Arrest Of Intelligence Officer Sparks Fears Of Chinese Hacking Attack

Top figures in the infosec industry fear that the recent arrest of a top Chinese intelligence officer will spark an increase in cyber-attacks from Chinese hacking groups in the coming months.

These fears were expressed after the US Department of Justice announced the arrest and extradition of Yanjun Xu, a high-ranking director in China's Ministry of State Security (MSS), the country's counter-intelligence and foreign intelligence agency.

Xu was not arrested on hacking charges, but for attempting to commit economic espionage and steal trade secrets after trying to recruit several insiders from multiple US aviation and aerospace companies.

But reports from US cyber-security firm Recorded Future, and from shadowy group Intrusion Truth, have pegged the MSS as the Chinese agency in control of China's cyber-espionage operations.

"Currently, the Ministry of State Security (MSS) is the primary government agency engaged in the majority of cyber-attacks with Chinese-government nexus, and CrowdStrike has observed multiple intrusions demonstrating their sophisticated tradecraft," Dmitri Alperovitch, Co-Founder and CTO of US cyber-intelligence firm CrowdStrike, told ZDNet today.

Alperovitch now fears that this arrest might trigger a retaliatory action from Chinese hackers, an opinion also shared by former Facebook Chief Security Officer, Alex Stamos, and others.

For years, Chinese state-sponsored hackers have breached US companies and pilfered proprietary technology that mysteriously made its way into the hands of Chinese companies.

The two nations agreed to cease all hacking operations aimed at intellectual property (IP) theft in the autumn of 2015, when the countries' two presidents, US President Obama and Chinese President Xi, signed a political agreement on the matter.

A FireEye report released in June 2016 found that China's IP theft cyber operations had considerably wound down following the pact, and the country appeared to have stopped all major operations.

But this pact appears to have unofficially dissolved during the Trump presidency, as diplomatic relations broke down between the two countries, and a trade war is slowly unraveling today.

The Trump administration accused China in March of breaking the Obama-Xi hacking agreement. A US Department of the Treasury investigation detailed in a 215-page report listed several Chinese hacking operations that took place after the pact's signing.

In a report published today, CrowdStrike confirmed the US Treasury's findings. The company said it detected an uptick in Chinese hacking operations during the past year, uptick that placed China above Russia in terms of number of attacks.

"CrowdStrike can now confirm that China is back (after a big drop off in activity in 2016) to being the predominant nation-state intrusion threat in terms of volume of activity against Western industry," Alperovitch said in a tweet today, an opinion he also shared in an interview on Bloomberg TV. "MSS is now their [number one] cyber actor," he added.

Even if there is no evidence Xu was involved in China's cyber operations, it is now a general opinion among many infosec pundits that China does not abide by the terms of the Obama-Xi agreement anymore [1, 2], and the arrest of one of its top MSS directors would unleash hacking efforts on the same level as they were before the pact.

In comments provided to ZDNet, Alperovitch also hoped today's arrest would also serve as a deterrent.

Nonetheless, that might not be the case as the indictment of three Chinese nationals believed to be MSS hacking contractors last year, who were also involved in IP theft, didn't appear to stop Chinese cyber-espionage operations at all.

The Washington Post has more details on Xu's indictment and insider recruitment tactics, as well as how federal agents lured the top MSS official in Belgium, where they arrested him on April 1, this year.

ZDNet:

You Might Also read:

China Is 'biggest state sponsor of Cyber-Attacks on the West'

« Facebook Sued Over Video Viewing Figures
Amazon Scraps AI Recruiting Tool That Showed Bias Against Women »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

SANS Institute

SANS Institute

SANS is the most trusted and by far the largest source for information security training and security certification in the world.

Adeptis Group

Adeptis Group

Adeptis are experts in cyber security recruitment, providing bespoke staffing solutions to safeguard your organisation against ever-changing cyber threats.

Cybereason

Cybereason

Cybereason provides attack protection with cutting edge EDR and XDR, and industry recognized consulting services to support organizations throughout any stage of the incident lifecycle.

HID Global

HID Global

HID Global is a trusted leader in products, services and solutions related to the creation, management, and use of secure identities.

Giesecke+Devrient (G+D)

Giesecke+Devrient (G+D)

Giesecke+Devrient develop security technologies in four major areas: enabling secure payment, providing trusted connectivity, safeguarding identities and protecting digital infrastructures.

Telia Cygate

Telia Cygate

Cygate are specialists in information security, data networks, and data centre and cloud technologies.

AEI Cybersecurity

AEI Cybersecurity

AEI brings together companies, Research Centres, Universities, and other organizations interested in promoting new cybersecurity technologies.

Verafin

Verafin

Verafin is one of the North American leaders in fraud detection and AML software.

Netacea

Netacea

Netacea provides a revolutionary bot management solution that protects websites, mobile apps and APIs from malicious attacks such as scraping, credential stuffing and account takeover.

Cyrebro

Cyrebro

CYREBRO is your online cybersecurity central command managed SOC that integrates all your security events with strategic monitoring, proactive threat intelligence, and rapid incident response.

Hyperproof

Hyperproof

Hyperproof is a cloud-based compliance operations software. Launch new programs immediately, collect evidence automatically, and manage a compliance program intelligently.

Nuts Technologies

Nuts Technologies

Nuts Technologies are simplifying data privacy and encryption with our innovative and novel data containers we call nuts based on our Zero Trust Data framework.

Eventus Security

Eventus Security

Eventus, are a team of highly skilled professionals who are committed to deliver excellence in next generation cyber security services and customized solutions for your enterprise.

Centre for Cyber Security Research & Innovation

Centre for Cyber Security Research & Innovation

The Centre for Cyber Security Research & Innovation is Nepal's First Academic Research Institute to focus on understanding the overall Information Security of Nepalese Organizations.

Resillion

Resillion

Resillion (formerly Eurofins Digital Testing) is a global leader in quality engineering and cyber security services with operations in Europe, US, UK, India and China.

Cytex

Cytex

Cytex is the All-in-One solution for SMB data protection & compliance needs.