City
Epaper

China-backed hackers access US critical infra, ready for cyber attack

By IANS | Updated: February 8, 2024 11:00 IST

Washington, Feb 8 China-sponsored cyber actors have accessed IT networks for destructive cyber attacks against US critical infrastructure ...

Open in App

Washington, Feb 8 China-sponsored cyber actors have accessed IT networks for destructive cyber attacks against US critical infrastructure in the event of a major crisis or conflict with the country, a coalition of top intelligence agencies haswarned.

The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA) and Federal Bureau of Investigation (FBI) said that People’s Republic of China (PRC)-backed hackers are seeking to pre-position themselves on IT networks for disruptive or destructive cyber attacks as they have gained access for “at least five years”.

Volt Typhoon, a state-sponsored group of hackers based in China, has compromised the IT environments of multiple critical infrastructure organisations -- primarily in communications, energy, transportation systems and water and wastewater systems sectors -- in the US and its territories, the agencies said in a joint statement late on Wednesday.

The US agencies are concerned about the potential for these actors to use their network access for disruptive effects in the event of potential geopolitical tensions and/or military conflicts.

“Volt Typhoon’s choice of targets and pattern of behaviour is not consistent with traditional cyber espionage or intelligence gathering operations,” warned US agencies.

The agencies urge critical infrastructure organisations to apply the mitigations and to hunt for similar malicious activity.

"If an activity is identified, the authoring agencies strongly recommend that critical infrastructure organisations apply the incident response recommendations in the advisory and report the incident to the relevant agency,” said the agencies.

Last week, the FBI and US Department of Justice announced they had disrupted the “KV Botnet” run by Volt Typhoon that had compromised US-based routers for small businesses and home offices.

Volt Typhoon has been exploiting vulnerabilities in routers, firewalls and VPNs to gain initial access to critical infrastructure.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

InternationalIran FM Araghchi to hold talks with EAM Jaishankar in New Delhi on Thursday

CricketJemimah Rodrigues' record ton powers India Women to 23-run win over South Africa

Cricket"Pre-season camp in Dharamsala helping us," says PBKS Spin-bowling coach Sunil Joshi

CricketIPL 2025: Rahane, Russell shine as KKR powers to 179/6 in their 20 overs against CSK

NationalTelangana CM to lead rally to show solidarity with Indian Army tomorrow

Technology Realted Stories

TechnologyC-DOT, CSIR-NPL sign MoU to boost joint research in classical and quantum communications

TechnologyWorld's wealthiest 10pc contributing most to global warming than poorest 50pc: Study

TechnologyIndia-UK FTA bypasses China’s dependence, navigates US tariffs: SBI report

TechnologyStudy shows diabetes drug may help treat prostate cancer

TechnologyChinese ex-SK hynix worker sentenced to 5 years in prison for tech leak