News: 1626937209

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

China pushes back against Exchange attack sponsorship claims

(2021/07/22)


China has very firmly pushed back against the accusation it paid contractors to attack Microsoft's Exchange Server.

The USA, UK, NATO and other nations on Monday named China as the source of the attack.

On Tuesday, spokesperson for the Chinese Foreign Ministry, Zhao Lijian, responded to [1]accusations that China's Ministry of State Security launched a global cyber hacking campaign.

[2]

Zhao [3]said :

The US ganged up with its allies to make groundless accusations out of thin air against China on the cyber security issue. This act confuses right with wrong and smears and suppresses China out of political purpose. China will never accept this.

The spokesperson then accused the US of being the world's largest source of cyber attacks. He launched into statistics reported by China's National Computer Network Emergency Response Technical Team (CNCERT):

… about 52,000 malicious program command and control servers located outside China took control of about 5.31 million computer hosts in China in 2020. The US and two of its NATO allies are the top three in terms of the number of computers under their control in China.

In addition, 360's report also showed that APT-C-39, a cyber attack organization of the US Central Intelligence Agency, has carried out cyber infiltration and attacks on China for 11 years in key areas such as aerospace, science and research institutions, oil industry, large Internet companies and government agencies.

Zhao took to Twitter to further air his grievances:

The US is the world's top "hacking empire". It mustered allies to make groundless accusations against China on cybersecurity. By distorting facts, they aim to smear & suppress China to serve political purposes. We categorically reject their allegations. [4]pic.twitter.com/Np6qgjxFny — Lijian Zhao 赵立坚 (@zlj517) [5]July 20, 2021

Still hot under the collar during Wednesday's briefing with [6]more tweets to prove it, Zhao cited data that appears to come from CNCERT's China Internet Cyber Security Report 2020 dated June 2021 and [7]published online yesterday.

The spokesperson [8]claimed that 53 per cent of the 42 million malicious programs found in 2020 originated from the US. Then, for the second day in a row, he made a point of the United States’ penchant for wiretapping – not just its enemies but also its allies.

[9]

[10]

Zhao concluded that: "People can tell right from wrong. The US has not a shred of credibility left on the issue of cyber security, making whatever it says more than dubious."

The 248-page Mandarin-language CNCERT report's early pages claim a fall in cyber incidents across China during 2020.

[11]Miscreants started scanning for Exchange Hafnium vulns five minutes after Microsoft told world about zero-days

[12]Microsoft's GitHub under fire after disappearing proof-of-concept exploit for critical Microsoft Exchange vuln

[13]US National Security Council urges review of Exchange Servers in wake of Hafnium attack

For example, the document states the number of cases the organization handled fell by 4.2 per cent year-on-year. Implanted backdoors among Chinese web sites fell overall 37.3 per cent year-on-year and domestic government sites with backdoors fell even more – a whopping 64.3 per cent year-on-year. Tampered web sites decreased by 45.9 per cent year-on-year. DDoS attacks, total attack traffic and botnet control terminals all dropped year-on-year – 16.16 per cent, 19.67 per cent and 2.05 per cent respectively.

CNCERT is a non-governmental, non-profit organization that has put out an annual cyber security report on China since 2008. ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2021/07/19/hafnium_china_state_security/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPlBueJY2DM@wPaOaohbWgAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.fmprc.gov.cn/mfa_eng/xwfw_665399/s2510_665401/2511_665403/t1893769.shtml

[4] https://t.co/Np6qgjxFny

[5] https://twitter.com/zlj517/status/1417499859754442752?ref_src=twsrc%5Etfw

[6] https://twitter.com/zlj517/status/1417819030878969860

[7] https://www.cert.org.cn/publish/main/46/2021/20210721130944504525772/20210721130944504525772_.html

[8] https://www.fmprc.gov.cn/mfa_eng/xwfw_665399/s2510_665401/2511_665403/t1894104.shtml

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPlBueJY2DM@wPaOaohbWgAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPlBueJY2DM@wPaOaohbWgAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2021/05/19/hafnium_scans_5_mins_post_disclosure/

[12] https://www.theregister.com/2021/03/12/github_disappears_exploit/

[13] https://www.theregister.com/2021/03/08/us_national_security_council_says/

[14] https://whitepapers.theregister.com/



sitta_europea

In other news ... Teapot Calls Kettle Black!

lglethal

And have you, China, provided the addresses and details of these "American" miscreants to the relevant American authorities? I'm sure some of them are NSA or the like, but how many are just regular miscreants who have chosen not to p&ss in their own backyard (in order to avoid the local plod, like the Russian crews). I have no doubt the US would also like to collar those miscreants. It would be a nice little bit of publicity to say "See we're stopping our own miscreants! Now its time for Russian and China to do the same!". The Yanks are not going to avoid an opportunity like that, if you give them the details! So why havent you protected your citizens and handed over the details?

And having been provided with the details by the US, UK and EU of your Chinese miscreants have you acted against them?

Hmmm... Methinks he doth protest too much...

The opposite would have been so surprising

Potemkine!

"Yeah, we did it, and fuck the USA! "

The US has not a shred of credibility left on the issue of cyber security

Nor does China.

What did everyone expect?

Eclectic Man

Let me get this straight - everyone with the technical ability spies on everyone else, if they think they can get away with it?

Sounds about right. Plus

Everyone who is spied upon complains that this is aggressive and not fair.

Sounds about right too.

The USA, NATO etc complain about Russia, North Korea and the PRC using technology to enhance their 'intelligence gathering capabilities', while doing the exact same thing themselves. (If 'our lot' didn't they would have some serious questions to answer to the relevant government ministers and parliamentary select committees.)

There are spy agencies and criminals in all countries, some more effective than others, and some are probably difficult to tell apart. Forgive me but I am not entirely surprised.

Never ask the barber if you need a haircut.