13661807498?profile=RESIZE_400xChinese-linked hackers are targeting the Taiwanese semiconductor industry and investment analysts as part of a string of cyber espionage campaigns, researchers said on 17 July.  While hacking to steal data and information about the industry is not new, there is an increase in sustained hacking campaigns from several China-aligned hacking groups, researchers with cybersecurity firm Proofpoint said in a new analysis.  “We’ve seen entities that we hadn’t ever seen being targeted in the past being targeted,” said a threat researcher focused on Chinese-related threats at Proofpoint.[1]

The previously unreported hacking campaigns were carried out by at least three distinct Chinese-linked groups primarily between March and June of this year, with some activity likely ongoing, Proofpoint said.  They come amid rising restrictions by Washington on exports to China of US-designed chips that are often manufactured in Taiwan. China's chip industry has been working to replace its dwindling supply of sophisticated US chips, especially those used in artificial intelligence.

The researchers declined to identify the hacking targets but told Reuters that approximately 15 to 20 organizations ranging from small businesses, analysts employed by at least one US-headquartered international bank, and large global enterprises faced attacks.

Major Taiwanese semiconductor firms include Taiwan Semiconductor Manufacturing Company, MediaTek, United Microelectronics Corp, Nanya Technology and RealTek Semiconductor. TSMC declined to comment.  MediaTek, UMC, Nanya and RealTek did not respond to requests for comment.  Media was unable to identify the specific hacking targets or determine whether any of the efforts were successful.        

A spokesperson for the Chinese embassy in Washington said in an email that cyber-attacks “are a common threat faced by all countries, China included,” and that the Asian country “firmly opposes and combats all forms of cyber-attacks and cybercrime, a position that is consistent and clear.”

The activity ranged from one or two emails sent as part of the more targeted campaign focused on specific people, to as many as 80 emails when trying to gain information from the company at large, Kelly said.

One group targeted semiconductor design, manufacturing and supply-chain organizations using compromised Taiwanese university email accounts to pose as job seekers and send malware via PDFs with URLs leading to malicious files, or a password-protected archive.

 

Another targeted financial analyst at major unnamed investment firm focused on the Taiwanese semiconductor industry by posing as a fictitious investment firm and sought collaboration.  Two of the entities are based in Asia, while the third is based in the US. 

A representative of TeamT5, a cybersecurity firm based in Taiwan, reported that it had also seen an increase in emails being sent targeting the semiconductor industry tied to a few hacking groups, “but not a wide or general phenomenon.”

Targeting of semiconductors and the supply chain around them “is a persistent threat that has existed for long,” the representative said, and a “constant interest” for Chinese-related advanced hacking operators.

These groups often target “peripheral suppliers or related industries,” the representative said, such as a situation in June where a China-linked hacking group identified by TeamT5 as "Amoeba" launched a phishing campaign against an unnamed chemical company that plays a critical role in the semiconductor supply chain.

This article is shared with permission at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information via a notification service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://register.gotowebinar.com/register/5207428251321676122

[1] https://www.msn.com/en-us/money/other/exclusive-china-linked-hackers-target-taiwans-chip-industry-with-increasing-attacks-researchers-say/ar-AA1IJPDc/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!