MACAU DAILY TIMES 澳門每日時報

Top Menu

  • Our Team
  • Editorial Statute
    • Code of Ethics
    • Privacy Policy
    • Terms and Conditions
  • Archive
    • PDF Editions
  • Contacts
  • Extra Times
    • Drive In
    • Book It
    • tTunes
    • Features
    • World of Bacchus
    • Taste of Edesia

Main Menu

  • Home
  • Macau
    • Photo Shop
    • Advertorial
  • Interview
  • Greater Bay
  • Business
    • Corporate Bits
  • China
  • Asia
  • World
  • Sports
  • Opinion
    • Editorial
    • Our Desk
    • Business Views
    • China Daily
    • Multipolar World
    • The Conversation
    • World Views
  • Our Team
  • Editorial Statute
    • Code of Ethics
    • Privacy Policy
    • Terms and Conditions
  • Archive
    • PDF Editions
  • Contacts
  • Extra Times
    • Drive In
    • Book It
    • tTunes
    • Features
    • World of Bacchus
    • Taste of Edesia
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
logo
FOUNDER & PUBLISHER Kowie Geldenhuys
EDITOR-IN-CHIEF Paulo Coutinho
Macau,

MACAU DAILY TIMES 澳門每日時報

  • Home
  • Macau
    • Photo Shop
    • Advertorial
  • Interview
  • Greater Bay
  • Business
    • Corporate Bits
  • China
  • Asia
  • World
  • Sports
  • Opinion
    • Editorial
    • Our Desk
    • Business Views
    • China Daily
    • Multipolar World
    • The Conversation
    • World Views
  • Sam pledges talent study as gov’t prioritizes local employment, reviews foreign worker approvals

  • CE: Orientation fund not expected to generate substantial returns early on

  • New economy chief vows steady progress, says portfolio ‘no stranger’ to her

  • CE: Population decline a development issue

  • Proposed consumption tax overhaul heads to AL

  • Building maintenance fund expanded as subsidy scope widens, procedures streamlined

World
Home›World›Cybersecurity | Report says Russian hackers haven’t eased spying efforts

Cybersecurity | Report says Russian hackers haven’t eased spying efforts

By -
December 8, 2021
13
0
Share:

The elite Russian state hackers behind last year’s massive SolarWinds cyberespionage campaign hardly eased up this year, managing plenty of infiltrations of U.S. and allied government agencies and foreign policy think tanks with consummate craft and stealth, a leading cybersecurity firm reported.

Also yesterday [Macau time], Microsoft announced that it had disrupted the cyber-spying of a state-backed Chinese hacking group by seizing websites it used to gather intelligence from foreign ministries, think tanks and human rights organizations in the U.S. and 28 other countries, chiefly in Latin America and Europe. 

Microsoft said a Virginia federal court had granted its request last Thursday to seize 42 web domains that the Chinese hacking group, which it calls Nickel but which is also known as APT15 and Vixen Panda, were using to access targets typically aligned with China’s geopolitical interests. It said in a blog that “a key piece of the infrastructure the group has been relying on” in its latest wave of infiltrations was removed. The seized domains include “elperuanos.org,” “pandemicacre.com” and “cleanskycloud.com.” 

The dual announcements, though unrelated, highlight the unrelenting drumbeat of digital spying by its top U.S. geopolitical rivals, whose cyber-intrusion skillset is matched only by that of the United States.

A year after it discovered the SolarWinds intrusions, Mandiant said the hackers associated with Russia’s SVR foreign intelligence agency continue to steal data “relevant to Russian interests” with great effect using novel, stealthy techniques that it detailed in a mostly technical report aimed at helping security professionals stay alert. It was Mandiant, not the U.S. government, that disclosed SolarWinds.

While the number of government agencies and companies hacked by the SVR was smaller this year than last, when some 100 organizations were breached, assessing the damage is difficult, said Charles Carmakal, Mandiant’s chief technical officer. Overall, the impact is quite serious. “The companies that are getting hacked, they are also losing information.”

“Not everybody is disclosing the incident(s) because they don’t always have to disclose it legally,” he said, complicating damage-assessment. 

The Russian cyber spying unfolded, as always, mostly in the shadows as the U.S. government was consumed in 2021 by a separate, eminently “noisy” and headline-grabbling cyber threat — ransomware attacks launched not by nation-state hackers but rather criminal gangs. As it happens, those gangs are largely protected by the Kremlin. 

The Mandiant findings follow an October report from Microsoft that the hackers, whose umbrella group it calls Nobelium, continue to infiltrate the government agencies, foreign policy think tanks and other organizations focused on Russian affairs through the cloud service companies and so-called managed services providers on which they increasingly rely. The Mandiant researchers said the Russian hackers “continue to innovate and identify new techniques and tradecraft” that lets them linger in victim networks, hinder detection and confuse attempts to attribute hacks to them.

Mandiant did not identify individual victims or describe what specific information may have been stolen but did say unspecified “diplomatic entities” that received malicious phishing emails were among the targets.

Often, the researchers say, the hackers’ path of least resistance to their targets were cloud-computing services. From there, they used stolen credentials to infiltrate networks. The report describes how in one case they gained access to one victim’s Microsoft 365 system through a stolen session token. And, the report says, the hackers routinely relied on advanced tradecraft to cover their tracks.

One clever technique discussed in the report illustrates the ongoing cat-and-mouse game that digital espionage entails. Hackers set up intrusion beachheads using IP addresses, a numeric designation that identifies its location on the internet, that were physically located near an account they are trying to breach — in the same address block, say, as the person’s local internet provider. That makes it highly difficult for security software to detect a hacker using stolen credentials posing as someone trying to access their work account remotely. 

Microsoft expressed no illusions that the website seizures it announced yesterday would discourage the Chinese hackers, who it has been tracking since 2016. It said the takedowns were of infrastructure it has been tracking since 2019, much of it exploiting on-premises —- as opposed to cloud-based — Exchange Server and SharePoint systems. The company has used the legal takedown tactic in 24 lawsuits to date, Microsoft said, knocking out a total of 600 sites used by nation-state actors and 10,000 by cybercriminals.

The SolarWinds hack exploited vulnerabilities in the software supply-chain system and went undetected for most of 2020 despite compromises at a broad swath of federal agencies — including the Justice Department — and dozens of companies, primarily telecommunications and information technology providers and including Mandiant and Microsoft.

The hacking campaign is named SolarWinds after the U.S. software company whose product was exploited in the first-stage infection of that effort. The Biden administration imposed sanctions last April in response to the hack, including against six Russian companies that support the country’s cyber efforts. ERIC TUCKER & FRANK BAJAK, WASHINGTON, MDT/AP

FacebookTweetPin

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Like this:

Like Loading…

Related

Previous Article

This day in history | 1980 John ...

Next Article

Japan | About 100 lawmakers visit controversial ...

0
Shares

    Related articles More from author

    • World

      France rethinks romance with Macron as his popularity sinks

      August 7, 2017
      By -
    • World

      Czech Republic | Orchestra of disabled musicians gets world attention

      July 5, 2017
      By -
    • World

      Cecil the lion | Minnesota dentist who killed beloved lion returns to work

      September 9, 2015
      By -
    • World

      Kremlin says it still expects Putin-Trump summit to go ahead

      November 29, 2018
      By -
    • World

      Migration | US decision would hit families’ pocketbooks in El Salvador

      January 11, 2018
      By -
    • World

      This day in history | 1984 Sandinistas claim election victory

      November 5, 2021
      By -

    • Sports

      EPL | Arsenal moves top, Van Gaal says he won’t leave United

    • Breaking News

      Opinion | Fall of Singapore would be beginning of the end for Uber

    • Macau

      HK corruption watchdog charges Stanley Ho’s relative in corruption case

    DAILY EDITION

    Wednesday, June 17, 2026 – edition no. 4973
    Wednesday, June 17, 2026 – edition no. 4973

    Greater Bay

    MDT MACAU GRAND PRIX SPECIAL

    June 2026
    M T W T F S S
    1234567
    891011121314
    15161718192021
    22232425262728
    2930  
    « May    

    Timeline

    • June 17, 2026

      Sam pledges talent study as gov’t prioritizes local employment, reviews foreign worker approvals

    • June 17, 2026

      CE: Orientation fund not expected to generate substantial returns early on

    • June 17, 2026

      New economy chief vows steady progress, says portfolio ‘no stranger’ to her

    • June 17, 2026

      CE: Population decline a development issue

    • June 17, 2026

      Proposed consumption tax overhaul heads to AL

    • June 17, 2026

      Building maintenance fund expanded as subsidy scope widens, procedures streamlined

    • June 17, 2026

      Surging Chinese exports threaten Europe’s economy, raising concern at G7 summit 

    • June 17, 2026

      G7 needs to focus guidance and impetus on inclusive global growth and development

    • June 17, 2026

      Strengthening good governance requires dialogue with the legislative branch: CE

    • June 17, 2026

      Culture-sports synergy drives Dragon Boat Festival

    Extra Times

    Extra TimesFeatures

    Le Mans 24 Hours: More than just a race

    With the change of seasons, from the end of winter to spring, when the days get longer and the fields and trees are covered in flowers in the Northern Hemisphere, ...
    • Expectations running high

      By Sérgio de Almeida Correia, MDT
      June 12, 2026
    • Shared Summer 

      By Irene Sam, MDT
      June 5, 2026
    • Boots Riley’s ‘I Love Boosters’ is a wild, surrealist social satire

      By MDT/AP
      June 5, 2026
    • On McCartney’s ‘The Boys of Dungeon Lane,’ an ex-Beatle reminisces

      By MDT/AP
      June 5, 2026
    • Recent

    • Popular

    • Sam pledges talent study as gov’t prioritizes local employment, reviews foreign worker approvals

      By Yuki Lei, MDT
      June 17, 2026
    • CE: Orientation fund not expected to generate substantial returns early on

      By Renato Marques, MDT
      June 17, 2026
    • New economy chief vows steady progress, says portfolio ‘no stranger’ to her

      By Yuki Lei, MDT
      June 17, 2026
    • CE: Population decline a development issue

      By -
      June 17, 2026
    • Proposed consumption tax overhaul heads to AL

      By Nadia Shaw, MDT
      June 17, 2026
    • Building maintenance fund expanded as subsidy scope widens, procedures streamlined

      By Nadia Shaw, MDT
      June 17, 2026
    • Surging Chinese exports threaten Europe’s economy, raising concern at G7 summit 

      By MDT/AP
      June 17, 2026
    • Canidrome may have its days numbered, decision in ‘one or two months’

      By Paulo Coutinho, MDT
      May 26, 2016
    • Animal Welfare | Macau: Anima slams Canidrome management for avoiding debate

      By -
      May 4, 2016
    • Editorial | Canidoomed

      By Paulo Coutinho, MDT
      June 1, 2016
    • Animal Welfare | Canidrome presented with ultimatum: close or move

      By Daniel Beitler, MDT
      July 22, 2016
    • Australia regulator cracks down on alleged exportation of dogs to Macau

      By Paulo Coutinho, MDT
      June 10, 2016
    • USE OF ENGLISH IN MACAU | A ‘de facto’ official language

      By Catarina Pinto
      July 6, 2015
    • Animal rights | Canidrome: Anima in fresh airline negotiations as Canidrome closure looks more likely

      By Daniel Beitler, MDT
      May 27, 2016
    • Contact our Administrator
    • Contact our Editor-in-Chief
    • Contacts
    • Our Team
    • Privacy Policy
    • Terms and Conditions
    • Editorial Statute
    • Code of Ethics
    COPYRIGHT © MACAU DAILY TIMES 2008-2026. ALL RIGHTS RESERVED
    MACAU DAILY TIMES
    • Home
    • Macau
      • Photo Shop
      • Advertorial
    • Interview
    • Greater Bay
    • Business
      • Corporate Bits
    • China
    • Asia
    • World
    • Sports
    • Opinion
      • Editorial
      • Our Desk
      • Business Views
      • China Daily
      • Multipolar World
      • The Conversation
      • World Views
    • Our Team
    • Editorial Statute
      • Code of Ethics
      • Privacy Policy
      • Terms and Conditions
    • Archive
      • PDF Editions
    • Contacts
    • Extra Times
      • Drive In
      • Book It
      • tTunes
      • Features
      • World of Bacchus
      • Taste of Edesia

    Loading Comments...

    You must be logged in to post a comment.

      %d