Chinese Hackers Behind US Ransomware Attacks: Security Firms

Advertisement
By Reuters | Updated: 15 March 2016 09:50 IST
Hackers using tactics and tools previously associated with Chinese government-supported computer network intrusions have joined the booming cybercrime industry of ransomware, four security firms that investigated attacks on US companies said.

Ransomware, which involves encrypting a target's computer files and then demanding payment to unlock them, has generally been considered the domain of run-of-the-mill cybercriminals.

But executives of the security firms have seen a level of sophistication in at least a half dozen cases over the last three months akin to those used in state-sponsored attacks, including techniques to gain entry and move around the networks, as well as the software used to manage intrusions.

"It is obviously a group of skilled of operators that have some amount of experience conducting intrusions," said Phil Burdette, who heads an incident response team at Dell SecureWorks.

Advertisement

Burdette said his team was called in on three cases in as many months where hackers spread ransomware after exploiting known vulnerabilities in application servers. From there, the hackers tricked more than 100 computers in each of the companies into installing the malicious programs.

Advertisement

The victims included a transportation company and a technology firm that had 30 percent of its machines captured.

Security firms Attack Research, InGuardians and G-C Partners, said they had separately investigated three other similar ransomware attacks since December.

Advertisement

Although they cannot be positive, the companies concluded that all were the work of a known advanced threat group from China, Attack Research Chief Executive Val Smith told Reuters.

The ransomware attacks have not previously been reported. None of the companies that were victims of the hackers agreed to be identified publicly.

Advertisement

The security companies investigating the advanced ransomware intrusions have various theories about what is behind them, but they do not have proof and they have not come to any firm conclusions.

Most of the theories flow from the possibility that the Chinese government has reduced its support for economic espionage, which it pledged to oppose in an agreement with the United States late last year. Some US companies have reported a decline in Chinese hacking since the agreement.

Smith said some government hackers or contractors could be out of work or with reduced work and looking to supplement their income via ransomware.

It is also possible, Burdette said, that companies which had been penetrated for trade secrets or other reasons in the past were now being abandoned as China backs away, and that spies or their associates were taking as much as they could on the way out. In one of Dell's cases, the means of access by the team spreading ransomware was established in 2013.

The cyber-security experts could not completely rule out more prosaic explanations, such as the possibility that ordinary criminals had improved their skills and bought tools previously used only by governments.

Dell said that some of the malicious software had been associated by other security firms with a group dubbed Codoso, which has a record of years of attacks of interest to the Chinese government, including those on US defence companies and sites that draw Chinese minorities.

Payment in Bitcoin
Ransomware has been around for years, spread by some of the same people that previously installed fake anti-virus programs on home computers and badgered the victims into paying to remove imaginary threats.

In the past two years, better encryption techniques have often made it impossible for victims to regain access to their files without cooperation from the hackers. Many ransomware payments are made in the virtual currency Bitcoin and remain secret, but institutions including a Los Angeles hospital have gone public about ransomware attacks.

Ransomware operators generally set modest prices that many victims are willing to pay, and they usually do decrypt the files, which ensures that victims will post positively online about the transaction, making the next victims who research their predicament more willing to pay.

Security software companies have warned that because the aggregate payoffs for ransomware gangs are increasing, more criminals will shift to it from credit card theft and other complicated scams.

The involvement of more sophisticated hackers also promises to intensify the threat.

InGuardians CEO Jimmy Alderson said one of the cases his company investigated appeared to have been launched with online credentials stolen six months earlier in a suspected espionage hack of the sort typically called an Advanced Persistent Threat, or APT.

"The tactics of getting access to these networks are APT tactics, but instead of going further in to sit and listen stealthily, they are used for smash-and-grab," Alderson said.

© Thomson Reuters 2016

 

Also seeCryptocurrency Prices across Indian exchanges

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Bitcoin, Cyber attack, Internet, Ransomware
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  2. Scientists May Have Found a Way to Predict Volcano Eruptions
  3. Poco F8 Ultra Listing on NBTC Certification Site Hints at Imminent Launch
  4. Ganoshotru OTT Release: Know When and Where to Watch the Bengali Crime-Thriller Online
  5. OnePlus 15 India Launch Teased; Key Features Revealed Ahead of Launch
  6. These Are the 5 Biggest OxygenOS 16 Features You Should Know About
  7. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  8. Redmi K90 Pro Max Key Features Revealed Ahead of Launch on October 23
  1. Samsung Galaxy XR Headset Launching Today: Know Price, Features, and Specifications
  2. Smartwatch Breakthrough Brings GPS Accuracy Down to a Few Centimetres
  3. SpaceX Launches 10,000th Starlink Satellite, Sets New Annual Record
  4. Scientists Discover New Seismic Clue to Predict Mount Etna Eruptions
  5. NASA and ESA Trace Mysterious Lunar Flashes to Meteors and Gas Leaks
  6. Valsala Club Is Streaming Now: Know All About the Malayali Comedy-Drama Movie
  7. Ganoshotru OTT Release: Know When and Where to Watch the Bengali Crime-Thriller Online
  8. Mr Shudai OTT Release: Know When and Where to Watch the Punjabi Horror-Comedy
  9. SpaceX May Miss First Crewed Moon Landing as NASA Reopens Artemis Bid
  10. OpenAI Introduces ChatGPT Atlas, an AI-Powered Web Browser With Agentic Capabilities
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.