By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Tech NewsTech NewsTech News
Reading: Ransomware Tactics by Chinese Spies
Share
Notification Show More
Font ResizerAa
Tech NewsTech News
Font ResizerAa
Follow US
© 2024 TECH.Forum | Technology News . All Rights Reserved.
Tech News > Blog > Latest Tech > Cybersecurity > Ransomware Tactics by Chinese Spies
CybersecurityLatest Tech

Ransomware Tactics by Chinese Spies

Elina Norberg
Last updated: June 27, 2024 4:33 am
Elina Norberg 11 months ago
Share
SHARE

Chinese Cyber Spies Turn to Ransomware to Obscure Their Tracks

Cybersecurity experts have linked ransomware attacks to groups engaged in espionage, specifically identifying a group believed to be from China known as ChamelGang. They reportedly use the CatB ransomware to complicate tracing the source of attacks, distract security teams, or as an additional method to gain financially while they steal sensitive data.

ChamelGang’s Ransomware Strategy

ChamelGang, also referred to as CamoFei, has focused its efforts on government and critical infrastructure sectors from 2021 to 2023. Their approach includes sophisticated methods to infiltrate networks, scout for valuable information, and move stealthily across the system to extract data.

One notable incident occurred in November 2022 when they targeted Brazil’s Presidential offices, affecting 192 computers. The group used ransomware to encrypt files, leaving ransom notes embedded within, and demanded payment via Bitcoin. Initially, these attacks were wrongly attributed to another malware, but further investigations pointed back to ChamelGang.

Furthermore, in a separate instance late in 2022, they disrupted operations at the All India Institute Of Medical Sciences (AIIMS), highlighting the severe implications of their attacks on healthcare services.

Variations in Ransomware Use

Aside from CatB, there has been a noticeable pattern of using Jetico BestCrypt and Microsoft BitLocker, targeting different types of technology environments. This varied approach affected 37 organizations primarily in North America, with some cases in South America and Europe. This method also showed potential links to other espionage activities believed to be connected to Chinese and North Korean groups.

These findings suggest that using ransomware can serve dual purposes for cyber spies: it can mislead analysts about the attackers’ true intentions and mask the espionage activities as mere cybercrime.

Why Use Ransomware?

Incorporating ransomware into cyberespionage provides strategic advantages. It not only causes immediate disruption but also creates confusion about the nature of the attack. This confusion can lead to misattribution, which benefits the attackers by hiding their real goals and prolonging their presence within the compromised networks.

The shift towards these tactics marks a significant evolution in cyber espionage strategies, indicating a blend of traditional hacking with ransomware attacks to effectively cover their tracks and achieve broader objectives.

For more insights on cybersecurity and protecting against ransomware, visit our Cybersecurity Hub.

To understand the broader implications of ransomware on global security, read this detailed analysis by The Global Security Institute.

You Might Also Like

AI Transforms iGaming: Key Trends & Effects

5G Takes to the Skies: Trial Success

Augmented Reality: Boosting Efficiency

CrowdStrike Update Triggers Major Global Outage

Steve Blank on AI: Strategy for Startups

Share This Article
Facebook Twitter LinkedIn Email
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Data Ethics in the Digital Age: Navigating Innovation with Integrity
Next Article Garmin Rolls Out New Features for Cyclists
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

Italian Companies Lead the Way in Sustainable Governance
Sustainability
Brazil’s G20 Leadership: A Chance to Boost Public Health and Decolonise Global Health
Global & EU Policies World & Europe
Why Speeding Up Support for Article 6.2 of the Paris Agreement Matters
Global & EU Policies World & Europe
Embracing Sustainable Wellness: Eco-Friendly Practices for a Healthier Life
Sustainability

Most Viewed Posts

  • OpenAI Launches New AI Model GPT-4o with Realistic Voice Capabilities
  • EU Sets New Standards for Election Integrity: A Guide for Social Media Titans Under the Digital Services Act
  • How Secure Are Your Digital Footprints?
  • Renewables Reach Record Levels: Powering More than a Third of the Globe
  • Sustainable Practices and Goals at Largest Companies like Amazon, Google, and Apple
about us

Tech.forum News is Europe's premier source of technology related news, gathered from all over the globe on a single platform to fulfill your yearning for the latest updates on technology

Find Us on Socials

© Copyright | Tech.Forum News. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?