Chinese hackers targeted Thailand, other SE Asian nations

Chinese hackers targeted Thailand, other SE Asian nations

FILE PHOTO: Prince, a member of the hacking group Red Hacker Alliance who refused to give his real name, uses his computer at their office in Dongguan, China's southern Guangdong province, Aug 4, 2020. Chinese hackers targeted Thailand and other Southeast Asian nations this year, a report says. (AFP)

Chinese hackers this year targeted military and civilian organisations in several Southeast Asian nations, particularly those with similar territorial claims or strategic infrastructure projects, suggesting the involvement of the state, a US-based cybersecurity firm said in new research released late Wednesday.


Malaysia, Indonesia and Vietnam were the top three targeted countries over the past nine months, said the Insikt Group, the threat research arm of Massachusetts-based Recorded Future. The hackers also took aim at several other countries, including the Philippines, Laos, Cambodia and Thailand, it said.


“The identified intrusion campaigns almost certainly support key strategic aims of the Chinese government, such as gathering intelligence on countries engaged in South China Sea territorial disputes or related to projects and countries strategically important to the Belt and Road Initiative (BRI),” Insikt Group said in its report.


The hackers focused on the offices of the Thai and Malaysian prime ministers, the foreign affairs ministries of Indonesia and Malaysia, as well as their militaries, it said. Insikt said it identified over 400 unique servers in Southeast Asia communicating with infected networks that were likely linked to Chinese state-sponsored actors, adding that it didn’t have any insight into the specific data that might have been obtained. The group attributed much of the activity to a Chinese state-sponsored entity it has labeled Threat Activity Group 16. 


“We also identified evidence suggesting that TAG-16 shares custom capabilities with the People’s Liberation Army (PLA)-linked activity group RedFoxtrot,” it said. Insikt said it notified a ..

Support the originator by clicking the read the rest link below.