TechCrunch News 01月04日
US sanctions Chinese cyber firm linked to Flax Typhoon hacks
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国政府因其与名为Flax Typhoon的中国政府支持的黑客组织有关联,对一家总部位于北京的网络安全公司实施制裁。美国财政部外国资产控制办公室(OFAC)宣布对诚信科技集团实施制裁,原因是该公司参与了“多起针对美国受害者的计算机入侵事件”,包括美国关键基础设施。诚信科技集团被指控运营一个与Flax Typhoon黑客组织相关的僵尸网络,该网络由超过26万个互联网连接设备组成,用于隐藏黑客活动。Flax Typhoon利用与诚信科技相关的基础设施,在2022年中期至2023年末期间入侵了多个美国和欧洲组织,包括美国大学、政府机构、电信供应商和媒体组织。

🌐美国财政部对诚信科技集团实施制裁,因其涉嫌参与针对美国关键基础设施的计算机入侵活动,并与Flax Typhoon黑客组织有关联。

💻诚信科技集团被指控运营一个由26万多个互联网连接设备组成的僵尸网络,该网络被Flax Typhoon黑客利用,以隐藏其入侵活动。

🎯Flax Typhoon黑客组织利用与诚信科技相关的基础设施,成功入侵了多个美国和欧洲组织,包括大学、政府机构、电信供应商和媒体组织。

🏛️美国财政部自身也遭受了网络攻击,并将其归咎于中国政府支持的黑客,这突显了美国国家安全面临的持续威胁。

The U.S. government has sanctioned a Beijing-based cybersecurity company over its alleged links to a China government-backed hacking group, tracked as Flax Typhoon.

The Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday announced the sanctions against the Integrity Technology Group for its role in “multiple computer intrusion incidents against U.S. victims,” including U.S. critical infrastructure.

The sanctions land months after the U.S. government accused Integrity Technology, also known as Yongxin Zhicheng, of running a botnet associated with the Flax Typhoon hacking group. 

The botnet, which was dismantled by the FBI in a court-authorized operation in September, was made up of more than 260,000 internet-connected devices, including cameras, storage devices, and routers, according to a joint advisory published by the FBI and the National Security Agency at the time. The agencies said the botnet had been operated and controlled by the Integrity Technology Group since 2021 to conceal the activities of the Flax Typhoon hackers. 

The Treasury said in its statement that Flax Typhoon used infrastructure linked to Integrity Tech to compromise multiple U.S. and European organizations between mid-2022 and late-2023. The hacking victims were not named, but the Treasury added that the China-backed hacking group compromised “multiple servers and workstations at a California-based entity.” 

According to a separate press release published by the U.S. Department of State on Friday, Flax Typhoon successfully targeted multiple U.S. universities, government agencies, telecommunications providers, and media organizations.

The new sanctions, which designate Integrity Tech as an organization involved in “malicious cyber-enabled activities,” come just days after the Treasury confirmed it was subject to a cyberattack in December that it attributed to China government-backed hackers. The hackers reportedly targeted the Treasury’s sanctions office, OFAC, during the intrusion, which gave the hackers remote access to Treasury employees and access to unclassified documents.

U.S. officials told The Washington Post that the intrusion may have given the hackers access to information about Chinese organizations that the U.S. government may be considering designating for financial sanctions.

A spokesperson for the Treasury did not return TechCrunch’s request for comment. In its statement Friday, the Treasury called Chinese malicious actors “one of the most active and most persistent threats” facing U.S. national security, referencing the targeting of the Treasury’s own IT infrastructure.

Integrity Tech, which is traded on the Shanghai Stock Exchange, did not respond to TechCrunch’s questions.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络安全 美国制裁 Flax Typhoon 中国黑客 僵尸网络
相关文章