TechCrunch News 03月06日
Justice Department charges Chinese hackers-for-hire linked to Treasury breach
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国司法部宣布对12名与中国政府有关联的黑客提起刑事诉讼,指控他们在过去十年中入侵了包括美国财政部在内的100多家美国机构。这些黑客被指在中国“黑客雇佣”生态系统中扮演了关键角色,他们针对美国和全球的组织,目的是“压制言论自由和宗教自由”。其中两人与中国政府支持的黑客组织APT27有关联,他们涉嫌通过利用企业软件的安全漏洞,窃取受害者数据并出售给第三方,包括与中国政府有关联的实体。此外,司法部还起诉了中国政府黑客承包商I-Soon的八名员工,以及两名中国公安部官员,指控他们参与了从2016年到2023年的大规模黑客活动,获利数千万美元。美国国务院的“正义奖励计划”已宣布悬赏高达1000万美元,以获取有助于追踪I-Soon员工的信息。

🚨美国司法部起诉了12名与中国政府有关联的黑客,他们被控入侵了包括美国财政部在内的100多家美国机构,时间跨度长达十年。这些黑客的行为被认为是压制言论自由和宗教自由。

🧑‍💻其中两名被告Yin Kecheng和Zhou Shuai与中国政府支持的黑客组织APT27有关联,他们涉嫌自2013年以来进行多年的“以盈利为目的的计算机入侵活动”,通过利用微软Exchange、Palo Alto Networks防火墙、Citrix NetScaler设备和Ivanti Pulse Connect Secure设备中的漏洞,窃取数据并出售给第三方,包括与中国政府有关联的实体。

💰司法部还起诉了中国政府黑客承包商I-Soon的八名员工,包括其首席执行官和首席运营官,以及两名中国公安部官员。他们被控参与了从2016年到2023年的大规模黑客活动,获利数千万美元。I-Soon员工还被指控应中国安全机构的要求进行黑客攻击,以及在“自己主动”进行入侵后将窃取的数据出售给中国政府。

📢美国国务院的“正义奖励计划”已宣布悬赏高达1000万美元,以获取有助于追踪I-Soon员工的信息,并悬赏200万美元以获取导致逮捕和定罪Yin和Zhao的信息。

The Department of Justice has announced criminal charges against 12 Chinese government-linked hackers who are accused of hacking over 100 American organizations, including the U.S. Treasury, over the course of a decade.

The charged individuals all played a “key role” in China’s hacker-for-hire ecosystem, a senior DOJ official said on a background call with reporters, including TechCrunch, on Wednesday. The official added that those charged, which includes contract hackers and Chinese law enforcement officials, targeted organizations in the U.S. and worldwide for the purposes of “suppressing free speech and religious freedoms.”

The DOJ also confirmed that two of the indicted individuals are linked to the China government-backed hacking group APT27, or Silk Typhoon

The two individuals, named as Yin Kecheng and Zhou Shuai, are accused of carrying out “multi-year, for-profit computer intrusion campaigns” dating back to 2013. Prosecutors say these campaigns allowed the two individuals to steal data from victim organizations before selling that information to third parties, some of which had links to the Chinese government.

The two hackers gained access to victims’ networks by exploiting multiple security flaws in widely used enterprise software, according to the DOJ’s now-unsealed indictment. New research from Microsoft published on Wednesday confirms the hackers exploited flaws in Microsoft Exchange, Palo Alto Networks firewalls, Citrix NetScaler appliances, and Ivanti Pulse Connect Secure appliances as recently as January.

Organizations targeted by Yin and Zhou include U.S.-based technology companies, think tanks, law firms, defense contractors, local governments, health care systems, and universities, said U.S. prosecutors. 

Yin has also been linked to the recent widespread hack of the U.S. Treasury in December 2024. Yin was sanctioned by the Treasury Department’s Office of Foreign Assets Control in February after linking Yin to China’s Ministry of State Security (MSS), the intelligence agency responsible for the country’s foreign intelligence collection.

According to the DOJ, the FBI has seized the virtual private servers and other infrastructure used by Yin to carry out the hack on the U.S. Treasury. 

The Justice Department also on Wednesday announced charges against eight employees of Chinese government hacking contractor I-Soon, including its chief executive and chief operating officer, along with two alleged officers of China’s Ministry of Public Security, the government agency that oversees public policing in the country.

According to the DOJ, the I-Soon employees were involved in a widespread hacking campaign from 2016 to 2023, generating “tens of millions of dollars.” The I-Soon employees are also accused of carrying out hacks at the request of China’s security agencies, as well as carrying out intrusions on their “own initiative” before selling the stolen data to the Chinese government.

This hacking campaign saw the I-Soon employees target a number of U.S.-based organizations, prosecutors say, including a religious organization that was critical of the Chinese government, an organization focused on promoting religious freedoms in China, and several U.S. news organizations, the DOJ said.

Data stolen by Yin was also sold through I-Soon, prosecutors say, though it’s unclear if this includes data stolen during the breach at the U.S. Treasury.

The defendants remain at large. The U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information that helps to track down any employees of I-Soon. Separately, a reward of $2 million is being offered for information that leads to the arrest and conviction of Yin and Zhao. 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络安全 黑客攻击 美国司法部 中国 APT27
相关文章