Shining Bangladesh Wednesday | 04 August 2021

Headline

Covid-19: 3rd vaccine consignment leaves Japan for Bangladesh Everyone to have an address: PM about housing for all

China accused of cyber-attack on Microsoft Exchange servers

Tech & IT desk || shiningbd

Published: 11:53, 20 July 2021  
China accused of cyber-attack on Microsoft Exchange servers

The attack affected about a quarter of a million Microsoft Exchange servers

The UK, US and EU have accused China of carrying out a major cyber-attack earlier this year.

The attack targeted Microsoft Exchange servers, affecting at least 30,000 organisations globally.

Western security services believe it signals a shift from a targeted espionage campaign to a smash-and-grab raid, leading to concerns Chinese cyber-behaviour is escalating.

The Chinese Ministry of State Security (MSS) has also been accused of wider espionage activity and a broader pattern of "reckless" behaviour.

China has previously denied allegations of hacking and says it opposes all forms of cyber-crime.

The unified call-out of Beijing shows the gravity with which this case has been taken. Western intelligence officials say aspects are markedly more serious than anything they have seen before.

It began in January when hackers from a Chinese-linked group known as Hafnium began exploiting a vulnerability in Microsoft Exchange. They used the vulnerability to insert backdoors into systems which they could return to later.

The UK said the attack was likely to enable large-scale espionage, including the acquisition of personal information and intellectual property.

It was mainly carried out against specific systems which aligned with Hafnium's previous targets, such as defence contractors, think tanks and universities.

"We believe that cyber-operators working under the control of Chinese intelligence learned about the Microsoft vulnerability in early January, and were racing to exploit the vulnerability before [it] was widely identified in the public domain," a security source told the BBC.

If this had been all, it would have been just another espionage operation. But in late February something significant changed.

 

Shiningbd/Mb