Two Tech Companies Report Chinese Malware in the Power Grids

No worries America, President Biden is on vacation again, this time for a week. Meanwhile, it was back in May that Microsoft and Mandiant (0wned by Google) reported Volt Typhoon was in a few power systems either for espionage or worse for later capability to disrupt. Presently, there is no immediate threat however, experts outside of the Federal government are studying the cyber language and issuing warnings.

Volt Typhoon's Cyberattack: Key Concerns and Implications for the Industry  | TXOne Networks source

Experts say it’s one of the largest known cyber espionage campaigns against the US.

A key US military outpost, Guam’s ports and air bases would be crucial to any Western response to a conflict in Asia. Together with the Five Eyes alliance – comprising the intelligence agencies of the US, Australia, Britain, New Zealand and Canada – Microsoft published details of the malware.

A cyberattack on Guam is equivalent to an attack on Silicon Valley. Guam, with a population of nearly 154,000, is indistinguishable from the 50 states for the purposes of defense under international and domestic law. It would also be vital to US military operations in any conflict over Taiwan. The Guam Defense System, the defense architecture surrounding Guam and the Mariana Island Chain, is the top homeland defense priority of the current commander of the US Indo-Pacific Command, Admiral John Aquilino. Guam contains the United States’ largest refueling and armament stations in the first and second island chains that provide lines of defense against China. The 2023 National Defense Authorization Act also announced $1.4 billion for defense projects in Guam, and the U.S. Marine Corps is building its first new base in 72 years there. Guam has among the highest military recruitment levels in the United States. In recognition of Guam’s military importance, China calls its DF-26 intermediate ballistic missile, which has a 2500-mile firing range, “the Guam Killer.” Source

The U.S. has 3 military bases (installations in Guam)

Q&A: What does the US military do on the island of Guam? source

***

China’s “peacetime” targeting of critical infrastructure that is used by both civilians and the US military erodes the principles of the law of war. The principle of distinction ordinarily forbids targeting civilian objects, such as civilian property and infrastructure. However, many computer networks are used for both civilian and military purposes. Such “dual use” objects may be targetable based on their nature, purpose, and use. However, combatants must still comply with the other principles of the law of war: military necessity, proportionality, and avoiding unnecessary suffering.

Microsoft has tracked a group of what it believes to be Chinese state-sponsored hackers who have since 2021 carried out a broad hacking campaign that has targeted critical infrastructure systems in US states and Guam, including communications, manufacturing, utilities, construction, and transportation.

Microsoft’s blog post offered technical details of the hackers’ intrusions that may help network defenders spot and evict them: The group, for instance, uses hacked routers, firewalls, and other network “edge” devices as proxies to launch its hacking—targeting devices that include those sold by hardware makers ASUS, Cisco, D-Link, Netgear, and Zyxel. The group also often exploits the access provided from compromised accounts of legitimate users rather than its own malware to make its activity harder to detect by appearing to be benign.

Blending in with a target’s regular network traffic in an attempt to evade detection is a hallmark of Volt Typhoon and other Chinese actors’ approach in recent years, says Marc Burnard, a senior consultant of information security research at Secureworks. Like Microsoft and Mandiant, Secureworks has been tracking the group and observing its campaigns. He added that the group has demonstrated a “relentless focus on adaption” to pursue its espionage.

US government agencies, including the National Security Agency, the Cybersecurity and Infrastructure Security Agency (CISA), and the Justice Department published a joint advisory about Volt Typhoon’s activity today alongside Canadian, UK, and Australian intelligence. “Private sector partners have identified that this activity affects networks across US critical infrastructure sectors, and the authoring agencies believe the actor could apply the same techniques against these and other sectors worldwide,” the agencies wrote. As early as 2009, US intelligence officials warned that Chinese cyberspies had penetrated the US power grid to “map” the country’s infrastructure in preparation for a potential conflict. Two years ago, CISA and the FBI also issued an advisory that China had penetrated US oil and gas pipelines between 2011 and 2013. China’s Ministry of State Security hackers have gone much further in cyberattacks against the country’s Asian neighbors, actually crossing the line of carrying out data-destroying attacks disguised as ransomware, including against Taiwan’s state-owned oil firm CPC. Source

It was not until the New York Times reported this condition that anyone took it seriously. What is worse are the facts reported by CyberScoop in part:

The largely unknown amount of Chinese-made equipment within the North American grid is a threat to national security, experts warned during a Thursday congressional hearing that explored cybersecurity vulnerabilities within the electric sector.

Witnesses from the Department of Energy and private sector testifying during the Senate Energy and Natural Resources Committee echoed a sentiment increasingly heard in Washington that a longstanding dependence on Chinese technologies and cheap components is now an alarming national security issues for U.S. critical infrastructure.

 

 

 

Hat Tip to MasterCard

It is a fact that the United States has a drug/narcotics epidemic. The problem is so bad that it can no longer be estimated how many people across the country abuse the various types of drugs even at work or while driving cars. Furthermore, it is so bad state governments and the Federal government is actually admitting failure and funding programs that encourage drug use…imagine that.

Dispensaries have popped up all over the country and in fact, China is behind many of them.

The Pennsylvania Cannabis Movement, by the Numbers

How about Oklahoma for example?

At least $500 million of black market marijuana was seized during a multi-agency operation led by the Oklahoma Bureau of Narcotics this week, after a yearlong investigation of nine Oklahoma farms.

“It’s much like we see with groups that are trafficking methamphetamine, cartels moving heroin; it is simply people involved in the criminal movement of marijuana on a commercial scale to the illicit market around the United States, and moving money — millions of dollars of money — worldwide,” said Woodward. Read more here.

At least Mastercard appears to take a stand…

PM: Mastercard has told financial institutions to stop allowing the purchase of marijuana with their debit cards.

The move to ban card purchases of the drug comes because of legal ramifications under federal law. Marijuana is illegal nationwide despite having been legalized on the state level in places like Colorado and Oregon.A spokesman for Mastercard said, “The federal government considers cannabis sales illegal, so these purchases are not allowed on our systems.”

“As we were made aware of this matter, we quickly investigated it. In accordance with our policies, we instructed the financial institutions that offer payment services to cannabis merchants and connects them to Mastercard to terminate the activity,” the spokesman said on Wednesday.

Bradey Cobb, the CEO of Sunburn Cannabis, said in a statement about the ban, “this move is another blow to the state-legal cannabis industry and patients/consumers who want to access this budding category.”

The subject of legalizing cannabis has been recently fought over in the federal legislature. Earlier in July, Senate Majority Leader Chuck Schumer released a letter calling for “bipartisan bills” that could be passed in the July work period.

These included “safeguard[ing] cannabis banking.”

 

 

Sen. John Cornyn (R-TX) reacted to Schumer’s desire to pass a marijuana bill during the July summer months by calling it part of a “wish list.”

In addition, Cornyn added, “it is only wishful thinking to believe that in the U.S. Senate you are going to be able to get all of these necessary items addressed in the next ten working days.”

Skepticism about the legalization and use of cannabis has been raised since some data has recently shown that an increase in overdoses “may be correlated” to its legalization with the rise in such illicit drugs as fentanyl.

Putin’s Meeting with Wagner Included 35 Others

Primer:

BRUSSELS (AP) — Nearly 50,000 Russian men have died in the war in Ukraine, according to the first independent statistical analysis of Russia’s war dead.

Two independent Russian media outlets, Mediazona and Meduza, working with a data scientist from Germany’s Tübingen University, used Russian government data to shed light on one of Moscow’s closest-held secrets — the true human cost of its invasion of Ukraine.

To do so, they relied on a statistical concept popularized during the COVID-19 pandemic called excess mortality. Drawing on inheritance records and official mortality data, they estimated how many more men under age 50 died between February 2022 and May 2023 than normal.

*** So, then what was this meeting about that Putin invited 35 top people to attend? After 3 hours in this meeting, it was meant to show Putin maintains control…control of what remains unclear but the read outs from the meeting are scarce on details except that General Valery Gerasimov is keeping his position and title which was the main complaint of Prighozin. It could be however that his duties and responsibilities are diminished. Furthermore, due to the high casualty rate of injuries and death of Russian fighters, Moscow is turning to the Chechen Republic. Chechen fighters are some of the deadliest fighters known but have yet to appear on the battlefield. This is one to watch. Preparation of Jumping-off Ground for Russian Air Forces in Belarus ... (2 Russian bases in Belarus/source)

Next, NATO leadership, at least our own State Department and Department of Defense need to address Belarus and Lukashenko, the president of Belarus.

MEMRI is reporting:

On June 28, 2023, the Russian media outlet Vzglyad published an article titled “How To Manage The Legacy Of The Wagner Group” about the future of the Wagner Group mercenaries after the attempted mutiny that took place few days earlier.

As many Wagner group fighter are preparing to move to Belarus, Belarusian military expert Alexander Alesin told Vzglyad that these fighters may become instructors in the Belarus Army or may provide security for Belarusian workers in Africa.

On June 28, 2023, the Russian media outlet Vzglyad published an article titled “How To Manage The Legacy Of The Wagner Group” about the future of the Wagner Group mercenaries after the attempted mutiny that took place few days earlier.

As many Wagner group fighter are preparing to move to Belarus, Belarusian military expert Alexander Alesin told Vzglyad that these fighters may become instructors in the Belarus Army or may provide security for Belarusian workers in Africa.

Meanwhile, the other topic that should be part of major discussions at the NATO summit is Germany. Exactly what side is Chancellor Scholz on any way? German intelligence knew in advance?

 

… criticism came from the ranks of the center-left German Social Democratic Party (SPD), which is the primary political party behind the government of German Chancellor Olaf Scholz. However, criticism also came from the Green Party —which also supports Scholz’s administration— and the center-right Free Democratic Party (FDP), which opposes Scholz’s government. The criticism intensified after June 28, when, during a live television interview, Chancellor Scholz appeared to confirm speculation that the BND had left his administration in the dark about the Wagner mutiny until it was too late.

Late last week, however, a joint investigation by two of Germany’s most respected public television broadcasters, the Hamburg-based NDR and the Cologne-based WDR, concluded that the BND had been far more informed about the Wagner mutiny than its critics have claimed. The investigation concluded that, not only did the BND have foreknowledge of the mutiny nearly a week before it materialized, but that it was able to listen-in to the frantic telephone conversations between Prigozhin and Belarussian President Lukashenko, as the latter tried to dissuade the Wagner leader from storming the Russian capital with his heavily armed band of mercenaries.

According to the NDR-WDR report, the BND had been able to hack into Wagner’s internal communications system up for over a year. However, its operation was betrayed by “Carsten L.”, a German intelligence officer who was arrested late last year for spying for Russia. However, the German spy service was able to continue to monitor the internal affairs of Wagner through other sources and had access to channels of information within Wagner in the months leading up to the mutiny. Thus, according to the report, the BND had “vague indications of an imminent uprising by Wagner” about a week prior to June 23. source and read more here. 

Cuba Agrees to Host Chinese Spy Base

First there was a full-throated denial by Adm. Kirby from the White House Press Room that the story the Wall Street Journal reported was true. Then a couple of days later, Adm. Kirby walked it back and attempted in national security platitudes to explain why he initially denied the story. Then the White House decided to blame the Trump administration stating that China has had a base in Cuba since 2019. If that was true, then why would the Biden administration lift some sanctions on Cuba?

Well….no , under the Trump administration, that is not accurate either. Perhaps China only has had radar surveillance installation since 2018. but you can bet that since Russia has had a spy base in Cuba known as the Lourdes signals intelligence facility, they are not only collaborating but perhaps co-locating especially since Beijing and Moscow have nurtured a a friendly business relationship without limitations. However, no one is putting China and Cambodia in the conversation…that is right, China has a secret base there too, called the Ream Base. .Satellite imagery of Ream Naval Base from 5 February 2023, annotated to show the shape of the pier extension. Original image courtesy of BlackSky

 

Lourdes

Russia 'to reopen Lourdes spy base in Cuba' - BBC News 2014 source

Beyond the Wall Street Journal doing great work, then comes the Miami Herald with more.

The CIA and Office of the Director of National Intelligence declined to comment. The Cuban government also pushed back against the initial WSJ report calling it “totally false and unfounded information” in a statement made by the Vice-minister of Foreign Affairs, Carlos Fernández de Cossío.

Regardless of Cuba’s sovereign rights in defense matters, the official said, Cuba rejects “any foreign military presence in Latin America and the Caribbean, including that of numerous United States military bases and troops, especially the military base that illegally occupies a portion of the national territory in the province of Guantánamo.” While China might be already collecting intelligence on the U.S. from its commercial facilities in the region, having a signals-intelligence facility “adds to China’s capabilities, especially in times of war,” said Evan Ellis, professor at the U.S. Army War College Strategic Studies Institute, which monitors China’s relationship with Latin America and the Caribbean. “I think it telegraphs Chinese willingness in the current difficult environment between our two countries to take some of these bolder steps and their sense, with their growing military power and economic power and the perception of the U.S. democratic disarray, that they can take these steps that maybe a decade ago, they would not have risked,” Ellis said. “It’s not that big of a threshold that they’ve crossed, but it is significant,” he added.

The news follows intense speculation that Russia, not China, was planning to reopen its Soviet-era espionage base in Lourdes, a town near Havana, which it shut down in 2002. High-ranking Russian national security officials and diplomats have been traveling to the island recently and the two governments appear as close as ever, with Cuban leaders offering public support for Russia’s invasion of Ukraine. But when publicly asked about reopening the Lourdes base during his trip to Havana in April, Russian Foreign Minister Sergei Lavrov did not directly address the question. And despite several economic agreements recently announced by Russian and Cuban authorities, including land-lease deals, the news about a Chinese spy base speaks to the realities on the ground: The island is desperate for cash as its economy continues sinking. Russia had limited resources even before embarking on a war against Ukraine — and China can pay. On May 20, Cuba’s Interior Minister, Gen. Lázaro Alberto Álvarez Casas, met with China’s Minister of Public Security, Wang Xiaohong. “China stands ready to work with Cuba to implement the important consensus reached by the leaders of the two countries and deepen pragmatic cooperation in various fields, especially in law enforcement and security,” a Chinese government statement said.

The news about the spy base comes as the Biden administration has been taking steps to improve its strained relationship with China, which is considered the United States’ primary military and economic rival. At the same time, State Department officials and members of Congress have been raising concerns about China’s increased influence in Latin America and the Caribbean. China has become South America’s largest trading partner and has exploited the Biden administration’s reluctance to new trade deals and has inked a free trade agreement with Ecuador, while Uruguay and Panama are in line, U.S. Rep Maria Elvira Salazar, a Miami Republican, said during a congressional hearing she chaired on Wednesday. “That is very troublesome,” Salazar said, blaming the Biden administration for ignoring the pleas of allies in the region with conservative governments “to the benefit of our enemies.”

When asked by representative Warren Davidson, R-Ohio, why the United States has seemed to become “more passive” and allowed China to increase its influence in the Western Hemisphere, the State Department’s top diplomat for the region acknowledged the administration needs to act with a sense of urgency. “This is the most challenging moment I have seen in 30 years in our hemisphere, and we have to do everything that we can to help our neighbors and our partners around the region to succeed and resist these strategic competitors from outside,” Assistant Secretary for Western Hemisphere affairs Brian Nichols said. The China deal also complicates U.S. policy towards Cuba.

The administration has lifted some restrictions on flights and remittances, resumed the family reunification program for Cubans and reestablished migration and law enforcement talks with the Cuban government. But it stopped short of easing other embargo restrictions and removing Cuba from the list of countries that sponsor terrorism, which the Cuban government had made a condition to improving relations. The cozying up to Russia and China indicates the Cuban government has chosen to seek further support from its longtime political and ideological allies rather than pursuing normalization of relations with the U.S. at a time Cuban authorities perceive their grip on power is at risk. Cuba is facing its worst economic crisis in decades and serious political challenges from a population that has taken to the streets to protest and demand regime change. Ebrahim Raeisi, the president of Iran, another major U.S. adversary, is set to travel to the island after visiting Venezuela and Nicaragua next week. The strategy suggests something else: The Cuban military is calling the shots on the island, not the civilian team led by Cuba’s handpicked president, Miguel Díaz-Canel. If true, the deal with China shows “Cuba’s desperation. It’s the same thing with Russian investors. Cuba is looking for cash where it can get it,” Ellis said. “Cuba also understands the limits of the Biden administration.

With the Republicans in control of the House in Washington, with Biden being more conservative, with a sense of lessons learned that the Obama opening was seen as ‘we gave up too much and receive too little from Cuba,’ there’s an understanding in Cuba that they’re not going to get much more out of Washington.” Latin America’s sharp turn to the left and the consolidation of power by Nicolás Maduro in Venezuela also gives Cuba confidence to do bolder things, Ellis said, while noticing that island has not gone that far as to sign military agreements with Russia or receive Russian weapons. Florida Republicans in Congress quickly reacted to the report on the China espionage base deal to highlight what they said is an increasing national security threat coming from Cuba. “The threat to America from Cuba isn’t just real, it is far worse than this,” Sen. Marco Rubio tweeted. “But to date, not only does the Biden White House not care, they have people who actually want to appease the regime.” “The Cuban regime is auctioning off land to the Russians, hosting the Iranians, and letting the Chinese open a base to spy on the U.S.,” Salazar tweeted. “Just 90 miles from our coast, the dictatorship has opened the door to our greatest enemies!” Later on Thursday, Rubio, who is the Vice Chairman of the Select Committee on Intelligence and the committee’s chairman, Mark R. Warner (D-VA), issued a statement urging the Biden administration “to take steps to prevent this serious threat to our national security and sovereignty.” “We must be clear that it would be unacceptable for China to establish an intelligence facility within 100 miles of Florida and the United States, in an area also populated with key military installations and extensive maritime traffic,” they said.

Read more at: https://www.miamiherald.com/news/nation-world/world/americas/cuba/article276215936.html#storylink=cpy

 

The Clop Ransomware Gang Have Struck State, Federal Agencies and Hospitals

It was several days ago that the first reports started to surface and as CISA/FBI issued warnings, the target list/victims continues to expand.

All attributions so far point to an Russian entity with history on this and those attributions do  not come from the Federal government but rather outside cyber expert companies across the country.

Clop ransomware gang starts extorting MOVEit data-theft victims source and expanded details

So, anyone remember when President Biden gave a list of entities that were completely off limits to cyber attacks? Remember?

Well it was exactly a year ago this month…

There are 16 critical infrastructure sectors whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof. Presidential Policy Directive 21 (PPD-21): Critical Infrastructure Security and Resilience advances a national policy to strengthen and maintain secure, functioning, and resilient critical infrastructure. This directive supersedes Homeland Security Presidential Directive 7.

Click here for the full description of the list. 

Meanwhile, the victims of this cyber attack related to MoveIT and CLOT include:

Reported by TechTarget:

Illinois, Minnesota and Missouri state governments are among a growing list of organizations attacked via a critical flaw in Progress Software’s MoveIT Transfer product.

Progress Software on May 31 detailed an SQL injection bug in its managed file transfer (MFT) software MoveIt Transfer. Progress urged customers to immediately apply mitigations for the vulnerability, tracked as CVE-2023-34362, while it worked on a patch, which was released later that day. But as security vendors reported soon after, the critical bug was already under active exploitation in the wild.

wave of organizations have disclosed data breaches in the wake of CVE-2023-34362 coming to light. Some of the early major names affected by the MoveIT flaw included the government of Nova Scotia, Canada; HR software provider Zellis; the BBC; British Airways; and British retailer Boots.

Several other organizations have disclosed compromises since that initial wave, including U.K. broadcast regulator Ofcom and networking vendor Extreme Networks. Multinational accounting firm Ernst and Young was also reportedly breached via the critical flaw. Ernst and Young did not reply to TechTarget Editorial’s request for comment, but the BBC said it received confirmation of a data breach from the firm.

Additionally Johns Hopkins University Hospital got hit as well as British Airlines. 

CNN adds information to the report:

A Russian-speaking hacking group known as CLOP last week claimed credit for some of the hacks, which have also affected employees of the BBC, British Airways, oil giant Shell, and state governments in Minnesota and Illinois, among others.

The Russian hackers were the first to exploit the vulnerability, but experts say other groups may now have access to software code needed to conduct attacks.

The ransomware group had given victims until Wednesday to contact them about paying a ransom, after which they began listing more alleged victims from the hack on their extortion site on the dark web. As of Thursday morning, the dark website did not list any US federal agencies.

The episode shows the widespread impact that a single software flaw can have if exploited by skilled criminals.

The hackers – a well-known group whose favored malware emerged in 2019 – in late May began exploiting a new flaw in a widely used file-transfer software known as MOVEit, appearing to target as many exposed organizations as they could. The opportunistic nature of the hack left a broad swath of organizations vulnerable to extortion.

Progress, the US firm that owns the MOVEit software, has also urged victims to update their software packages and has issued security advice.