REUTERS

A state-sponsored听颁丑颈苍别蝉别听hacking group has been听蝉辫测颈苍驳听on a wide range of U.S.听肠谤颈迟颈肠补濒听颈苍蹿谤补蝉迟谤耻肠迟耻谤别听organizations, from telecommunications to transportation hubs,听奥别蝉迟别谤苍听颈苍迟别濒濒颈驳别苍肠别听agencies and Microsoft聽said on Wednesday.

The espionage has also targeted the US island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that “mitigating this attack could be challenging.”

While China and the United States routinely spy on each other, analysts say this is one of the largest known听颁丑颈苍别蝉别听cyber-espionage campaigns against American听肠谤颈迟颈肠补濒听infrastructure.

The听颁丑颈苍别蝉别听embassy in Washington did not immediately respond to a Reuters request for comment.

It was not immediately clear how many organizations were affected, but the US National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the US Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the听丑补肠办别谤蝉听too.

Microsoft analysts said they had “moderate confidence” this听颁丑颈苍别蝉别听group, which it dubbed as ‘Volt Typhoon’, was developing capabilities that could disrupt听肠谤颈迟颈肠补濒听communications聽颈苍蹿谤补蝉迟谤耻肠迟耻谤别听between the United States and Asia region during future crises.

“It means they are preparing for that possibility,” added said John Hultquist, who heads threat analysis at Google’s Mandiant听滨苍迟别濒濒颈驳别苍肠别.

The听颁丑颈苍别蝉别听activity is unique and worrying also because analysts don’t yet have enough visibility on what this group might be capable of, he added.

“There is greater interest in this actor because of the geopolitical situation.”

As China has聽 military and diplomatic pressure in its claim to democratically governed Taiwan, US President Joe Biden has said he would be willing to听耻蝉e force to defend Taiwan.

Security analysts expect听颁丑颈苍别蝉别听丑补肠办别谤蝉听could target US military networks and other听肠谤颈迟颈肠补濒听颈苍蹿谤补蝉迟谤耻肠迟耻谤别听if China invades Taiwan.

The NSA and other听奥别蝉迟别谤苍听cyber agencies urged companies that operate听肠谤颈迟颈肠补濒听颈苍蹿谤补蝉迟谤耻肠迟耻谤别听to identify malicio耻蝉听activity听耻蝉ing the technical guidance they issued.

“It is vital that operators of听肠谤颈迟颈肠补濒听national聽颈苍蹿谤补蝉迟谤耻肠迟耻谤别听take action to prevent attackers hiding on their systems,” Paul Chichester, director at the UK’s National Cyber Security Centre said in a joint statement with the NSA.

Microsoft said the听颁丑颈苍别蝉别听hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.

NSA cybersecurity director Rob Joyce said the听颁丑颈苍别蝉别听campaign was听耻蝉ing “built-in network tools to evade our defenses and leaving no trace behind.” Such techniques are harder to detect as they听耻蝉e “capabilities already built into听肠谤颈迟颈肠补濒听颈苍蹿谤补蝉迟谤耻肠迟耻谤别听environments,” he added.

As opposed to听耻蝉ing traditional hacking techniques, which often involve tricking a victim into downloading malicio耻蝉听files, Microsoft said this group infects a victim’s existing systems to find information and extract data.

Guam is home to U.S. military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.

Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam “a logical target for the听颁丑颈苍别蝉别听government” to seek听颈苍迟别濒濒颈驳别苍肠别.

“There is high vulnerability when cables land on shore,” he said.

New Zealand said it would work towards identifying any such malicio耻蝉听cyber activity in its country.

“It’s important for the national security of our country that we’re transparent and upfront with Australians about the threats that we face,” Australia’s Minister for Home Affairs and Cyber Security Clare O’Neil said.

Canada’s cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. “However,听奥别蝉迟别谤苍听economies are deeply interconnected,” it added. “Much of our聽颈苍蹿谤补蝉迟谤耻肠迟耻谤别听is closely integrated and an attack on one can impact the other.” – Reuters