{"id":1471118,"date":"2024-06-14T03:00:00","date_gmt":"2024-06-14T07:00:00","guid":{"rendered":"https:\/\/bugaluu.com\/news\/china-linked-cyber-campaign-infiltrated-dozens-of-western-governments-dutch-intelligence\/1471118\/"},"modified":"2024-06-14T03:00:00","modified_gmt":"2024-06-14T07:00:00","slug":"china-linked-cyber-campaign-infiltrated-dozens-of-western-governments-dutch-intelligence","status":"publish","type":"post","link":"https:\/\/bugaluu.com\/news\/china-linked-cyber-campaign-infiltrated-dozens-of-western-governments-dutch-intelligence\/1471118\/","title":{"rendered":"China-Linked Cyber Campaign Infiltrated Dozens Of Western Governments: Dutch Intelligence"},"content":{"rendered":"<p><span class=\"field field--name-title field--type-string field--label-hidden\">China-Linked Cyber Campaign Infiltrated Dozens Of Western Governments: Dutch Intelligence<\/span><\/p>\n<div class=\"clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item\">\n<p><em><a href=\"https:\/\/www.theepochtimes.com\/china\/china-linked-cyber-campaign-infiltrated-dozens-of-western-governments-report-5667428?utm_source=partner&amp;utm_campaign=ZeroHedge&amp;src_src=partner&amp;src_cmp=ZeroHedge\">Authored by Andrew Thornebrooke via The Epoch Times<\/a> (emphasis ours),<\/em><\/p>\n<p><a href=\"https:\/\/cms.zerohedge.com\/s3\/files\/inline-images\/image_92%28664%29.jpg?itok=1yWcWP2F\"><em>Prince, a member of the hacking group Red Hacker Alliance who refused to give his real name, uses a website that monitors global cyberattacks on his computer at their office in Dongguan, Guangdong Province, China, on Aug. 4, 2020. (Nicolas Asfouri\/AFP via Getty Images)<\/em><\/a><\/p>\n<p><strong>A China-linked cyber campaign that infiltrated a Dutch defense network last year is much larger than previously thought and has infiltrated tens of thousands of government and defense systems in Western nations,<\/strong> according to the Dutch government.<\/p>\n<p>The campaign, dubbed COATHANGER, has been linked to communist China and it exploited a zero-day vulnerability in the FortiGate firewall system used by the Netherlands and other nations on many government networks. Zero-day vulnerabilities exist when a software update is first deployed.<\/p>\n<p>Dutch intelligence\u2019s original report, released in February, said that <a href=\"https:\/\/www.theepochtimes.com\/china\/chinese-hackers-penetrated-dutch-defense-network-report-5581865\">damage from the breach was limited<\/a> because of \u201cnetwork segmentation,\u201d which separates an affected system from the nation\u2019s wider defense network.<\/p>\n<p>The Netherlands\u2019 National Cyber Security Center (NCSC) announced on June 10, however, that <strong>the Chinese cyber campaign is far larger than previously thought.<\/strong><\/p>\n<p>NCSC said that COATHANGER compromised 20,000 systems across dozens of Western governments, international organizations, and a large number of companies within the defense industry.<\/p>\n<p>Moreover, the statement said, the attackers used the intrusion to install malware on some of those compromised targets to guarantee continued access to those systems. The malware still has not been cut off.<\/p>\n<p>\u201cThis gave the state actor permanent access to the systems,\u201d the statement reads. \u201cEven if a victim installs FortiGate security updates, the state actor continues to have this access.\u201d<\/p>\n<p>\u201cIt is not known how many victims are actually malware installed. The Dutch intelligence services and the NCSC consider it likely that the state-owned actor could potentially expand its access to hundreds of victims worldwide and has been able to carry out additional actions such as stealing data.\u201d<\/p>\n<p>Likewise,<strong> the Dutch statement said that \u201cit is likely that the state actor still has access to systems of a significant number of victims at the moment\u201d and that organizations should take measures to mitigate the possible fallout from that access.<\/strong><\/p>\n<p>The Netherlands\u2019 original report, jointly published by the Dutch Military Intelligence and Security Service and the General Intelligence and Security Service, didn\u2019t clarify what information the hackers were trying to obtain.<\/p>\n<p>The scope of the latest discovery suggests that the campaign sought to gain persistent access to the defense industries of Western nations. However, it remains unclear whether all the victims were in NATO nations or shared some other connection.<\/p>\n<p>The Dutch statement said that, like many hackers, the COATHANGER campaign targeted \u201cedge devices\u201d like firewalls, VPN servers, routers, and email servers that connect a system to the wider network.<\/p>\n<p>Because zero-day vulnerabilities are hard to anticipate, the statement said, the government encouraged the adoption of an \u201cassume breach\u201d principle.<\/p>\n<p><strong>This means that an initial breach should be assumed and efforts should be taken to limit the damage.<\/strong><\/p>\n<p>Numerous reports have found that China-backed actors associated with both Chinese intelligence and law enforcement are behind the world\u2019s <a href=\"https:\/\/www.theepochtimes.com\/us\/meta-purges-massive-influence-operation-linked-to-chinas-law-enforcement-5482769\">largest online influence operations<\/a>.<\/p>\n<p>U.S. intelligence leaders announced earlier in the year that they had <a href=\"https:\/\/www.theepochtimes.com\/us\/us-dismantles-ccp-malware-that-threatened-physical-safety-of-americans-5577737\">dismantled Chinese malware<\/a> known as Volt Typhoon, which had been planted on hundreds of devices and threatened vital U.S. infrastructure, including water, energy, oil, and air traffic control systems.<\/p>\n<\/div>\n<p>      <span class=\"field field--name-uid field--type-entity-reference field--label-hidden\"><a title=\"View user profile.\" href=\"https:\/\/cms.zerohedge.com\/users\/tyler-durden\" class=\"username\">Tyler Durden<\/a><\/span><br \/>\n<span class=\"field field--name-created field--type-created field--label-hidden\">Thu, 06\/13\/2024 &#8211; 23:00<\/span><\/p>\n<p>\u200b<a href=\"https:\/\/www.zerohedge.com\/geopolitical\/china-linked-cyber-campaign-infiltrated-dozens-western-governments-dutch-intelligence\" target=\"_blank\" class=\"\" rel=\"noopener\">https:\/\/www.zerohedge.com\/geopolitical\/china-linked-cyber-campaign-infiltrated-dozens-western-governments-dutch-intelligence<\/a>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>China-Linked Cyber Campaign Infiltrated Dozens Of Western Governments: Dutch Intelligence Authored by Andrew Thornebrooke via The Epoch Times (emphasis ours), Prince, a member of the&#8230;<\/p>\n","protected":false},"author":0,"featured_media":1471119,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1471118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","wpcat-1-id"],"_links":{"self":[{"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/posts\/1471118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/comments?post=1471118"}],"version-history":[{"count":0,"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/posts\/1471118\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/media\/1471119"}],"wp:attachment":[{"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/media?parent=1471118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/categories?post=1471118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bugaluu.com\/news\/wp-json\/wp\/v2\/tags?post=1471118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}