China’s National Computer Network Emergency Response Technical Team (CNCERT) has reported a significant escalation in cyberattacks by US intelligence agencies targeting Chinese defense and high-tech sectors. According to the China Cybersecurity Association, these attacks specifically aim to steal sensitive military research data and core production information from universities, research institutes, and defense contractors.
The attacks intensified after the 2022 exposure of NSA cyberattacks on Northwestern Polytechnical University. Since then, US intelligence agencies have conducted increasingly sophisticated operations against China’s defense industrial base.
The first case occurred from July 2022 to July 2023, where attackers exploited a Microsoft Exchange zero-day vulnerability to control a major military contractor’s email servers for nearly a year. The attackers compromised the company’s domain controller, gained access to over 50 critical devices, and established persistent backdoors. Using proxy servers in Germany, Finland, South Korea, and Singapore, they launched more than 40 attacks and stole emails from 11 executives, including sensitive military product designs and system parameters.
The second case ran from July to November 2024, targeting a communications and satellite internet defense company. Attackers used proxy IPs from Romania and the Netherlands to exploit unauthorized access and SQL injection vulnerabilities. They planted memory backdoors, infected over 300 devices, and specifically searched for keywords like “military network” and “core network” to steal classified data.
The report indicates that in 2024 alone, foreign state-sponsored Advanced Persistent Threat (APT) groups launched over 600 cyberattacks against Chinese critical infrastructure, with defense contractors being the primary target. US intelligence-backed groups demonstrate particular sophistication through organized attack teams, extensive support systems, and advanced vulnerability exploitation capabilities, posing serious threats to China’s national cybersecurity.
Source: Sputnik News, August 1, 2025
https://sputniknews.cn/20250801/1066658052.html
