CISA, FBI, NSA and International Partners Warn of China-based Cybersecurity Company Enabling Threat Actors to Target Multiple Critical Infrastructure Sectors Worldwide
WASHINGTON – Today the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and international partners issued a joint Cybersecurity Advisory warning that Integrity Technology Group (Integrity Tech), a China-based cybersecurity company, is enabling threat actors to target multiple critical infrastructure sectors worldwide using a range of sophisticated tools, such as large-scale botnets, virtual private network infrastructure and living off the land. Based on real-world investigations and observed activity in North America, Southeast Asia and Africa, this advisory provides recommended mitigations and information to help network defenders detect and respond to this malicious activity.
With ties to the Chinese government, Integrity Tech is a key enabler of malicious cyber activity by acquiring or developing cyber tools, hosting infrastructure, and compromising networks globally. These Integrity Tech-enabled threat actors are using tactics, techniques, and procedures (TTPs) consistent with the activity publically known as Flax Typhoon, Ethereal Panda, and Red Juliett. To maintain long-term, stealthy access to networks, these actors are targeting edge devices that are not closely monitored by the targeted organization. The advisory includes a range of actionable steps for network defenders to secure edge infrastructure and protect their networks which includes patching the listed known exploited common vulnerabilities and exposures (CVEs).
“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA urges organizations to review this advisory to be aware of the wide range of tactics used by these actors and implement recommended actions and mitigations. The advisory underscores the critical role of collaboration between government agencies and the private sector.”
«Under the FBI Cyber Strategy, we pursue both the actors who threaten critical infrastructure and the enterprises that support them,» said Assistant Director Brett Leatherman of the FBI’s Cyber Division. «Integrity Technology Group, a China-based company with ties to the Chinese government, is one of those enterprises, acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide. We urge every organization to apply this advisory’s mitigations and report suspicious activity to their local FBI field office.»
The advisory highlights that Chinese government-linked cyber actors targeted critical infrastructure across sectors to include government, critical manufacturing, healthcare. They also targeted victims in US law enforcement, and education organizations.
CISA, FBI and partners strongly urge all organizations, especially those in critical infrastructure to review the advisory, hunt for signs of compromise, and implement the recommended mitigations.
For more information, please visit China Threat Overview and Advisories.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original