U.S. says it broke up China-backed infrastructure hacking operation

The FBI Director accused the hackers of readying to “wreak havoc and cause real-world harm to American citizens and communities”

February 01, 2024 05:17 am | Updated 07:47 am IST - Washington

FBI Director Christopher Wray, testifies during a House Select Committee focusing on China on Capitol Hill.

FBI Director Christopher Wray, testifies during a House Select Committee focusing on China on Capitol Hill. | Photo Credit: AP

U.S. authorities said on January 31 that they had dismantled a network of hackers known as Volt Typhoon, which was targeting key American public sector infrastructure like water treatment plants and transportation systems at the behest of China.

FBI Director Christopher Wray explained the operation in testimony before a congressional committee on U.S.-China competition, and the Justice Department offered more details in a statement.

In May 2023, the United States and its allies had accused Volt Typhoon, described as a "state-sponsored hacking group" backed by China, of infiltrating critical U.S. infrastructure networks — claims rejected by Beijing.

"Just this morning, we announced an operation where we and our partners identified hundreds of routers that had been taken over by the PRC state-sponsored hacking group known as Volt Typhoon," Mr. Wray told lawmakers.

Also read: U.S., Microsoft warn Chinese hackers attacking ‘critical’ infrastructure

"The Volt Typhoon malware enabled China to hide, among other things, pre-operational reconnaissance and network exploitation against critical infrastructure like our communications, energy, transportation and water sectors."

Mr. Wray accused the hackers of readying to "wreak havoc and cause real-world harm to American citizens and communities."

"If and when China decides the time has come to strike, they're not focused just on political or military targets," he added. "Low blows against civilians are part of China's plan."

Assistant Attorney General Matthew Olsen, who works in the Justice Department's national security division, said access to U.S. infrastructure sought by Volt Typhoon was something China "would be able to leverage during a future crisis."

The U.S. operation to disrupt the hackers was authorized by a federal court in Texas, the Justice Department said in its statement.

By taking control of hundreds of routers, which were vulnerable as they were no longer supported by their maker's security patches or software updates, the hackers sought to disguise the origin of future China-based hacking activities, it said.

The operation succeeded in wiping the malware from the routers, without impacting their legitimate functions or collecting any information, it added, while saying there was no guarantee the routers could not be reinfected.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.