Chinese cyber-espionage groups used the same sophisticated hacking tool in campaigns targeting U.S. aerospace companies, nongovernmental organizations, mining companies, and commodity traders, according to two cybersecurity firms that separately investigated the activity.
Volexity, a Virginia-based cybersecurity firm, said on Sept. 21 its discovery of another Chinese hacking group using the same tool added to evidence of coordinated sharing within China’s cyber-espionage community.
The company said the widespread adoption “suggests a coordinated effort within the Chinese CNE community,” referring to computer network exploitation, and assessed that the core tool was likely shared, customized, and used by multiple groups.
Proofpoint, a U.S. cybersecurity company, separately documented on Sept. 9 the same capability in campaigns against a small number of U.S. NGOs, mining companies, commodity-trading firms, and multiple U.S. aerospace companies. It found several espionage groups adopting the tool within days of one another, with most of the observed clusters having a suspected China nexus.
Neither company has publicly identified who developed the tool or how it reached the different hacking groups.
The Epoch Times asked both companies whether they had identified its developer or distributor and whether they had found additional U.S. targets. Neither responded by publication time.
Same Tool, Different Targets
The hacking groups pursued different victims and installed different spying software after gaining access, but researchers found that they relied on the same underlying break-in capability.
The attacks took advantage of previously unknown weaknesses in Google Chrome and Microsoft Windows. If successful, they could allow hackers to install spying software and maintain access to a victim’s computer.
Volexity said the additional Chinese operator it identified used the same attack chain on Sept. 3 and 4, when the vulnerabilities were still unpatched.
The company cautioned that what Volexity and Proofpoint have observed may represent only part of the activity.
“The full scope and impact are likely far broader,” Volexity said.