China is likely stockpiling and deploying vulnerabilities, says Microsoft
- Reference: 1667807765
- News link: https://www.theregister.co.uk/2022/11/07/china_stockpiles_vulnerabilities_microsoft_asserts/
- Source link:
China's [1]2021 law required organizations to report security vulnerabilities to local authorities before disclosing them to any other entity. The rules mean Beijing can use local research to hoard vulnerability information.
A year later, researchers from the Atlantic Council [2]found there was a decrease in reported vulnerabilities coming from China – and an increase in anonymous reports.
[3]
Microsoft's 2022 Digital Defense Report, released last Friday, asserts the Chinese law "might" be enabling the Chinese government to weaponize the vulnerabilities.
[4]
[5]
"The increased use of zero days over the last year from China-based actors likely reflects the first full year of China's vulnerability disclosure requirements for the Chinese security community and a major step in the use of zero-day exploits as a state priority," [6]said [PDF] Microsoft.
The company described China-based and -backed threat actors as "particularly proficient" when it comes to discovering and developing zero-day exploits.
[7]
Microsoft listed several vulnerabilities it said were first developed and deployed by Chinese actors before they were discovered and adopted by other attackers. Those attacks include [8]CVE-2021-35211 SolarWinds Serv-U , [9]CVE-2021-40539 Zoho ManageEngine ADSelfService Plus , CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus, [10]CVE-2021-42321 Microsoft Exchange , and [11]CVE-2022-26134 Confluence .
[12]China's infosec researchers obeyed Beijing and stopped reporting vulns … or did they?
[13]Atlassian: Unpatched years-old flaw under attack right now to hijack Confluence
[14]Zero-day proof-of-concept exploit lands for Windows make-me-admin vulnerability
[15]Chinese carriers collectively claim to have cracked a billion 5G subs
According to [16]Microsoft , China stepped up its espionage and information-stealing cyber attacks in order to counter the USA's attempts to increase its influence in Southeast Asia.
Microsoft detailed multiple examples of major known campaigns linked to various Chinese state-sponsored threat actors:
the targeting of 100 accounts affiliated with a prominent Southeast Asia intergovernmental organization by [17]Gallium as the org announced meetings between the US government and regional leaders;
Malware from Gadolinium on Solomon Islands government systems and malicious code from Radiumon in Papua New Guinea's telecommunications networks – both likely for intelligence collection purposes as Solomon Islands and China entered a military agreement;
Campaigns targeting nations across the global South in line with its Belt and Road Initiative, including Namibia, Mauritius, and Trinidad and Tobago, among others, even as China considers countries like Trinidad and Tobago important partners in the region.
The 114-page report detailed other tactics – such as China's participation in foreign propaganda operations, alongside Russia and Iran.
Microsoft credited Russia with increasing the number of cyber attacks targeting critical infrastructure from 20 percent of all nation-state attacks it detected in 2021 to 40 percent in 2022, with most attacks due to Russia relentlessly targeting Ukraine.
Iran also reacted to deteriorating geo-political relationships by launching campaigns against US port authorities, in addition to swipes at Israel and the EU.
Meanwhile North Korea continued to steal cryptocurrency from financial and tech companies while launching attacks on aerospace companies and researchers. The hermit kingdom also attempted to gain access to global news organizations. ®
Get our [18]Tech Resources
[1] https://www.theregister.com/2021/07/15/china_vulnerability_law/
[2] https://www.theregister.com/2022/09/27/atlantic_council_china_vuln_research/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2jlSw5vADMTgWfCL-hJWgAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2jlSw5vADMTgWfCL-hJWgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2jlSw5vADMTgWfCL-hJWgAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE5bUvv?culture=en-us&country=us
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2jlSw5vADMTgWfCL-hJWgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/11/10/stor_a_file_ransomware_attack_solarwinds_serv_u/
[9] https://www.theregister.com/2022/04/14/microsoft-tarrask-malware-in-windows/
[10] https://www.theregister.com/2021/11/09/microsoft_spreads_patch_tuesday_joy/
[11] https://www.theregister.com/2022/06/03/atlassian_confluence_critical_flaw_attacked/
[12] https://www.theregister.com/2022/09/27/atlantic_council_china_vuln_research/
[13] https://www.theregister.com/2022/06/03/atlassian_confluence_critical_flaw_attacked/
[14] https://www.theregister.com/2021/11/23/windows_lpe/
[15] https://www.theregister.com/2022/10/25/china_5g_carrier_subscriptions_data/
[16] https://blogs.microsoft.com/on-the-issues/2022/11/04/microsoft-digital-defense-report-2022-ukraine/
[17] https://www.theregister.com/2022/06/14/gallium-pingpull-rat/
[18] https://whitepapers.theregister.com/
How is that any different than what the NSA do with stuff like EternalBlue in which the vulnerability was not disclosed to Microsoft and ended up getting leaked by the Shadow Brokers?
I suspect that every developed nation is now using these tactics in their cyber warfare
It's a huge difference. The CCP has every Chinese IT worker bound by law to report vulnerabilities to them first. Nation state hacking teams number maybe a few thousand staff. For the last year, China has effectively had c. 5m working on it.
Cut them off at source
Perhaps Microsoft could stop manufacturing vulnerabilities in the first place?
They are not alone
> "might" be enabling the Chinese government to weaponize the vulnerabilities.
Presumably doing precisely what every other actor in the field of cyber espionage is doing. The only difference is that nobody is talking about what is happening behind the closed doors of western (and others) security services.
Microsoft said China is, "particularly proficient" when it comes to discovering and developing zero-day exploits.
Funny I always thought that Microsoft was developing the bugs without any help from China !
ALF
It's a case of supply and demand...
Redmond produces the shit (probably in HyrderaBAD) and the Chinese just cant enough of it.