top of page
  • Writer's pictureBy The Financial District

FIRM TAGS CHINESE HACKERS FOR SPYING ON U.S., EUROPEAN TARGETS

Suspected state-backed Chinese hackers exploited widely used networking devices to spy for months on dozens of high-value government, defense industry, and financial sector targets in the US and Europe, according to cybersecurity firm FireEye, Alan Suderman reported for the Associated Press (AP).

EON Reality is the global leader in Augmented and Virtual Reality-based knowledge and skills transfer for industry and education.

FireEye said Tuesday that it believes two hacking groups linked to China broke into several targets through Pulse Connect Secure devices, which numerous companies and governments use for secure remote access to their networks.


After FireEye released a blog post detailing its findings Tuesday, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) issued an alert saying it was aware of “ongoing exploitation” of Pulse Connect Secure that is “compromising US government agencies, critical infrastructure entities, and private sector organizations.”


All the news: Business man in suit and tie smiling and reading a newspaper near the financial district.

The agency did not provide additional details about which organizations were breached.


Ivanti, the Utah-based owner of Pulse Connect Secure, said a limited number of customers “experienced evidence of exploit behavior.” The company said the hackers used three known exploits and a previously unknown one.


The company says it will release a patch in early May.


Charles Carmakal, the chief technology officer at FireEye, said it is still trying to piece together details about the hack but that available evidence suggests the hackers are aligned with the Chinese government.


Government & politics: Politicians, government officials and delegates standing in front of their country flags in a political event in the financial district.

Carmakal, whose company discovered in December the months-long SolarWinds hacking campaign attributed to Russian cyberspies, said the Pulse Connect Secure hack had several notable aspects: The hackers were highly skilled, were able to evade multifactor authentication, and could stay hidden on a penetrated network even if the software was reset or upgraded. “Their tradecraft is really good,” he said.


Neither FireEye nor Ivanti would specify who was targeted. But Carmakal said those hacked were government agencies in both the U.S. and Europe as well as U.S-based defense companies “you would anticipate the Chinese government being interested in.” A spokesman for the Chinese Embassy, Liu Pengyu, said: “it is irresponsible and ill-intentioned to accuse a particular party when there is no sufficient evidence around.”



Happyornot makes feedback terminals measuring customer satisfaction sing smiley-face buttons.
EON Reality is the global leader in Augmented and Virtual Reality-based knowledge and skills transfer for industry and education.

bottom of page