<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hackers &#8211; Asia Pacific Report</title>
	<atom:link href="https://asiapacificreport.nz/tag/hackers/feed/" rel="self" type="application/rss+xml" />
	<link>https://asiapacificreport.nz</link>
	<description>Independent Asia Pacific news and analysis</description>
	<lastBuildDate>Fri, 26 May 2023 12:33:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Highly secretive Five Eyes alliance disrupts China-backed hacker group</title>
		<link>https://asiapacificreport.nz/2023/05/27/highly-secretive-five-eyes-alliance-disrupts-china-backed-hacker-group/</link>
		
		<dc:creator><![CDATA[APR editor]]></dc:creator>
		<pubDate>Fri, 26 May 2023 12:33:12 +0000</pubDate>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Australia]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Guam]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[Pacific Report]]></category>
		<category><![CDATA[Philippines]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Taiwan]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cyber attacks]]></category>
		<category><![CDATA[Cyber operations]]></category>
		<category><![CDATA[Digital data]]></category>
		<category><![CDATA[Digital platforms]]></category>
		<category><![CDATA[Five Eyes]]></category>
		<category><![CDATA[Guam military]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Intelligence agencies]]></category>
		<category><![CDATA[Secrecy]]></category>
		<category><![CDATA[South China Sea]]></category>
		<category><![CDATA[US intelligence]]></category>
		<category><![CDATA[US National Security Agency]]></category>
		<category><![CDATA[Volt Typhoon]]></category>
		<category><![CDATA[Western Pacific]]></category>
		<guid isPermaLink="false">https://asiapacificreport.nz/?p=88945</guid>

					<description><![CDATA[ANALYSIS: By Dennis B. Desmond, University of the Sunshine Coast This week the Five Eyes alliance &#8212; an intelligence alliance between Australia, the United Kingdom, Canada, New Zealand and the United States &#8212; announced its investigation into a China-backed threat targeting US infrastructure. Using stealth techniques, the attacker &#8212; referred to as “Volt Typhoon” &#8212; ]]></description>
										<content:encoded><![CDATA[<p><strong>ANALYSIS:</strong> <em>By <a href="https://theconversation.com/profiles/dennis-b-desmond-1252874">Dennis B. Desmond</a>, <a href="https://theconversation.com/institutions/university-of-the-sunshine-coast-1068">University of the Sunshine Coast</a></em></p>
<p>This week the Five Eyes alliance &#8212; an intelligence alliance between Australia, the United Kingdom, Canada, New Zealand and the United States &#8212; <a href="https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF">announced its investigation</a> into a China-backed threat targeting US infrastructure.</p>
<p>Using stealth techniques, the attacker &#8212; referred to as “Volt Typhoon” &#8212; exploited existing resources in compromised networks in a technique called “<a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3406058/nsa-and-partners-identify-china-state-sponsored-cyber-actor-using-built-in-netw/">living off the land</a>”.</p>
<p>Microsoft made a concurrent <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/">announcement</a>, stating the attackers’ targeting of Guam was telling of China’s plans to potentially disrupt critical communications infrastructure between the US and Asia region in the future.</p>
<ul>
<li><strong><a href="https://theconversation.com/deterring-china-isnt-all-about-submarines-australias-cyber-offence-might-be-its-most-potent-weapon-204749">READ MORE: </a></strong><a href="https://theconversation.com/deterring-china-isnt-all-about-submarines-australias-cyber-offence-might-be-its-most-potent-weapon-204749">Deterring China isn&#8217;t all about submarines. Australia&#8217;s &#8216;cyber offence&#8217; might be its most potent weapon</a></li>
</ul>
<p>This comes hot on the heels <a href="https://www.nknews.org/pro/how-new-us-cybersecurity-task-force-can-effectively-target-north-korean-hackers/">of news</a> in April of a North Korean supply chain attack on Asia-Pacific telecommunications provider 3CX. In this case, hackers gained access to an employee’s computer using a compromised desktop app for Windows and a compromised signed software installation package.</p>
<p>The Volt Typhoon announcement has led to a rare admission by the US National Security Agency that Australia and other Five Eyes partners are engaged in a targeted search and detection scheme to uncover China’s clandestine cyber operations.</p>
<p>Such public admissions from the Five Eyes alliance are few and far between. Behind the curtain, however, this network is persistently engaged in trying to take down foreign adversaries. And it’s no easy feat.</p>
<p>Let’s take a look at the events leading up to Volt Typhoon &#8212; and more broadly at how this secretive transnational alliance operates.</p>
<p><strong>Uncovering Volt Typhoon<br />
</strong>Volt Typhoon is an “advanced persistent threat group” that has been active since at least mid-2021. It’s believed to be sponsored by the Chinese government and is targeting critical infrastructure organisations in the US.</p>
<p>The group has focused much of its efforts on Guam. Located in the Western Pacific, this US island territory is home to a significant and growing US military presence, including the air force, a contingent of the marines, and the US navy’s nuclear-capable submarines.</p>
<p>It’s likely the Volt Typhoon attackers intended to gain access to networks connected to US critical infrastructure to disrupt communications, command and control systems, and maintain a persistent presence on the networks.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">Volt Typhoon is the name Microsoft and the Five Eyes intelligence agencies have given a Chinese state sponsored hacking group, which they say installed a mysterious code in Guam&#8217;s telecommunications systems. <a href="https://t.co/xEwith7ZmM">https://t.co/xEwith7ZmM</a></p>
<p>— RN Breakfast (@RNBreakfast) <a href="https://twitter.com/RNBreakfast/status/1661843955909275648?ref_src=twsrc%5Etfw">May 25, 2023</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>The latter tactic would allow China to influence operations during a potential conflict in the South China Sea.</p>
<p>Australia wasn’t directly impacted by Volt Typhoon, according to official statements. Nevertheless, it would be a primary target for similar operations in the event of conflict.</p>
<p>As for how Volt Typhoon was caught, this hasn’t been disclosed. But Microsoft documents highlight previous observations of the threat actor attempting to dump credentials and stolen data from the victim organisation. It’s likely this led to the discovery of compromised networks and devices.</p>
<p><strong>Living-off-the-land<br />
</strong>The hackers initially gained access to networks through internet-facing Fortinet FortiGuard devices, such as routers. Once inside, they employed a technique called “living-off-the-land”.</p>
<p>This is when attackers rely on using the resources already contained within the exploited system, rather than bringing in external tools. For example, they will typically use applications such as PowerShell (a Microsoft management programme) and Windows Management Instrumentation <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/">to access</a> data and network functions.</p>
<p>By using internal resources, attackers can bypass safeguards that alert organisations to unauthorised access to their networks. Since no malicious software is used, they appear as a legitimate user.</p>
<p>As such, living-off-the-land allows for lateral movement within the network, and provides opportunity for a persistent, long-term attack.</p>
<p>The simultaneous announcements from the Five Eyes partners points to the seriousness of the Volt Typhoon compromise. It will likely serve as a warning to other nations in the Asia-Pacific region.</p>
<p><strong>Who are the Five Eyes?<br />
</strong><a href="https://www.theguardian.com/world/2013/dec/02/history-of-5-eyes-explainer">Formed in 1955</a>, the Five Eyes alliance is an intelligence-sharing partnership comprising Australia, Canada, New Zealand, the UK and the US.</p>
<p>The alliance was formed after World War II to counter the potential influence of the Soviet Union. It has a specific focus on signals intelligence. This involves intercepting and analysing signals such as radio, satellite and internet communications.</p>
<p>The members share information and access to their respective signals intelligence agencies, and collaborate to collect and analyse vast amounts of global communications data. A Five Eyes operation might also include intelligence provided by non-member nations and the private sector.</p>
<p>Recently, the member countries expressed concern about China’s de facto military control <a href="https://theconversation.com/explainer-why-is-the-south-china-sea-such-a-hotly-contested-region-143435">over the South China Sea</a>, its suppression of <a href="https://theconversation.com/china-is-taking-a-risk-by-getting-tough-on-hong-kong-now-the-us-must-decide-how-to-respond-139294">democracy in Hong Kong</a>, and threatening moves towards Taiwan.</p>
<p>The latest public announcement of China’s cyber operations no doubt serves as a warning that Western nations are paying strict attention to their critical infrastructure &#8212; and can respond to China’s digital aggression.</p>
<p>In 2019, Australia was <a href="https://theconversation.com/a-state-actor-has-targeted-australian-political-parties-but-that-shouldnt-surprise-us-111997">targeted</a> by Chinese state-backed threat actors gaining unauthorised access to Parliament House’s computer network. Indeed, there is evidence that China is engaged in a concerted <a href="https://theconversation.com/australia-is-under-sustained-cyber-attack-warns-the-government-whats-going-on-and-what-should-businesses-do-141119">effort to target</a> Australia’s public and private networks.</p>
<p>The Five Eyes alliance may well be one of the only deterrents we have against long-term, persistent attacks against our critical infrastructure.</p>
<p><!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img decoding="async" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" src="https://counter.theconversation.com/content/206403/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --><br />
<em><a href="https://theconversation.com/profiles/dennis-b-desmond-1252874">Dennis B. Desmond</a> is a lecturer, Cyberintelligence and Cybercrime Investigations, <em><a href="https://theconversation.com/institutions/university-of-the-sunshine-coast-1068">University of the Sunshine Coast</a></em>. This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons licence. Read the <a href="https://theconversation.com/the-highly-secretive-five-eyes-alliance-has-disrupted-a-china-backed-hacker-group-in-an-unusually-public-manner-206403">original article</a>.</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Calling out China for cyberattacks is risky — but a lawless digital world is even riskier</title>
		<link>https://asiapacificreport.nz/2021/07/21/calling-out-china-for-cyberattacks-is-risky-but-a-lawless-digital-world-is-even-riskier/</link>
		
		<dc:creator><![CDATA[APR editor]]></dc:creator>
		<pubDate>Tue, 20 Jul 2021 23:08:03 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Democracy]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Global]]></category>
		<category><![CDATA[Human Rights]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[Pacific Report]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Science-Technology]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Syndicate]]></category>
		<category><![CDATA[Australia]]></category>
		<category><![CDATA[Cyber attacks]]></category>
		<category><![CDATA[Cyber security]]></category>
		<category><![CDATA[Cyber-crime laws]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Digital disruption]]></category>
		<category><![CDATA[GCSB]]></category>
		<category><![CDATA[Government Communications Security Bureau]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Weapons of mass destruction]]></category>
		<category><![CDATA[WMD]]></category>
		<guid isPermaLink="false">https://asiapacificreport.nz/?p=60732</guid>

					<description><![CDATA[ANALYSIS: By Alexander Gillespie, University of Waikato The multi-country condemnation of cyber-attacks by Chinese state-sponsored agencies is a sign of increasing frustration at recent behaviour. But it also masks the real problem — international law isn’t strong or coherent enough to deal with this growing threat. The coordinated announcement by several countries, including the US, ]]></description>
										<content:encoded><![CDATA[<p><strong>ANALYSIS:</strong> <em>By <a href="https://theconversation.com/profiles/alexander-gillespie-721706">Alexander Gillespie</a>, <a href="https://theconversation.com/institutions/university-of-waikato-781">University of Waikato</a></em></p>
<p>The multi-country <a href="https://www.rnz.co.nz/news/political/447239/government-points-finger-at-china-over-cyber-attacks">condemnation of cyber-attacks</a> by Chinese state-sponsored agencies is a sign of increasing frustration at recent behaviour. But it also masks the real problem — international law isn’t strong or coherent enough to deal with this growing threat.</p>
<p>The coordinated announcement by several countries, including the US, UK, Australia and New Zealand, echoes the most <a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2021-Unclassified-Report.pdf">recent threat assessment</a> from the US intelligence community: cyber threats from nation states and their surrogates will remain acute for the foreseeable future.</p>
<p>Joining the chorus against China may be <a href="https://www.rnz.co.nz/news/national/447255/nz-in-position-of-vulnerability-over-china-hacking-accusations">diplomatically risky</a> for New Zealand and others, and China has already described the claims as “groundless and irresponsible”. But there is no doubt the problem is real.</p>
<ul>
<li><strong><a href="https://theconversation.com/with-cyberattacks-growing-more-frequent-and-disruptive-a-unified-approach-is-essential-162219">READ MORE: </a></strong><a href="https://theconversation.com/with-cyberattacks-growing-more-frequent-and-disruptive-a-unified-approach-is-essential-162219">With cyberattacks growing more frequent and disruptive, a unified approach is essential</a></li>
<li><a href="https://theconversation.com/improving-cybersecurity-means-understanding-how-cyberattacks-affect-both-governments-and-civilians-163261">Improving cybersecurity means understanding how cyberattacks affect both governments and civilians</a></li>
<li><a href="https://theconversation.com/ransomware-data-breach-cyberattack-what-do-they-have-to-do-with-your-personal-information-and-how-worried-should-you-be-162404">Ransomware, data breach, cyberattack: What do they have to do with your personal information, and how worried should you be?</a><em><strong><br />
</strong></em></li>
<li><a href="https://theconversation.com/cyber-cold-war-the-us-and-russia-talk-tough-but-only-diplomacy-will-ease-the-threat-163171">Cyber Cold War? The US and Russia talk tough, but only diplomacy will ease the threat</a></li>
</ul>
<p>The latest <a href="https://www.gcsb.govt.nz/assets/GCSB-Annual-Reports/2020-GCSB-Annual-Report.pdf">report</a> from New Zealand’s Government Communications Security Bureau (GCSB) recorded 353 cyber security incidents in the 12 months to the middle of 2020, compared with 339 incidents in the previous year.</p>
<p>Given the focus is on potentially high-impact events targeting organisations of national significance, this is likely only a small proportion of the total. But the GCSB estimated state-sponsored attacks accounted for up to 30 percent of incidents recorded in 2019-20.</p>
<p>Since that report, more serious incidents have occurred, including attacks on the <a href="https://www.bbc.com/news/53918580">stock-exchange</a> and <a href="https://www.stuff.co.nz/national/health/125235676/waikato-dhb-scrambles-to-contain-cyber-attack-safety-of-patient-data-unclear">Waikato hospital</a>. The attacks are becoming <a href="https://www.rnz.co.nz/national/programmes/checkpoint/audio/2018802677/gcsb-boss-warns-cyber-attacks-getting-more-sophisticated">more sophisticated</a> and inflicting greater damage.</p>
<p>Globally, there are warnings that a major cyberattack could be as deadly as a <a href="https://www.sciencealert.com/a-major-cyber-attack-could-be-just-as-damaging-as-a-nuclear-weapon">weapon of mass destruction</a>. The need to de-escalate is urgent.</p>
<p><strong>Global solutions missing<br />
</strong>New Zealand would be relatively well-prepared to cope with domestic incidents using <a href="https://www.legislation.govt.nz/act/public/1961/0043/latest/DLM330415.html?search=sw_096be8ed81a1107c_cyber_25_se&amp;p=1">criminal</a>, <a href="https://www.legislation.govt.nz/act/public/2020/0031/latest/LMS23223.html">privacy</a> and even <a href="https://www.legislation.govt.nz/act/public/2015/0063/latest/whole.html">harmful digital communications</a> laws. But most cybercrime originates overseas, and global solutions don’t really exist.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">The government says it has uncovered evidence of Chinese state-sponsored cyber attacks in New Zealand.<a href="https://t.co/wB5Q8M4lwO">https://t.co/wB5Q8M4lwO</a></p>
<p>— RNZ (@radionz) <a href="https://twitter.com/radionz/status/1417183449845157911?ref_src=twsrc%5Etfw">July 19, 2021</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>In theory, the attacks can be divided into two types — those by criminals and those by foreign governments. In reality, the line between the two is blurred.</p>
<p>Dealing with foreign criminals is slightly easier than combating attacks by other governments, and Prime Minister Jacinda Ardern has recognised the need for a <a href="https://www.stuff.co.nz/national/politics/125470096/prime-minister-jacinda-ardern-says-global-effort-needed-to-confront-cyber-attacks">global effort</a> to fight this kind of cybercrime.</p>
<p>To that end, the government recently announced <a href="https://www.beehive.govt.nz/release/new-zealand-join-council-europe-convention-cybercrime">New Zealand was joining</a> the <a href="https://rm.coe.int/CoERMPublicCommonSearchServices/DisplayDCTMContent?documentId=0900001680081561">Council of Europe’s Convention on Cybercrime</a>, a global regime signed by <a href="https://www.coe.int/en/web/cybercrime/parties-observers">66 countries</a> based on shared basic legal standards, mutual assistance and extradition rules.</p>
<p>Unfortunately, some of the countries most often suspected of allowing international cybercrime to be committed from within their borders have not signed, meaning they are not bound by its obligations.</p>
<p>That includes Russia, China and North Korea. Along with several other countries <a href="https://www.hrw.org/news/2021/01/19/proposed-un-cybercrime-treaty-could-undermine-human-rights">not known for their tolerance</a> of an <a href="https://www.cfr.org/blog/new-un-cybercrime-treaty-way-forward-supporters-open-free-and-secure-internet">open, free and secure</a> internet, they are trying to create an alternative international cybercrime regime, now entering a <a href="https://www.un.org/press/en/2021/ga12328.doc.htm">drafting process through the United Nations</a>.</p>
<blockquote class="twitter-tweet">
<p dir="ltr" lang="en">&#8216;Groundless, irresponsible&#8217;: China fires back at NZ after cyber attack accusation <a href="https://t.co/oGSOMtFdXT">https://t.co/oGSOMtFdXT</a></p>
<p>— Newshub Politics (@NewshubPolitics) <a href="https://twitter.com/NewshubPolitics/status/1417257839077203974?ref_src=twsrc%5Etfw">July 19, 2021</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p><strong>Cyberattacks as acts of war<br />
</strong>Dealing with attacks by other governments (as opposed to criminals) is even harder.</p>
<p>Only broad principles exist, including that countries <a href="https://legal.un.org/repertory/art2/english/rep_supp7_vol1_art2_4.pdf">refrain from the threat or use of force</a> against the territorial integrity or political independence of any state, and that they should <a href="https://www.un.org/ruleoflaw/files/3dda1f104.pdf">behave in a friendly</a> way towards one another. If one is attacked, it has an inherent <a href="https://www.un.org/en/about-us/un-charter/full-text">right of self-defence</a>.<em><br />
</em></p>
<p>Malicious state-sponsored cyber activity involving espionage, ransoms or breaches of privacy might qualify as unfriendly and in bad faith, but they are not acts of war.</p>
<p>However, cyberattacks directed by other governments could amount to acts of war if they cause death, serious injury or significant damage to the targeted state. Cyberattacks that meddle in foreign elections may, depending on their impact, dangerously undermine peace.</p>
<p>And yet, despite these extreme risks, there is no international convention governing state-based cyberattacks in the ways the <a href="https://www.icrc.org/en/doc/war-and-law/treaties-customary-law/geneva-conventions/overview-geneva-conventions.html">Geneva Conventions</a> cover the rules of warfare or <a href="https://www.armscontrol.org/treaties">arms control conventions</a> limit weapons of mass destruction.</p>
<figure style="width: 600px" class="wp-caption alignnone"><img fetchpriority="high" decoding="async" src="https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip" sizes="(min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" srcset="https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=1 600w, https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=2 1200w, https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=3 1800w, https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;h=503&amp;fit=crop&amp;dpr=1 754w, https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=754&amp;h=503&amp;fit=crop&amp;dpr=2 1508w, https://images.theconversation.com/files/412034/original/file-20210720-21-13uy45q.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=754&amp;h=503&amp;fit=crop&amp;dpr=3 2262w" alt="Vladimir Putin shaking hands with Joe Biden" width="600" height="400" /><figcaption class="wp-caption-text">Drawing a red line on cybercrime &#8230; US President Joe Biden meets Russian President Vladimir Putin in Geneva in June. Image: The Conversation/GettyImages</figcaption></figure>
<p><strong>Risks of retaliation<br />
</strong>The latest condemnation of Chinese-linked cyberattacks notwithstanding, the problem is not going away.</p>
<p>At their recent meeting in Geneva, US President Joe Biden told his Russian counterpart, Vladimir Putin, the US would <a href="https://www.theguardian.com/us-news/2021/jun/16/biden-to-meet-putin-at-highly-anticipated-summit-in-geneva">retaliate</a> against any attacks on its <a href="https://www.cisa.gov/critical-infrastructure-sectors">critical infrastructure</a>. A new US agency aimed at countering ransomware attacks would respond in “<a href="https://thehill.com/policy/cybersecurity/563121-biden-administration-stepping-up-efforts-to-respond-to-ransomware">unseen and seen ways</a>”, according to the administration.</p>
<p>Such responses would be legal under international law if there were no alternative means of resolution or reparation, and could be argued to be necessary and proportionate.</p>
<p>Also, the response can be unilateral or collective, meaning the US might call on its friends and allies to help. New Zealand has said it is <a href="https://dpmc.govt.nz/publications/application-international-law-state-activity-cyberspace">open to the proposition</a> that victim states can, in limited circumstances, request assistance from other states to apply proportionate countermeasures against someone acting in breach of international law.</p>
<p><strong>A drift towards lawlessness<br />
</strong>But only a month after Biden drew his red line with Putin, <a href="https://edition.cnn.com/2021/07/02/tech/ransomware-cybersecurity-attack-kaseya/index.html">another massive ransomware attack</a> crippled hundreds of service providers across <a href="https://www.nzherald.co.nz/world/scale-details-of-massive-kaseya-ransomware-attack-emerge/KWI34JA7GV6U3VHU4X66ZCXT6M/">17 countries</a>, including New Zealand <a href="https://www.rnz.co.nz/news/national/446225/kaseya-ransomware-attack-hits-new-zealand-kindergartens">schools and kindergartens</a>.</p>
<p>The Russian-affiliated ransomware group REvil that was probably behind the attacks mysteriously <a href="https://edition.cnn.com/2021/07/13/tech/revil-ransomware-disappears/index.html">disappeared</a> from the internet a few weeks later.</p>
<p>Things are moving fast and none of it is very reassuring. In an interconnected world facing a growing threat from cyberattacks, we appear to be drifting away from order, stability and safety and towards the darkness of increasing lawlessness.</p>
<p>The coordinated condemnation of China by New Zealand and others has considerably upped the ante. All parties should now be seeking a rules-based international solution or the risk will only grow.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img decoding="async" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important; text-shadow: none !important;" src="https://counter.theconversation.com/content/164771/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>
<p><em>Dr <a href="https://theconversation.com/profiles/alexander-gillespie-721706">Alexander Gillespie</a> is professor of law, <a href="https://theconversation.com/institutions/university-of-waikato-781">University of Waikato</a>. This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons licence. Read the <a href="https://theconversation.com/calling-out-china-for-cyberattacks-is-risky-but-a-lawless-digital-world-is-even-riskier-164771">original article</a>.</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NZ cyber agency chief worried China hacks exploiting security weakness</title>
		<link>https://asiapacificreport.nz/2021/07/20/nz-cyber-agency-chief-worried-china-hacks-exploiting-nz-security/</link>
		
		<dc:creator><![CDATA[APR editor]]></dc:creator>
		<pubDate>Tue, 20 Jul 2021 11:13:17 +0000</pubDate>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Global]]></category>
		<category><![CDATA[Human Rights]]></category>
		<category><![CDATA[Multimedia]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[Pacific Report]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[RNZ Pacific]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Syndicate]]></category>
		<category><![CDATA[Cyber attacks]]></category>
		<category><![CDATA[Cyber security]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[GCSB]]></category>
		<category><![CDATA[Government Communications Security Bureau]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Hacking]]></category>
		<guid isPermaLink="false">https://asiapacificreport.nz/?p=60709</guid>

					<description><![CDATA[RNZ News New Zealand&#8217;s cyber security agency believes China has been behind numerous hack attacks spanning years. The government joined Western allies and Japan in calling out Beijing for so-called state-sponsored hacks, including a major incursion in February when Microsoft email servers were targeted. The US has charged four Chinese nationals &#8212; three security officials ]]></description>
										<content:encoded><![CDATA[<p><a href="https://www.rnz.co.nz/national/programmes/checkpoint/"><em>RNZ News</em></a></p>
<p>New Zealand&#8217;s cyber security agency believes China has been behind numerous hack attacks spanning years.</p>
<p>The government joined Western allies and Japan in calling out Beijing for so-called state-sponsored hacks, including a major incursion in February when Microsoft email servers were targeted.</p>
<p>The US has <a href="https://www.aljazeera.com/economy/2021/7/19/us-uk-and-allies-tie-chinese-government-to-microsoft-hack">charged four Chinese nationals</a> &#8212; three security officials and one contract hacker &#8212; with targeting dozens of companies and government agencies in the United States and overseas under the cover of a tech company.</p>
<ul>
<li><a href="https://podcast.radionz.co.nz/ckpt/ckpt-20210720-1807-recent_microsoft_hack_definitely_from_china_-_gcsb_boss-128.mp3"><strong>WATCH RNZ CHECKPOINT LIVESTREAM:</strong> <span class="c-play-controller__title">&#8216;</span><span class="c-play-controller__title">This is obviously a real concern&#8217; (<span class="c-play-controller__duration"><span class="hide">Duration </span>7<span aria-hidden="true">′</span><span class="acc-visuallyhidden">:</span>39&#8243;)</span></span></a></li>
<li><a href="https://www.rnz.co.nz/news/on-the-inside/447314/geoffrey-miller-nz-s-statement-on-china-a-shot-across-the-bow"><strong>READ MORE:</strong> NZ&#8217;s statement on China a shot across the bow &#8211; <em>Geoffrey Miller</em></a></li>
<li><a href="https://www.rnz.co.nz/news/political/447239/government-points-finger-at-china-over-cyber-attacks">NZ government points finger at China over cyber attacks</a></li>
</ul>
<p>&#8220;What we do is when we see malicious cyber activity on New Zealand networks, that may be through our own capabilities that we have to help protect New Zealand networks or it may be something that&#8217;s reported to us, we look at the malware that&#8217;s used,&#8221; Government Communications Security Bureau Director-General Andrew Hampton told RNZ <em>Checkpoint</em>.</p>
<p>&#8220;We look at how the actor behaves. We look at who they might be targeting and what they do if they get onto a network.</p>
<p>&#8220;That allows us to build a bit of a picture of who the actor is. We then compare that with information that we receive, often from our intelligence partners who are also observing such activity.</p>
<p>&#8220;That allows us to make an assessment, and it&#8217;s always a probability assessment about who the actor is.</p>
<p><strong>The APT 40 group</strong><br />
&#8220;In this case, because of the amount of information we&#8217;ve been able to access both from our own capabilities and from our partners, we&#8217;ve got a reasonably high level of confidence that the actor who we&#8217;ve seen undertaking this campaign over a number of years, and in particular, who was responsible for the Microsoft Exchange compromise, was the APT 40 group &#8212; Advanced Persistent Threat Group 40 &#8212; which has been identified as associated with the Chinese Ministry of State Security.</p>
<div class="embedded-media brightcove-video">
<div class="fluidvids"><iframe loading="lazy" class="fluidvids-item" src="https://players.brightcove.net/6093072280001/default_default/index.html?videoId=6264391882001" width="480" height="270" frameborder="0" allowfullscreen="allowfullscreen" data-fluidvids="loaded" data-mce-fragment="1"></iframe><br />
<em>The RNZ National live stream.  Video: Checkpoint</em></div>
</div>
<p>&nbsp;</p>
<p>&#8220;The actors here are state sponsored actors rather than what we would normally define as a criminal group. What we&#8217;re seeing here is a state sponsored actor likely to be motivated by a desire to steal information.&#8221;</p>
<p>Hampton said there was a blurring of lines between what a state agency does, and what a criminal group does.</p>
<p>&#8220;Some of the technical capabilities that previously only state organisations had, have now got into the hands of criminal groups.</p>
<p>&#8220;Also what we&#8217;ve seen in a range of countries is individuals who may work part-time in a government intelligence agency, and then may work part-time in a criminal enterprise. Or they may have previously worked in a state intelligence agency and are now out by themselves but still have links links back to the state.</p>
<p>&#8220;We don&#8217;t know the full detail of the nature of the relationship, but what we do know is the Ministry of State Security in China, for example, is a very large organisation with many thousands of of employees.</p>
<p>&#8220;So they are big organisations with people on their payroll but they also would have connections with other individuals and organisations.</p>
<p><strong>Information shared with criminals</strong><br />
&#8220;Something else worth noting with regard to this most recent compromise involving the Microsoft Exchange, what we saw there is once the Ministry of State Security actors had identified the vulnerability and exploited it, they then shared that information with a range of other actors, including criminal groups, so they too could exploit it.</p>
<p>&#8220;This is obviously a real concern to see this type of behaviour occurring,&#8221; Hampton said.</p>
<p>All evidence showed the cyber attacks were all originating from mainland China, Hampton told <em>Checkpoint</em>.</p>
<p>He said such attacks would be aimed at stealing data or possibly positioning themselves on a system to be able to access information in the future.</p>
<p>&#8220;A common tactic we see, unfortunately, is there may be a vulnerability in a system,&#8221; Hampton said.</p>
<p>&#8220;It could be a generic vulnerability across all users of that particular system, and a malicious actor may become aware of that vulnerability, so they would use that to get onto the network.</p>
<p>&#8220;That doesn&#8217;t mean they will then start exfiltrating data from day one or something like that. They may just want to to sit there in the event that at some point in the future they may want to start doing that.</p>
<p><strong>Malicious actors</strong><br />
&#8220;This exploitation of known vulnerabilities is a real concern. This is why all organisations need to keep their security patches up to date, because what can happen is you can have malicious actors use technology to scan whole countries to see who hasn&#8217;t updated their patches.</p>
<p>&#8220;They then use that vulnerability to get on the network and they may not do anything with it for some time. Or they might produce a list of all the organisations, say, in New Zealand who haven&#8217;t updated their patches.</p>
<p>&#8220;Then they make a decision &#8211; okay these are the four to five we want to further exploit.&#8221;</p>
<p><i><em>This article is republished under a community partnership agreement with RNZ.</em></i></p>
]]></content:encoded>
					
		
		<enclosure url="https://podcast.radionz.co.nz/ckpt/ckpt-20210720-1807-recent_microsoft_hack_definitely_from_china_-_gcsb_boss-128.mp3" length="7379791" type="audio/mpeg" />

			</item>
		<item>
		<title>Kurdish anti-ISIS hacker attacks Fiji defence websites</title>
		<link>https://asiapacificreport.nz/2016/03/04/kurdish-hacker-attacks-fiji-defence-websites/</link>
		
		<dc:creator><![CDATA[APR editor]]></dc:creator>
		<pubDate>Fri, 04 Mar 2016 03:45:34 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Fiji]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Pacific Media Centre]]></category>
		<category><![CDATA[Pacific Report]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Islamic State]]></category>
		<category><![CDATA[Kurdish independence]]></category>
		<guid isPermaLink="false">http://asiapacificreport.nz/?p=10869</guid>

					<description><![CDATA[By Allison Penjueli of Newswire Fiji Websites belonging to the Republic of Fiji Military Force (RFMF), Fiji Police Force and the Immigration Department were today “defaced” apparently by a Kurdish hacker known for his anti-ISIS views.  In the attack, MuhmadEmad uploaded a picture of the Kurdish flag along with the words, “KurDish HaCkerS WaS Here” ]]></description>
										<content:encoded><![CDATA[<p><em>By Allison Penjueli of <a href="https://www.newswire.com.fj/" target="_blank">Newswire Fiji</a></em></p>
<p>Websites belonging to the Republic of Fiji Military Force (RFMF), Fiji Police Force and the Immigration Department were today “defaced” apparently by a Kurdish hacker known for his anti-ISIS views. <span id="more-5894"></span></p>
<p>In the attack, MuhmadEmad uploaded a picture of the Kurdish flag along with the words, “KurDish HaCkerS WaS Here” and “HaCKeD by MuhmadEmad, Long Live to peshmarga.” This was a reference to the Kurdish army of Peshmerga, which has been fighting to defend its homeland from the so-called Islamic State force based in Iraq.</p>
<figure id="attachment_10876" aria-describedby="caption-attachment-10876" style="width: 500px" class="wp-caption alignright"><img loading="lazy" decoding="async" class="size-full wp-image-10876" src="https://asiapacificreport.nz/wp-content/uploads/2016/03/fiji-police-well-be-back-soon.jpg" alt="The maintenance message on the Fiji police website 6 hours after Newswire Fiji reported the hack. Image: Cafe Pacific" width="500" height="421" srcset="https://asiapacificreport.nz/wp-content/uploads/2016/03/fiji-police-well-be-back-soon.jpg 500w, https://asiapacificreport.nz/wp-content/uploads/2016/03/fiji-police-well-be-back-soon-300x253.jpg 300w, https://asiapacificreport.nz/wp-content/uploads/2016/03/fiji-police-well-be-back-soon-499x420.jpg 499w" sizes="auto, (max-width: 500px) 100vw, 500px" /><figcaption id="caption-attachment-10876" class="wp-caption-text">The maintenance message on the Fiji police website more than 6 hours after Newswire Fiji reported the hack. Image: <a href="http://cafepacific.blogspot.co.nz/2016/03/kurdish-hacker-targets-fiji-police.html" target="_blank">Cafe Pacific</a></figcaption></figure>
<p>Fiji police spokesperson Inspector Josaia Weicavu said the force was aware of the hack and was working to rectify it.</p>
<p>An RFMF spokesperson was unaware of the incident when contacted, but said he would look into the issue.</p>
<p>Director of Immigration Nemani Vuniwaqa also said he was unaware of the hack, but would look into it urgently.</p>
<p>MuhmadEmad has reportedly hacked numerous US and Turkey government websites over the past two years.</p>
<p>Website &#8220;defacement&#8221;:</p>
<blockquote><p>Website defacement is an attack on a website that changes the visual appearance of the site or a webpage. These are typically the work of system crackers, who break into a web server and replace the hosted website with one of their own.</p></blockquote>
<p><a href="http://cafepacific.blogspot.co.nz/2016/03/kurdish-hacker-targets-fiji-police.html" target="_blank">The aftermath &#8211; six hours later &#8211; on Café Pacific</a></p>
<p><a href="http://www.fijitimes.com/story.aspx?id=307223" target="_blank">Hacking horrors in Fiji</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
