By Interestana AI Editorial — AI-drafted, human-overseen. How we report
US Seizes Domains Linked to Chinese Hackers Targeting Government
United States authorities announced the seizure of two internet domains that were allegedly used by a China-linked hacking group to target sensitive government networks, including those of NASA and the U.S. Senate, dating back to at least 2018. The Department of Justice (DOJ) stated that the domains, identified as "us-senate.gov" and "nasa-gov.org," were part of a sophisticated cyber-espionage campaign orchestrated by a group known as "Volt Typhoon." This group, also referred to as "Barium" or "Wuhan Mayi," has been linked to the People's Republic of China and has been observed using these domains to impersonate legitimate government entities and trick individuals into downloading malware. The operation aimed to gain unauthorized access to sensitive information and critical infrastructure. The DOJ's announcement, made on June 5, 2024, detailed how the hackers employed spear-phishing techniques, sending emails with malicious links or attachments to government employees. Upon clicking these links, victims would be directed to fake login pages hosted on the seized domains, where their credentials would be captured. This information would then be used to access internal government systems. The investigation revealed that the campaign had been ongoing for several years, indicating a persistent threat to national security. The seizure of these domains represents a significant disruption to the group's operations and a proactive measure to protect U.S. government data. The DOJ emphasized that this action underscores the ongoing threat posed by state-sponsored cyber actors and the commitment of U.S. law enforcement to combatting such activities. The domains were seized under a court order obtained by the U.S. Attorney's Office for the Eastern District of Virginia. The investigation involved multiple agencies, including the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA). The Volt Typhoon group has previously been implicated in attacks targeting various sectors beyond government, including critical infrastructure in the United States and other allied nations. Their tactics often involve maintaining a low profile and using advanced persistent threat (APT) techniques to remain undetected within victim networks for extended periods. The U.S. government has repeatedly warned about the increasing sophistication and prevalence of cyber threats originating from China, urging both public and private sector organizations to bolster their cybersecurity defenses. The seizure serves as a reminder of the constant vigilance required to safeguard digital assets and national security interests in the face of evolving cyber threats.
Original source — read the full reporting at the publisher:
Read on Al JazeeraGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.