Security

China pushes back against Exchange attack sponsorship claims

Chinese Foreign Ministry spokesperson says 53 per cent of cyber attacks on China come from the US


China has very firmly pushed back against the accusation it paid contractors to attack Microsoft's Exchange Server.

The USA, UK, NATO and other nations on Monday named China as the source of the attack.

On Tuesday, spokesperson for the Chinese Foreign Ministry, Zhao Lijian, responded to accusations that China's Ministry of State Security launched a global cyber hacking campaign.

Zhao said:

The US ganged up with its allies to make groundless accusations out of thin air against China on the cyber security issue. This act confuses right with wrong and smears and suppresses China out of political purpose. China will never accept this.

The spokesperson then accused the US of being the world's largest source of cyber attacks. He launched into statistics reported by China's National Computer Network Emergency Response Technical Team (CNCERT):

… about 52,000 malicious program command and control servers located outside China took control of about 5.31 million computer hosts in China in 2020. The US and two of its NATO allies are the top three in terms of the number of computers under their control in China.

In addition, 360's report also showed that APT-C-39, a cyber attack organization of the US Central Intelligence Agency, has carried out cyber infiltration and attacks on China for 11 years in key areas such as aerospace, science and research institutions, oil industry, large Internet companies and government agencies.

Zhao took to Twitter to further air his grievances:

Still hot under the collar during Wednesday's briefing with more tweets to prove it, Zhao cited data that appears to come from CNCERT's China Internet Cyber Security Report 2020 dated June 2021 and published online yesterday.

The spokesperson claimed that 53 per cent of the 42 million malicious programs found in 2020 originated from the US. Then, for the second day in a row, he made a point of the United States’ penchant for wiretapping – not just its enemies but also its allies.

Zhao concluded that: "People can tell right from wrong. The US has not a shred of credibility left on the issue of cyber security, making whatever it says more than dubious."

The 248-page Mandarin-language CNCERT report's early pages claim a fall in cyber incidents across China during 2020.

For example, the document states the number of cases the organization handled fell by 4.2 per cent year-on-year. Implanted backdoors among Chinese web sites fell overall 37.3 per cent year-on-year and domestic government sites with backdoors fell even more – a whopping 64.3 per cent year-on-year. Tampered web sites decreased by 45.9 per cent year-on-year. DDoS attacks, total attack traffic and botnet control terminals all dropped year-on-year – 16.16 per cent, 19.67 per cent and 2.05 per cent respectively.

CNCERT is a non-governmental, non-profit organization that has put out an annual cyber security report on China since 2008. ®

Send us news
16 Comments

Microsoft brings World of Warcraft and other Blizzard titles back to China

Battle with NetEase ends, peace deal will see games cross the Great Firewall - in both directions

Microsoft warns that China is using AI to stir the pot ahead of US election

Beware random inflammatory questions on social media – they may come from a threat actor

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

CISA calls for 'fundamental, security-focused reforms' to happen ASAP, delaying work on other software

Microsoft faces bipartisan criticism for alleged censorship on Bing in China

Redmond says it does what it's told, but still thinks users are better off

Chinese schools testing 10,000 locally made RISC-V-ish PCs

Today's lesson covers the potential for Loongson's made-in-China architecture to hurt Microsoft and Intel

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

In what other sphere does a bad supplier not feel pain for its foulups?

Microsoft breach allowed Russian spies to steal emails from US government

Affected federal agencies must comb through mails, reset API keys and passwords

Open source versus Microsoft: The new rebellion begins

Neither side can afford to lose, but one surely must

Microsoft squashes SmartScreen security bypass bug exploited in the wild

Plus: Adobe, SAP, Fortinet, VMware, Cisco issue pressing updates

Intel preps export-friendly lower-power Gaudi 3 AI chips for China

Beijing will be thrilled by this nerfed silicon

AI gold rush continues as Microsoft invests $1.5B in UAE's G42

Can regulators keep up?

US senator wants to put the brakes on Chinese EVs

Fears of low-cost invasion and data spies spark call for ban