Site navigation

Chinese ‘Cyber-attacks for Hire’ Scheme Unveiled After Vendor Leak

Staff Writer

,

Chinese cyber-attack
A data leak from a Chinese cybersecurity vendor has exposed the extent of its global surveillance operations.

Countries such as the UK, along with Taiwan, India, Indonesia, Nigeria are discovered to have been implicated in global surveillance operations following a massive data leak originating from a Chinese cybersecurity vendor called I-Soon. 

The leaked information, which is made up of around 190 megabytes of data, was recently discovered on GitHub. 

The information offers a glimpse into China’s state-sponsored cyber apparatus, as I-Soon is a Shanghai-based company believed to be one of numerous private contractors assisting the government in intelligence gathering, hacking, and surveillance gathering. 

“They are part of an ecosystem of contractors that has links to the Chinese patriotic hacking scene, which developed two decades ago and has since gone legit,” said John Hultquist, chief analyst at Google’s Mandiant Intelligence to the New York Times

In response to the allegations, Chinese authorities have denied any knowledge of the data leak. Mao Ning, a spokesperson for the Chinese Ministry of Foreign Affairs, asserted during a press briefing that she was unaware of any data leak from I-Soon. 

“As a matter of principle, China firmly opposes and cracks down on all forms of cyber-attacks in accordance with the law,” Mao stated

Data discovered on GitHub include emails, conversations, images, and a number of documents detailing contracts and communications between I-Soon and Chinese authorities, and thought by cyber experts to be genuine. The cache of more than 500 leaked files discuss targets such as Nato and the UK Foreign Office


Recommended reading


Analysis of the documents by cybersecurity experts indicate a systematic campaign that spanned around eight years, with targets in at least 20 foreign governments. One example being 95 gigabytes of immigration data from India, and 3 terabytes of call logs from South Korea’s LG U Plus telecoms provider. 

According to an assessment from SentinelOne, I-Soon utilises an array of hacking tools to gather intelligence, including methods to unearth identities on social media platforms and access emails, despite platforms like Facebook being inaccessible in China. Of particular concern are I-Soon’s sophisticated Remote Access Trojans (RATs) capable of infiltrating major operating systems, including Linux, Windows, macOS, iOS, and Android.

Most alarming is the revelation regarding the Android attack code, allegedly capable of extracting extensive messaging histories from Chinese chat applications and Telegram. The leaked documents also outline the use of hardware hacking devices by I-Soon, including a malicious power bank designed to surreptitiously upload data into victims’ systems.

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data