Chinese cybersecurity experts have exposed a hacker group, with its core members coming from Europe and North America, which has been launching sustained cyberattacks against China as its primary target, posing a serious threat to the country’s cybersecurity and data security, the Global Times learned from a Beijing-based cybersecurity lab on Sunday.
(资料图片仅供参考)
In a report the Global Times obtained from Qi An Pangu lab, it revealed the hacking group, named Against The West (ATW), has claimed to have disclosed sensitive information including source code and database of important information systems related to China about more than 70 times since 2021, involving some 300 information systems of more than 100 important government agencies as well as aviation and infrastructure departments.
In particular, since 2022, ATW has intensified its momentum and continued to carry out large-scale scanning detection and “supply chain” attacks on Chinese networks, the report shows.
Through long-term tracking, cybersecurity experts from Qi An Pangu lab found that the active members of ATW are mainly engaged in programming and network engineer-related occupations and they are mainly located in Switzerland, France, Poland, Canada and other countries.
This is the second time that the lab revealed the true face of a hacker organization that has been carrying out data theft and network attacks on China, following the exposure of the complete technical detailsof Equation, an elite hacking group affiliated with the NSA, in February 2022. Equation was found to have been creating an advanced and covert backdoor, which has been used to monitor 45 countries and regions for over a decade.
According to the report, the ATW group was established in June 2021 and became active in online forums in October that year. Since its establishment, ATW has expressed a clear anti-China bias. It publicly stated that it would “publish posts about data leakage in China, North Korea and other countries.” It also published a special post entitled “ATW-War against China,” which explicitly supported “Taiwan independence,” advocated “Hong Kong independence” and hyped up “human rights issues” in China’s Xinjiang region.
Since October 2021, the organization has been active across overseas social media platforms, displaying a clear pro-US and pro-West slant. ATW has published several statements claiming that the organization’s targets are Russia, Belarus, China, Iran and North Korea and it is willing to share files with the US and the EU or hired by their related agencies.
According to incomplete statistics, since 2021, ATW has disclosed important information system source code, database and other sensitive information more than 70 times. The organization claimed that the data came from more than 100 Chinese departments, involving government agencies and state-owned enterprises.
For example, on January 7, 2022, ATW claimed to sell “a large amount of government, NGO, institutional and corporate data in China, involving 102 Chinese entities.”
However, experts from the lab found that the so-called source code is the test data or project code files developed by small and medium-sized software development enterprises. Experts also found that, in order to gain attention, ATW tends to distort and exaggerate its attacks.
The lab team identified six active members from the ATW, with three of them from France and one from Canada. One of the members Tillie Kottmann, born in Switzerland, was charged by the US Department of Justice in March 2021, but the case was abruptly suspended at the end of March. Since then, China has been one of Kottmann’s main targets, according to the lab report.
The organization mainly carried out large-scale scanning and attacks against technical vulnerabilities on SonarQube, Gogs, Gitblit and other open-source network systems. They would then steal related source code and data, which can be used to further exploit and penetrate the network information system.
"This is a typical ‘supply chain" attack," a senior cybersecurity expert from the lab told the Global Times on Sunday.
He suggested that software development enterprises should immediately repair software vulnerabilities, strictly control public network access permissions, and make timely modifications to default access passwords, and further improve the security management ability of source code.
As for the leakage of the system source code deployed in the user unit, the expert suggested that software development enterprises should strengthen the security audit of the system source code and encrypt and store the source code and data of important information systems.
"Cybersecurity-related government departments and technical teams should strengthen the monitoring of illegal cyberattack activities of the ATW organization, warn the trend of attack, and carry out background tracing and other countermeasures," the expert said.
关键词: China cyberattacks
【速看料】Hacker group with members from Europe, North America found to have launched cyberattacks against China Chinesecybersecurityexpertshaveexposedahackergroup,withitscoremembers
全球今头条!【写意中国探寻汉字起源】濮阳市南乐县仓颉文化博物馆:字圣故里讲好... 字圣牌坊摄影张雨晴国际在线河南频道消息(张雨晴):2月19日下午,“写意中国——探寻汉字起源”网络主题宣传活动采访团走进濮阳南乐县...
当前快报:【走进区域看发展】重庆渝中:全方位服务矩阵“引凤长栖” 新华网重庆2月20日电(记者陈硕)“对待园区企业,我们不止是‘保姆式’服务,更要有‘亲妈式’服务意识。”重庆数字经济产业园管理委员...
当前关注:【走进区域看发展】重庆两江新区:“产学研”协同,打造“五分钟科研生... 光明网讯(记者徐皓)毕业后走出校门,在工作中是否还可以体验“大学生活”?重庆市两江新区给出了肯定的答案。在这里,随着明月湖产学...
走进区域看发展|渝西水资源配置工程金刚沱泵站:一江碧水向西“流” 流入渝西千万家 雨水时节,江津区油溪镇金刚社区长江左岸,春雨淅淅沥沥。▲2月20日,江津区油溪镇,金刚沱泵站工程施工现场。记者崔力摄 视觉重庆2月2...
走进区域看发展丨“老街巷”变“新地标” 百年老街龙门浩焕发新活力 华龙网-新重庆客户端讯(记者张馨月)2月19日,“走进区域看发展川渝奋楫谱新篇”网上主题宣传采访团来到重庆南滨路龙门浩老街。漫步老...
聚链成群,锻造产业竞争新优势(经济大省勇挑大梁②)_环球头条 江苏省连云港市东方盛虹炼化一体化项目。连云港市徐圩新区供图核心阅读2022年,面对国内外多重超预期因素影响,江苏经济运行呈现持续恢复、回
打通壁垒,让智能家电更便利(微经济) 打通智能家电操作端口上的壁垒,让更多消费者享受科技带来的便利生活,智能家电领域也将迎来更广阔的发展空间远程操控的电饭锅、自动巡...
今日报丨【团结奋斗 忠诚履职】黄花春:让乡村孩子获得优质教育资源 央视网消息(新闻联播):黄花春是广西崇左市高级中学副校长,在一线教育岗位工作了20多年,如何让偏远地区的孩子享受到优质均衡的教育...
走村入户 探访民生(代表委员履职故事) 每日热门 连着几日升温,初春的雪刚刚开始融化,宁夏回族自治区吴忠市红寺堡区红寺堡镇玉池村的道路变得更加湿滑难走。全国人大代表、红寺堡区红...
观天下!佛山举行高考备考分析研讨会,推进育人方式变革、构建“五好教育”新形态 推进普通高中育人方式变革,答好高...
禅城石湾今明两天重启“游朱紫 大红大紫”岭南民俗活动 环球观焦点 二月二龙抬头,来美陶湾,感受千年...
强镇兴村富农!佛山云浮携手 书写乡村振兴优秀答卷 世界快报 投入各类资金6亿元,推动46个农业...
看热讯:南海区领导带队开展2023年南海“企业暖春”行动 佛山新闻网讯珠江时报记者吴玮琛刘...
东莞新型冠状病毒肺炎疫情:2月21日东莞疫情最新消息今天数据统计情况通报 东莞新型冠状病毒肺炎疫情:2月21日...
社保卡到期了需要换吗?社保卡到期换卡要手续费吗? 社保卡到期了需要换吗?社保卡到期...
全球快资讯丨故组词语的组词 1、故乡2、故宫3、故意4、故事5、...
【防弹少年团BTS田柾国JK】《原来是初恋》19 田柾国昨晚选择和你分开睡,你其实...