Chinese cybersecurity experts have exposed a hacker group, with its core members coming from Europe and North America, which has been launching sustained cyberattacks against China as its primary target, posing a serious threat to the country’s cybersecurity and data security, the Global Times learned from a Beijing-based cybersecurity lab on Sunday.
(資料圖片僅供參考)
In a report the Global Times obtained from Qi An Pangu lab, it revealed the hacking group, named Against The West (ATW), has claimed to have disclosed sensitive information including source code and database of important information systems related to China about more than 70 times since 2021, involving some 300 information systems of more than 100 important government agencies as well as aviation and infrastructure departments.
In particular, since 2022, ATW has intensified its momentum and continued to carry out large-scale scanning detection and “supply chain” attacks on Chinese networks, the report shows.
Through long-term tracking, cybersecurity experts from Qi An Pangu lab found that the active members of ATW are mainly engaged in programming and network engineer-related occupations and they are mainly located in Switzerland, France, Poland, Canada and other countries.
This is the second time that the lab revealed the true face of a hacker organization that has been carrying out data theft and network attacks on China, following the exposure of the complete technical detailsof Equation, an elite hacking group affiliated with the NSA, in February 2022. Equation was found to have been creating an advanced and covert backdoor, which has been used to monitor 45 countries and regions for over a decade.
According to the report, the ATW group was established in June 2021 and became active in online forums in October that year. Since its establishment, ATW has expressed a clear anti-China bias. It publicly stated that it would “publish posts about data leakage in China, North Korea and other countries.” It also published a special post entitled “ATW-War against China,” which explicitly supported “Taiwan independence,” advocated “Hong Kong independence” and hyped up “human rights issues” in China’s Xinjiang region.
Since October 2021, the organization has been active across overseas social media platforms, displaying a clear pro-US and pro-West slant. ATW has published several statements claiming that the organization’s targets are Russia, Belarus, China, Iran and North Korea and it is willing to share files with the US and the EU or hired by their related agencies.
According to incomplete statistics, since 2021, ATW has disclosed important information system source code, database and other sensitive information more than 70 times. The organization claimed that the data came from more than 100 Chinese departments, involving government agencies and state-owned enterprises.
For example, on January 7, 2022, ATW claimed to sell “a large amount of government, NGO, institutional and corporate data in China, involving 102 Chinese entities.”
However, experts from the lab found that the so-called source code is the test data or project code files developed by small and medium-sized software development enterprises. Experts also found that, in order to gain attention, ATW tends to distort and exaggerate its attacks.
The lab team identified six active members from the ATW, with three of them from France and one from Canada. One of the members Tillie Kottmann, born in Switzerland, was charged by the US Department of Justice in March 2021, but the case was abruptly suspended at the end of March. Since then, China has been one of Kottmann’s main targets, according to the lab report.
The organization mainly carried out large-scale scanning and attacks against technical vulnerabilities on SonarQube, Gogs, Gitblit and other open-source network systems. They would then steal related source code and data, which can be used to further exploit and penetrate the network information system.
"This is a typical ‘supply chain" attack," a senior cybersecurity expert from the lab told the Global Times on Sunday.
He suggested that software development enterprises should immediately repair software vulnerabilities, strictly control public network access permissions, and make timely modifications to default access passwords, and further improve the security management ability of source code.
As for the leakage of the system source code deployed in the user unit, the expert suggested that software development enterprises should strengthen the security audit of the system source code and encrypt and store the source code and data of important information systems.
"Cybersecurity-related government departments and technical teams should strengthen the monitoring of illegal cyberattack activities of the ATW organization, warn the trend of attack, and carry out background tracing and other countermeasures," the expert said.
關(guān)鍵詞: China cyberattacks
【速看料】Hacker group with members from Europe, North America found to have launched cyberattacks against China Chinesecybersecurityexpertshaveexposedahackergroup,withitscoremembers
全球今頭條!【寫意中國探尋漢字起源】濮陽市南樂縣倉頡文化博物館:字圣故里講好... 字圣牌坊攝影張雨晴國際在線河南頻道消息(張雨晴):2月19日下午,“寫意中國——探尋漢字起源”網(wǎng)絡(luò)主題宣傳活動采訪團(tuán)走進(jìn)濮陽南樂縣...
當(dāng)前快報:【走進(jìn)區(qū)域看發(fā)展】重慶渝中:全方位服務(wù)矩陣“引鳳長棲” 新華網(wǎng)重慶2月20日電(記者陳碩)“對待園區(qū)企業(yè),我們不止是‘保姆式’服務(wù),更要有‘親媽式’服務(wù)意識。”重慶數(shù)字經(jīng)濟(jì)產(chǎn)業(yè)園管理委員...
當(dāng)前關(guān)注:【走進(jìn)區(qū)域看發(fā)展】重慶兩江新區(qū):“產(chǎn)學(xué)研”協(xié)同,打造“五分鐘科研生... 光明網(wǎng)訊(記者徐皓)畢業(yè)后走出校門,在工作中是否還可以體驗“大學(xué)生活”?重慶市兩江新區(qū)給出了肯定的答案。在這里,隨著明月湖產(chǎn)學(xué)...
走進(jìn)區(qū)域看發(fā)展|渝西水資源配置工程金剛沱泵站:一江碧水向西“流” 流入渝西千萬家 雨水時節(jié),江津區(qū)油溪鎮(zhèn)金剛社區(qū)長江左岸,春雨淅淅瀝瀝?!?月20日,江津區(qū)油溪鎮(zhèn),金剛沱泵站工程施工現(xiàn)場。記者崔力攝 視覺重慶2月2...
走進(jìn)區(qū)域看發(fā)展丨“老街巷”變“新地標(biāo)” 百年老街龍門浩煥發(fā)新活力 華龍網(wǎng)-新重慶客戶端訊(記者張馨月)2月19日,“走進(jìn)區(qū)域看發(fā)展川渝奮楫譜新篇”網(wǎng)上主題宣傳采訪團(tuán)來到重慶南濱路龍門浩老街。漫步老...
聚鏈成群,鍛造產(chǎn)業(yè)競爭新優(yōu)勢(經(jīng)濟(jì)大省勇挑大梁②)_環(huán)球頭條 江蘇省連云港市東方盛虹煉化一體化項目。連云港市徐圩新區(qū)供圖核心閱讀2022年,面對國內(nèi)外多重超預(yù)期因素影響,江蘇經(jīng)濟(jì)運行呈現(xiàn)持續(xù)恢復(fù)、回
打通壁壘,讓智能家電更便利(微經(jīng)濟(jì)) 打通智能家電操作端口上的壁壘,讓更多消費者享受科技帶來的便利生活,智能家電領(lǐng)域也將迎來更廣闊的發(fā)展空間遠(yuǎn)程操控的電飯鍋、自動巡...
今日報丨【團(tuán)結(jié)奮斗 忠誠履職】黃花春:讓鄉(xiāng)村孩子獲得優(yōu)質(zhì)教育資源 央視網(wǎng)消息(新聞聯(lián)播):黃花春是廣西崇左市高級中學(xué)副校長,在一線教育崗位工作了20多年,如何讓偏遠(yuǎn)地區(qū)的孩子享受到優(yōu)質(zhì)均衡的教育...
走村入戶 探訪民生(代表委員履職故事) 每日熱門 連著幾日升溫,初春的雪剛剛開始融化,寧夏回族自治區(qū)吳忠市紅寺堡區(qū)紅寺堡鎮(zhèn)玉池村的道路變得更加濕滑難走。全國人大代表、紅寺堡區(qū)紅...
觀天下!佛山舉行高考備考分析研討會,推進(jìn)育人方式變革、構(gòu)建“五好教育”新形態(tài) 推進(jìn)普通高中育人方式變革,答好高...
禪城石灣今明兩天重啟“游朱紫 大紅大紫”嶺南民俗活動 環(huán)球觀焦點 二月二龍?zhí)ь^,來美陶灣,感受千年...
強鎮(zhèn)興村富農(nóng)!佛山云浮攜手 書寫鄉(xiāng)村振興優(yōu)秀答卷 世界快報 投入各類資金6億元,推動46個農(nóng)業(yè)...
看熱訊:南海區(qū)領(lǐng)導(dǎo)帶隊開展2023年南?!捌髽I(yè)暖春”行動 佛山新聞網(wǎng)訊珠江時報記者吳瑋琛劉...
東莞新型冠狀病毒肺炎疫情:2月21日東莞疫情最新消息今天數(shù)據(jù)統(tǒng)計情況通報 東莞新型冠狀病毒肺炎疫情:2月21日...
社保卡到期了需要換嗎?社保卡到期換卡要手續(xù)費嗎? 社??ǖ狡诹诵枰獡Q嗎?社??ǖ狡?..
全球快資訊丨故組詞語的組詞 1、故鄉(xiāng)2、故宮3、故意4、故事5、...
【防彈少年團(tuán)BTS田柾國JK】《原來是初戀》19 田柾國昨晚選擇和你分開睡,你其實...