US Treasury hacked by state-sponsored Chinese APT group

0
6χλμ.

The U.S. Treasury Department Dec. 30 informed Congress that it sustained a “major cybersecurity incident” at the hands of a state-sponsored Chinese group in which a BeyondTrust API key was hacked, resulting in the compromise of Treasury workstations and the theft of unclassified documents.

 

In a letter to the Senate Committee on Banking, Housing and Urban Affairs, Aditi Hardikar, assistant secretary for management at Treasury, said that on Dec. 8, BeyondTrust notified Treasury that the threat actor used the stolen key to access the department’s systems.

Hardikar told the Senators that the compromised BeyondTrust cloud service was taken offline and that there was no evidence indicating that the threat actor has continued its access to Treasury information.

The Treasury Department will offer more information on this incident in its 30-day follow-up report later in January.

This incident joins a growing list of attacks on security firms, including Okta, LastPass, SolarWinds, and Snowflake, said former NSA expert Evan Dornbush.

“In today's interconnected landscape, the perimeter has all but vanished,” said Dornbush. “A single zero-day exploit against a vendor can cripple your own operations. The BeyondTrust response, while remarkably swift, underscores this harsh reality.”

The latest release by Treasury makes a little more sense of CISA’s Dec. 19 announcement of adding the BeyondTrust vulnerability CVE-2024-12356 to the KEV list, said John Bambenek, president at Bambenek Consulting.

Bambenek said at the time, CISA announced a limited number of customer’s Remote Support SaaS instances were targeted: it now appears that the U.S. Treasury was one of those customers.

While it’s a stunning year-end announcement from Treasury, we still don’t know how many workstations were compromised, which documents were stolen, and which advanced persistent threat (APT) conducted the campaign.

Given the recent stories about Chinese threat actor Salt Typhoon attacking up to nine U.S. telecoms, some speculated that they were the culprits.

But as of the afternoon of Dec. 31, no further details had emerged.    

“At this point, I don’t see anything to indicate clearly that it’s Salt Typhoon beyond it being the Chinese APT on people’s mind because of the recent telecom breaches,” said Bambenek. “However, that doesn’t mean it couldn’t be either.”

Dornbush gave some further context to the BeyondTrust hack, pointing out that they moved quickly. The hack was initially discovered on Dec. 2, with the root cause identified by Dec. 5. Clients were notified on Dec. 8, and BeyondTrust released on patch Dec. 16.

“Sixteen days from discovery to mitigation, patching, disclosure, and attribution is impressive,” said Dornbush. “However, this speed doesn't negate the fundamental problem: their zero-days are your problem. While BeyondTrust acted quickly, the attackers likely exfiltrated data long before the patch was available. In smash-and-grab operations like this, data theft doesn't take 16 days.”

 

 

***

 

 

Wow
1
Αναζήτηση
CryptoCurrency Rates
Κατηγορίες
Διαβάζω περισσότερα
News & Politics
Parliament to vote on sending British troops to Ukraine, says Starmer
The UK government will put to a vote in parliament the issue of sending troops to Ukraine after a...
από NavyVetUnited 2026-01-07 15:57:45 0 4χλμ.
Real Time Facts
THROWBACK: Were the COVID pandemic and Ukraine proxy war part of a bigger British plan?
In 2010, Bill Ryan, founder of the Project Avalon portal, claimed he received intel from an...
από NavyVetUnited 2025-06-07 08:19:28 0 9χλμ.
News & Politics
Why did Joe Biden’s brother do business with Qatar?
A new report revealed that Jim Biden repeatedly used his brother’s position as both a way...
από NavyVetUnited 2024-04-30 18:34:06 0 9χλμ.
News & Politics
Fidan, Blinken discuss Gaza crisis, Sweden’s NATO bid, safety of food shipments from Russia, Ukraine
Turkish and U.S. foreign ministers Hakan Fidan and Antony Blinken held talks in Istanbul to...
από NavyVetUnited 2024-01-06 16:30:52 0 25χλμ.
Real Time Facts
A British News Host Explained Trump's Stategy
𝐀 𝐁𝐑𝐈𝐓𝐈𝐒𝐇 𝐍𝐄𝐖𝐒 𝐇𝐎𝐒𝐓 𝐉𝐔𝐒𝐓 𝐄𝐗𝐏𝐋𝐀𝐈𝐍𝐄𝐃 𝐓𝐑𝐔𝐌𝐏’𝐒 𝐒𝐓𝐑𝐀𝐓𝐄𝐆𝐘 𝐁𝐄𝐓𝐓𝐄𝐑 𝐓𝐇𝐀𝐍 𝐀𝐍𝐘𝐎𝐍𝐄 𝐈𝐍 𝐀𝐌𝐄𝐑𝐈𝐂𝐀𝐍 𝐌𝐄𝐃𝐈𝐀...
από US-Israel Roaring Lion, Epic Fury Ops 2026-04-08 09:32:41 0 2χλμ.
X-Pulse, the HO1 Think Tank https://thinktank.x-pulse.org/