Chinese Cybercriminals Allegedly Target Taiwanese Research Facility

A hacking collective, suspected of having ties to the Chinese government, has compromised login credentials and sensitive documents from a Taiwanese research facility associated with the government, according to cybersecurity experts from Cisco Systems.

The breach, which occurred as early as July 2023, involved the use of a specific type of malicious software tool predominantly associated with groups operating out of China, as detailed in a report from Cisco’s Talos threat intelligence team. Based on the methods used, Cisco estimates with “moderate confidence” that the attackers are affiliated with APT41, a state-sponsored espionage group linked to China’s Ministry of State Security.

This incident underscores the significant risks posed by suspected Chinese cyber operations to Taiwan, an island at the heart of growing tensions between the U.S. and China. Beijing asserts sovereignty over Taiwan and has pledged to unify it with the mainland, although it consistently denies involvement in cyberattacks.

Experts assert that cyberespionage has become a critical element of China’s strategic toolkit in its geopolitical endeavors. Recent disclosures reveal that hackers sponsored by China have targeted high-priority geopolitical assets.

In the attack on the Taiwanese research center, the intruders utilized an outdated version of Microsoft Office to facilitate and obscure their intrusion, noted Vitor Ventura, a researcher with Talos. The precise method of breach remains undetermined, and specifics about the amount of data stolen during the 11-day operation have not been disclosed. The facility’s identity remains undisclosed.

Last year, Google’s cybersecurity team reported a significant uptick in Chinese cyberattacks on Taiwan. In response, Taiwan has sought assistance from U.S. Treasury experts and American cybersecurity firms to bolster defenses against potential future assaults from Beijing.

APT41, the group implicated in the recent breach, is believed to be based in Chengdu, China. The group has been linked to various high-profile intrusions, including attacks on multiple U.S. state governments and the theft of tens of millions of dollars from U.S. COVID-19 relief funds. In 2020, a federal grand jury indicted individuals associated with APT41 for targeting over 100 victims.

More Articles & Posts