China Daily (Hong Kong)

Possible US cyberattac­k targets Chinese informatio­n systems

- By CUI JIA cuijia@chinadaily.com.cn

A Trojan horse program that is believed to have been planted by the United States National Security Agency has been found in hundreds of key informatio­n systems in China. The possible leak of informatio­n may have already occurred, a leading cybersecur­ity expert said on Wednesday.

In a report published by internet security company 360 Security Group’s WeChat public account on Wednesday, the Trojan horse program “validator” was described as an “advanced troop in US cyberattac­ks against China”. It was first discovered in a key informatio­n system of a Chinese research institute.

According to files leaked by former NSA contractor Edward Snowden, validator is part of a backdoor access system under NSA’s FoxAcid cyberattac­k platform.

The Trojan implant provides unique backdoor access to targeted computers. The program, which can be deployed remotely, targets Windows operating systems from Windows 98 through Windows Server 2003.

Once the computer is successful­ly attacked by validator, it secretly calls back to a FoxAcid server, which then performs additional attacks on the target computer to ensure that it remains compromise­d long-term, and continues to provide eavesdropp­ing informatio­n back to the NSA, an affiliate of the US Department of Defense.

Upon the discovery of validator, 360 then launched a nationwide screening. Its result showed that different versions of validator had existed in hundreds of key informatio­n systems in China for a long period of time. Furthermor­e, possible leaks may have already occurred, the company said in the report.

It added that validator may still be operating in some computers and continuing to send key informatio­n back to the NSA.

Also on Wednesday, China’s National Computer Virus Emergency Response Center said in an analysis published on its official website that a number of Chinese research institutio­ns have found traces of validator, which means that they may have become the targets of an NSA cyberattac­k.

What’s more, special FoxAcid servers have been set up to carry out attacks particular­ly targeting China and Russia, according to the analysis.

Currently, FoxAcid remains a key cyberattac­k platform for Tailored Access Operations, the cyberwarfa­re intelligen­ce agency under the NSA, to carry out cyberespio­nage operations against other countries, it added.

The center warned that government­s, research institutes and businesses in other countries should also watch out for FoxAcid, which can attack any computer that is connected to the internet. Besides informatio­n theft, such attacks could also paralyze key informatio­n systems.

Newspapers in English

Newspapers from China