FireEye for years and is one of the most prolific cyber espionage groups. They have compromised dozens of public and private organizations worldwide, stealing valuable intellectual property and confidential information. The tactics described in the indictment and verticals targeted are consistent with what FireEye has seen from this group. APT10 has historically targeted organizations with long research and development cycles, including construction and engineering, aerospace and military, telecommunications, high technology sectors, as well as government entities. Their move towards compromising managed service providers (MSPs) showcases the danger of supply chain compromises and reflects their continuously evolving tactics. APT10 is a well-resourced and a global threat.

In the US, APT10 targeted numerous government agencies, including NASA's Goddard Space Center and Jet Propulsion Laboratory; the US Navy, which involved the theft of personal information involving 100,000 personnel; and the Department of Energy's Lawrence Berkeley National Laboratory, which conducts a number of government-sponsored research projects.

This is the second time in two months that federal prosecutors have charged Chinese nationals with cybersecurity and cyber espionage crimes. In November, the Justice Department unveiled a major case against ten people, who were charged with trying to steal intellectual property for years. (See DoJ Charges 10 Chinese Nationals in Elaborate Cyberespionage Case.)

In addition, federal officials believe that China and its spies are responsible for the data theft that affected 500 million customers of Marriott's Starwood chain of hotels, according to a report. (See China Suspected of Massive Marriott Data Breach Report.)

And tensions are mounting between the US and China, as American prosecutors pursue a case against the company's CFO for helping the firm violate trade sanctions involving Iran. (See Unknown Document 748364.)

Mukul Kumar, chief information security officer and vice president of cyber practice at security vendor Cavirin, noted in an email to Security Now that the Justice Department seems more willing to prosecute cases involving the theft of intellectual property than in the past. However, Kumar cautioned that the cyber activity involving these groups, such as APT10, are usually years in the making and enterprises need to factor that into their cybersecurity plans.

"What we all need to understand is that these attacks are not only in the past... they are ongoing as we speak," Kumar wrote. "Organizations must be continually diligent in protecting their cyber posture via a layered approach to security that includes inside-the-firewall protection, training and implementation of best practices."

Indeed, this week's indictment describes two specific incidents involving long-term spying operations.

The first campaign targeted an unnamed managed service provider (MSP), where APT10 successfully planted malware, including PlugX, RedLeaves and QuasarRAT, on the company's servers to help steal passwords and other credentials. The group then used those to gain access to administrative tools, including Remote Desktop Protocols. From there, the spies had access to the much larger network, which, in turn, gave them access to the MSP's clients in Brazil, Canada, Finland, France, Germany, India, Japan, Sweden, Switzerland, the United Arab Emirates, the UK and the US.

The second part of the indictment looks at the theft of data and intellectual property that included "hundreds of gigabytes of sensitive data and information from the victims' computer systems, including from at least the following victims: seven companies involved in aviation, space and/or satellite technology; three companies involved in communications technology; three companies involved in manufacturing advanced electronic systems and/or laboratory analytical instruments; a company involved in maritime technology; a company involved in oil and gas drilling, production, and processing."

This part of the campaign also included the thefts involving NASA, the Department of Energy and the Navy.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-20399
PUBLISHED: 2021-07-27
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
CVE-2021-20562
PUBLISHED: 2021-07-27
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos...
CVE-2020-18428
PUBLISHED: 2021-07-26
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
CVE-2020-18430
PUBLISHED: 2021-07-26
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
CVE-2021-37576
PUBLISHED: 2021-07-26
arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.