A state-sponsored Chinese hacking group has been spying on a wide range of U.S. critical infrastructure organizations, from telecommunications to transportation hubs, Western intelligence agencies and Microsoft said on Wednesday.
The espionage has also targeted the U.S. island territory of Guam, home to strategically important American military bases, Microsoft said in a report, adding that "mitigating this attack could be challenging."
While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure.
The Chinese embassy in Washington did not immediately respond to a Reuters request for comment.
It was not immediately clear how many organizations were affected, but the U.S. National Security Agency (NSA) said it was working with partners including Canada, New Zealand, Australia, and the UK, as well as the U.S. Federal Bureau of Investigation to identify breaches. Canada, UK, Australia and New Zealand warned they could be targeted by the hackers too.
Microsoft analysts said they had "moderate confidence" this Chinese group, which it dubbed as 'Volt Typhoon', was developing capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.
"It means they are preparing for that possibility," added said John Hultquist, who heads threat analysis at Google's Mandiant Intelligence.
The Chinese activity is unique and worrying also because analysts don't yet have enough visibility on what this group might be capable of, he added.
"There is greater interest in this actor because of the geopolitical situation."
As China has stepped up military and diplomatic pressure in its claim to democratically governed Taiwan, U.S. President Joe Biden has said he would be willing to use force to defend Taiwan.
Security analysts expect Chinese hackers could target U.S. military networks and other critical infrastructure if China invades Taiwan.
The NSA and other Western cyber agencies urged companies that operate critical infrastructure to identify malicious activity using the technical guidance they issued.
"It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems," Paul Chichester, director at the UK's National Cyber Security Centre said in a joint statement with the NSA.
Microsoft said the Chinese hacking group has been active since at least 2021 and has targeted several industries including communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education.
NSA cybersecurity director Rob Joyce said the Chinese campaign was using "built-in network tools to evade our defenses and leaving no trace behind." Such techniques are harder to detect as they use "capabilities already built into critical infrastructure environments," he added.
As opposed to using traditional hacking techniques, which often involve tricking a victim into downloading malicious files, Microsoft said this group infects a victim's existing systems to find information and extract data.
Guam is home to U.S. military facilities that would be key to responding to any conflict in the Asia-Pacific region. It is also a major communications hub connecting Asia and Australia to the United States by multiple submarine cables.
Bart Hoggeveen, a senior analyst at the Australian Strategic Policy Institute who specializes in state-sponsored cyber attacks in the region, said the submarine cables made Guam "a logical target for the Chinese government" to seek intelligence.
"There is high vulnerability when cables land on shore," he said.
New Zealand said it would work towards identifying any such malicious cyber activity in its country.
"It's important for the national security of our country that we're transparent and upfront with Australians about the threats that we face," Australia's Minister for Home Affairs and Cyber Security Clare O'Neil said.
Canada's cybersecurity agency said it had no reports of Canadian victims of this hacking as yet. "However, Western economies are deeply interconnected," it added. "Much of our infrastructure is closely integrated and an attack on one can impact the other."
Reuters
Thu May 25 2023

While China and the United States routinely spy on each other, analysts say this is one of the largest known Chinese cyber-espionage campaigns against American critical infrastructure. - REUTERS

Beware of scam tactics using AI
The drastic development of AI technology is being taken advantage of by scammers to reap huge profits by using various latest tactics.

Fired and rehired - the dizzying confusion of Trump's government overhaul
They have adopted a blunt force approach toward the wholesale firing of workers, often focusing on workers who are easier to fire.

Arab states scramble to counter Trump's Gaza 'Riviera' plan
Arab states trying to devise an alternative plan have yet to tackle critical issues like who will foot the bill for Gaza's reconstruction.

Chinese universities launch DeepSeek courses to capitalise on AI boom
Universities across China have launched artificial intelligence courses this month based on Chinese AI startup DeepSeek.

Astronomers reveal 3D structure of an alien planet's atmosphere
Astronomers find three layers on a scorching gas planet orbiting a star larger and hotter than the sun.

Public flips car involved in road accident to rescue child
According to JBPM, members of the public at the scene took initial action to rescue the victim before the fire brigade arrived.

Ramsay reveals hundreds of lucky cat statues stolen from new restaurant
Gordon Ramsay says about 477 Japanese cat models called maneki-neko were stolen from his Lucky Cat 22 Bishopsgate restaurant.

Zayn Rayyan case: Two child witnesses complete testimony today
So far, 20 prosecution witnesses, including the two children, have been called for this trial, according to the Deputy Public Prosecutor.

Macron says he will tell Trump not to be weak with Putin in Washington visit
Emmanuel Macron says showing any weakness to Russia's Vladimir Putin would make it harder to deal with China and Iran.

Israeli PM Netanyahu says Hamas will pay for not returning Shiri Bibas
Netanyahu accuse Hamas of acting "in an unspeakably cynical manner" by placing body of a Gaza woman in the coffin instead of Shiri Bibas.

Trump pulls US out of key global climate assessment, sources say
The US is a co-chair along with Malaysia of a working group on climate mitigation, or ways to reduce greenhouse gas emissions.

Japan to court Tesla on Nissan investment, FT reports
The group hopes Tesla will invest strategically, believing it's interested in acquiring Nissan's US plants, the report says.

185 children linked to GISB handed over to families - Exco
The children have been handed over to their families on bond with conditions by the court.

IRS fires 6,000 employees as Trump slashes US government
The move will eliminate roughly 6% of the agency's workforce in the midst of the busy tax-filing season.

Elon Musk wields chainsaw at conservative gathering, a gift from Argentina's Milei
This is the chainsaw for bureaucracy, says Elon Musk.
![[OPINION] For never again the world must know more about the Khojaly genocide [OPINION] For never again the world must know more about the Khojaly genocide](https://resizer-awani.eco.astro.com.my/tr:w-177,h-100,q-100,f-auto/https://img.astroawani.com/2025-02/41740112820_KhazarUniversity.jpg)
[OPINION] For never again the world must know more about the Khojaly genocide
For Azerbaijanis, the Khojaly genocide is more than a historical event - it is a collective trauma that shapes their identity and worldview.

Israeli military says body released by Hamas is not of a hostage
Two bodies were identified as infants, but a third, believed to be their mother, Shiri, didn't match any hostage and remains unidentified.

Key takeaways from Trump-Putin talks: Ukraine, energy, NATO, sanctions
Here's what is known so far about what was discussed.
![[COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights [COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights](https://resizer-awani.eco.astro.com.my/tr:w-177,h-100,q-100,f-auto/https://img.astroawani.com/2024-09/41726025526_UnitedNations.jpg)
[COLUMNIST] Whose rights? Islam, eurocentrism and the limits of human rights
For as long as rights are understood on Occidental terms, problems would inevitably remain. What is needed is an appreciation of diversity.

Argentina court clears 3 accused in singer Liam Payne's death
The court upheld the pre-trial detention of a hotel employee and a restaurant waiter held since last month.