The Los Angeles Post
U.S. World Business Lifestyle
Today: April 10, 2025
Today: April 10, 2025

FBI says it has disrupted major Chinese hacking operation that threatened US critical infrastructure

FBI says it has disrupted major Chinese hacking operation that threatened US critical infrastructure
September 18, 2024
Sean Lyngaas - CNN

(CNN) โ€” The FBI has used a court order to seize control of a network of hundreds of thousands of hacked internet routers and other devices that Chinese government-linked hackers were using to threaten critical infrastructure in the US and overseas, FBI Director Christopher Wray said Wednesday.

โ€œIt is just one round in a much longer fight,โ€ Wray said in a speech at the Aspen Cyber Summit in Washington, DC. โ€œThe Chinese government is going to continue to target your organizations and our critical infrastructure.โ€

The massive web of hacked devices โ€” known as a botnet โ€” was a menace that the Chinese hackers could have used to conduct targeted cyberattacks on US companies or government agencies, according to an advisory released by the US and its โ€œFive Eyesโ€ allies (the English-speaking alliance that includes Australia, Canada, New Zealand and the United Kingdom). As of June, the botnet included over 260,000 hacked devices from all over the world, from North and South America to Australia, according to US officials. Those hacked devices ranged from webcams to DVRs to routers, and about half of them were located in the US, according to Wray.

A spokesperson for the Chinese Embassy in Washington called the US allegations โ€œgroundlessโ€ and accused the US government of conducting cyberattacks against China.

Itโ€™s the latest tit-for-tat in the often-tense relations between US and China in cyberspace. The US government has long warned that another Chinese government-backed hacking group has been lurking in US transportation and communication networks, waiting to use that access to disrupt any US response to a potential Chinese invasion of Taiwan.

That Chinese hacking unit is preparing to โ€œwreak havoc and cause real-world harmโ€ to the US, Wray told Congress in January.

A tool of choice

The botnet targeted by the FBI and its allies on Wednesday was an active menace, Wray said in his speech.

The botnet caused โ€œan all-hands-on deck cybersecurity incidentโ€ for one unnamed California-based organization, causing โ€œsignificant financial loss,โ€ the FBI director said.

But Wednesdayโ€™s takedown was more about what the botnet could have done than what it did. The army of zombie computers has been a quiet and looming threat to US government networks for many months, according to experts. In late December 2023, the botnetโ€™s operators โ€œconducted extensive scanning effortsโ€ of US military and other government agencies, according to US tech firm Lumen Technologies, which investigated the activity.

Botnets are a tool of choice for both cybercriminals and state-backed hackers because users around the world are often unaware that their computers have been hijacked for scamming or espionage. The FBI said in February that it had helped disrupt a network of over 1,000 hacked internet routers that Russiaโ€™s military intelligence agency was allegedly using for cyber espionage operations against the United States and its European allies.

The Chinese botnet targeted on Wednesday had an array of capabilities, including the ability to conducted tailored cyberattacks using the devices it had compromised, according to Lumen researchers.

Lumen researchers are watching for signs that the Chinese hackers will resurrect the botnet. But for now, โ€œwe assess that the botnet has been taken offline due to a combination of law enforcement efforts and null routing as of September 18,โ€ Danny Adamitis, principle information security engineer at Lumenโ€™s Black Lotus Labs threat intelligence division, told CNN.

Null routing is a process that internet technology providers can use to stop data from being sent to a specific IP address.

A Chinese company named Integrity Technology Group managed the botnet for the last three years, according to US officials. CNN has requested comment from the company.

The Chinese tech firm is โ€œinvolved in many of Chinaโ€™s most important programs and efforts to improve its hacking capabilities,โ€ Dakota Cary, a consultant at security firm SentinelOne who focuses on China, told CNN. โ€œThe naming of the company is significant as it demonstrates allied governmentsโ€™ visibility into Chinaโ€™s operations, as well as enabling researchers to further investigate the company.โ€

The-CNN-Wire
โ„ข & ยฉ 2024 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.

Related Articles

Apple appealing against UK 'back door' order, tribunal confirms Philippines alarmed over China arrest of alleged Filipino spies UK courts release new documents on Prince Andrewโ€™s relationship to alleged Chinese spy Trump fires NSA director in national security purge, sources say
Share This

Popular

Americas|Crime|Political|US|World

US-Russian dual national Ksenia Karelina is released in prisoner swap between Moscow and Washington

US-Russian dual national Ksenia Karelina is released in prisoner swap between Moscow and Washington
Crime|Europe|Political|World

Russian drone attack injures 12 in two Ukrainian cities, officials say

Russian drone attack injures 12 in two Ukrainian cities, officials say
Crime|US

An alternate theory, Amazon searches and a new tip: This is what we learned at the latest hearing in the Idaho killings case

An alternate theory, Amazon searches and a new tip: This is what we learned at the latest hearing in the Idaho killings case
Americas|Crime|Entertainment|Political|Sports|World

Officials scramble to identify victims of Dominican club roof collapse that killed at least 184

Officials scramble to identify victims of Dominican club roof collapse that killed at least 184

Technology

Political|Science|Technology|US

Options for Trump's space-based 'Golden Dome' missile defense shield head to Hegseth for approval

Options for Trump's space-based 'Golden Dome' missile defense shield head to Hegseth for approval
Business|Political|Technology|US

Trump says TikTok deal is still 'on the table'

Trump says TikTok deal is still 'on the table'
Political|Technology|Travel|US

US lawmakers press FAA on recent outages of pilot messaging database

US lawmakers press FAA on recent outages of pilot messaging database
Environment|Political|Technology|US

US EPA tracking card swipes and laptop logins to check staff office return, memo shows

US EPA tracking card swipes and laptop logins to check staff office return, memo shows