Cybersecurity firm Area 1 defends pointing finger at China over European cables hack
Full article899 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The research has reignited a debate about attribution in infosec.
Chinese military hackers have used a persistent phishing campaign to steal thousands of European diplomatic cables on sensitive topics ranging from counterterrorism to technology exports, cybersecurity researchers charged Wednesday.
The years-long operation targeted over 100 organizations, including the United Nations and the AFL-CIO, according to Area 1, a California-based cybersecurity company.
The China’s People’s Liberation Army (PLA) was behind the effort, Area 1 said. The company did not list detailed forensic evidence linking the hack to the PLA, drawing criticism from other researchers as to why an attribution was made. But Area 1 defended its work, telling CyberScoop it had plenty of evidence of China’s role in the breach.
A spokesperson for the Chinese embassy in Washington, D.C., did not respond to a request for comment on the allegations. European Union officials said Wednesday that they were investigating the breach.
In an interview with CyberScoop, Area 1 co-founder Blake Darché said the company had solid evidence to attribute the activity to Chinese operatives, some of which was only released privately to Area 1 customers.
“We looked at IP addresses used, domain names registered by the attacker, and we were able to traces those pieces of information to certain geographic locations in China,” said Darché, a former National Security Agency official.
Juan Andres Guerrero-Saade, a researcher at Alphabet’s Chronicle, criticized what he called Area 1’s “unequivocal and unnuanced attribution statement” blaming the PLA for the hacking.
More importantly, what on earth is the justification for such an unequivocal and unnuanced attribution statement, signed by company senior management nonetheless? pic.twitter.com/B4MN8NbvQ5
— J. A. Guerrero-Saade (@juanandres_gs) December 19, 2018
But Darché argued that, in debates over attribution of cyber activity, outside observers will always call for more information that researchers don’t necessarily have to release.
“My customers have access to that information, I don’t have to publicize it,” he said.
The Area 1 report lays out the steps hackers took to gain access to victim networks, including the system that European Union officials use to communicate on foreign policy issues. After breaching the computer network of Cyprus’s Ministry of Foreign Affairs, the attackers used a command to reach a remote server that stored the diplomatic cables, according to the report.
The report describes Chinese government hacking as “technically unremarkable” and persistent rather than sophisticated. “Cyberattacks are more akin to an assembly line than to individual snowflakes,” says the report, which was first revealed in a story published Tuesday by The New York Times.
“This is a very cookie-cutter operation. Nothing is very customized here,” Darché told CyberScoop. “You don’t need custom tooling to cause a lot of damage.”
The attackers did use an implant known as PlugX to move through victim networks. That tool has been popular with Chinese hackers in recent years, though it is not exclusive to them, Darché said.
The New York Times story quotes from some of the 1,100 hacked cables Area 1 gave to the news outlet, leading some cybersecurity specialists to question why these revelations were being made in the press and not privately.
So a sec company found Chinese state actors had stolen classified diplomatic cables & the company decided to download all the data they knew to be stolen & send it to the press? Call me old fashioned but we used to avoid trafficking in stolen data & reported to victims, not press https://t.co/dRGnAzX5dc
— Artturi Lehtiö (@lehtior2) December 19, 2018
Darché said Area 1 notified victims of the hacking before publicly disclosing the campaign.
“As of very recently, we saw [the hackers] having access to that [EU network], which is why we took action to move people to start to address this problem,” Darché told CyberScoop.
Area 1, he added, gave The Times access to the hacked data in a “controlled environment” simply to provide context on the breach.
The research is a reminder of the scope and ambition of cyber-espionage campaigns, and comes amid mounting U.S. pressure on China for its alleged use of hacking to steal intellectual property.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/area-1-security-european-cable-hack-china-new-york-times/