
U.S. authorities thwart another China
2024-09-20 05:45- U.S. authorities dismantled a botnet operated by the Chinese hacker group Flax Typhoon, freeing hundreds of thousands of infected devices.
- The botnet targeted critical infrastructure and various sectors, with over 200,000 infected devices located in the U.S.
- FBI Director Christopher Wray stated that this disruption is part of a longer fight against ongoing cyber threats from the Chinese government.
Express your sentiment!
Insights
On September 19, U.S. authorities announced the dismantling of a China-backed botnet operated by the hacker group Flax Typhoon. This operation freed hundreds of thousands of infected devices, including routers and cameras, which had been compromised to exfiltrate confidential data. The botnet targeted critical infrastructure and various sectors, including public and private entities, as well as academia and media. The Justice Department revealed that over 200,000 of the infected devices were located in the United States, allowing hackers to conduct malicious activities disguised as normal internet traffic. The operation was executed through a court-authorized law enforcement initiative, which successfully took control of the malicious infrastructure. During the disbanding, Chinese hackers attempted to intervene but were unsuccessful. Flax Typhoon was identified as operating under the guise of a legitimate company, Integrity Technology Group, based in Beijing, which had developed an online application for controlling infected devices. FBI Director Christopher Wray emphasized that this disruption is part of an ongoing battle against cyber threats from the Chinese government, which continues to target U.S. organizations and critical infrastructure. He noted that the group had been active since mid-2021 and had caused significant harm to its victims, including financial losses and operational disruptions. This incident follows a similar disruption in January, where U.S. authorities dismantled another China-backed malware botnet known as Volt Typhoon. The ongoing efforts highlight the persistent threat posed by state-sponsored hacking groups and the need for continued vigilance and collaboration among U.S. authorities and their partners.
Contexts
On Wednesday, a 10-year-old student was attacked and stabbed near the Shenzhen Japanese School in southern China, prompting warnings from the Japanese Embassy for citizens to remain vigilant. The motive for the attack remains unknown, and the attacker was arrested at the scene. This incident occurs amid rising tensions between the U.S. and China, with Deputy Secretary of State Kurt Campbell identifying China as the top challenge to the U.S. He has called for increased investment in advanced technology and urged European allies to adopt a firmer stance on China, particularly regarding its ties with Russia during the ongoing Ukraine conflict. Additionally, the U.S. has recently blacklisted a network facilitating financial transactions between Russia and North Korea, highlighting the growing financial cooperation between these nations. This move reflects the broader geopolitical dynamics affecting U.S.-China relations. Moreover, the FBI's disruption of a Chinese hacking group targeting U.S. critical infrastructure underscores ongoing cybersecurity threats from China. These multifaceted tensions contribute to a complex landscape in U.S.-China relations, which may have significant implications for safety and security in the region.