US disables Chinese hacking network Volt Typhoon targeting critical infrastructure: Sources
Sign up now: Get ST's newsletters delivered to your inbox
The use of so-called botnets by both government and criminal hackers to launder their cyber operations is not new.
PHOTO: ST FILE
Follow topic:
WASHINGTON - The US government in recent months launched an operation to fight a pervasive Chinese hacking operation that compromised thousands of Internet-connected devices, according to two Western security officials and one person familiar with the matter.
The Justice Department and Federal Bureau of Investigation (FBI) sought and received legal authorisation to remotely disable aspects of the Chinese hacking campaign, the sources told Reuters.
The Biden administration has increasingly focused on hacking, not only for fear nation states may try to disrupt the US presidential election in November, but because ransomware wreaked havoc on corporate America in 2023.
The hacking group at the centre of recent activity, Volt Typhoon, has especially alarmed intelligence officials who say it is part of a larger effort to compromise Western critical infrastructure, including naval ports, Internet service providers and utilities.
While the Volt Typhoon campaign
The widespread nature of the hacks led to a series of meetings between the White House and private technology industry, including several telecommunications and cloud commuting companies, where the US government asked for assistance in tracking the activity.
Such breaches could enable China, national security experts said, to remotely disrupt important facilities in the Indo-Pacific region that in some form support or service US military operations.
Sources said US officials are concerned the hackers were working to hurt US readiness in case of a Chinese invasion of Taiwan.
China, which claims democratically governed Taiwan as its own territory, has increased its military activities near the island in recent years in response to what Beijing calls “collusion” between Taiwan and the United States.
The Justice Department and FBI declined to comment. The Chinese embassy in Washington did not immediately respond to a request for comment.
When Western nations warned about Volt Typhoon in May, Chinese Foreign Ministry spokeswoman Mao Ning said the hacking allegations were a “collective disinformation campaign” from the Five Eyes countries, a reference to the intelligence-sharing grouping made up of Australia, Britain, Canada, New Zealand and the US.
Volt Typhoon has functioned by taking control of swathes of vulnerable digital devices around the world – such as routers, modems and even Internet-connected security cameras – to hide later, downstream attacks into more sensitive targets, security researchers told Reuters.
This constellation of remotely controlled systems, known as a botnet, is of primary concern to security officials because it limits the visibility of cyber defenders who monitor for foreign footprints in their computer networks.
“How it works is the Chinese are taking control of a camera or modem that is positioned geographically right next to a port or ISP (internet service provider) and then using that destination to route their intrusions into the real target,” said a former official familiar with the matter.
“To the information technology team at the downstream target, it looks just like a normal, native user that’s sitting nearby.”
The use of so-called botnets by both government and criminal hackers to launder their cyber operations is not new. The approach is often used when an attacker wants to quickly target numerous victims simultaneously or seeks to hide his origins. REUTERS

