{"id":1527,"date":"2025-01-25T18:46:13","date_gmt":"2025-01-26T01:46:13","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=1527"},"modified":"2025-01-25T18:46:17","modified_gmt":"2025-01-26T01:46:17","slug":"us-treasury-hacked-by-chinese-sponsored-hackers","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/01\/25\/us-treasury-hacked-by-chinese-sponsored-hackers\/","title":{"rendered":"US Treasury Hacked by Chinese Sponsored Hackers"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What Happened:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It was reported on January 10<sup>th<\/sup> that the US Treasury department was victim of a hack that occurred a month earlier on December 8<sup>th<\/sup>. The US Treasury has since called it a \u2018Major Incident\u2019 and called in the Cybersecurity and Infrastructure Security Agency (CISA), FBI and other intelligence organizations for help in containing and investigating the incident. The attack is believed to be done by a Chinese sponsored hacking group called Silk Typhoon.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Was Affected:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The hackers where able to get access to over 400 computers and over 3000 unclassified files. The hackers were targeting computers and files focused on the topics of sanctions and international affairs and intelligence [5]. This led to documents with information related to policy and travel, organizational charts, materials on sanctions and foreign investment, and \u2018Law Enforcement Sensitive\u2019 data all being accessed and leaked. The last one of \u2018Law Enforcement Sensitive\u2019 data is related to the Committee on Foreign Investment in the United States (CFIUS) which is a committee that investigates foreign investments in the United States for national security purposes like real estate purchases and other foreign investments in the states.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of potential greater concern among the affected computers are the Secretary of the US Treasury, Janet Yellen and other high-ranking officials. Just under 50 files were accessed on the Secretary&#8217;s computer including information like usernames, passwords, and the documents related to CFIUS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Overall, the report says no high-value information within the Treasury department was accessed and emails and classified networks were untouched[5]. In addition, no long-term reconnaissance tools were deployed within the network and no signs of malware have been detected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How did the Hack Happen:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The hackers used two CVE\u2019s to gain access to the US Treasury department one of critical severity and the other of medium severity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2024-12356 &#8211; A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. [8]<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"160\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123456-1024x160.png\" alt=\"\" class=\"wp-image-1530 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123456-1024x160.png 1024w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123456-300x47.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123456-768x120.png 768w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123456.png 1132w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/160;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2024-12686 &#8211; A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. [9]<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"146\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123686-1-1024x146.png\" alt=\"\" class=\"wp-image-1532 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123686-1-1024x146.png 1024w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123686-1-300x43.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123686-1-768x110.png 768w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/CVE-2024-123686-1.png 1122w\" data-sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/146;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Theses vulnerabilities were present in BeyondTrust\u2019s SaaS application which the US Treasury used for cybersecurity. When BeyondTrust noticed suspicious activity on a computer and further investigated and discovered the vulnerability and hack they notified the US Treasury. Later on December 16, these vulnerabilities where patched on their cloud instances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2024-12356 attacks flaws in BeyondTrust SaaS applications Privileged Remote Access and Remote Support features. Attacking a vulnerable API endpoint which allowed hackers to execute code on the site as the user giving them privilege access to the user\u2019s network. CVE-2024-12686 is then used once privilege access is gained to help keep persistence and run more commands.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is Silk Typhoon:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Also known as HAFNIUM (G0125), Silk Typhoon are very likely a state-sponsored cyber group in China. They have over 26 TTP accredited to them on MITRE. Given this latest hack and hacks on the Telecom industry, the US has placed sanctions on Shanghai company Sichuan Juxinhe Network Technology CO. which is believed to have ties to Silk Typhoon. The sanctions specifically target hacker Yin Kecheng, both the company and Yin have ties to the China\u2019s Ministry of State Security. China\u2019s Foreign Minister spokesperson spoke out saying these claims that the attack was state sponsored are \u201cunwarranted and groundless\u201d.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What this means for us:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For future security professional like us, this means we need to be aware that not all hacks and attacks on our systems are going to be from random hacking groups but can and likely will be from state sponsored groups sometimes. Though just because these hackers might be state-sponsored doesn\u2019t mean we can\u2019t do anything to prevent things like this from happening.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are two things that the US Treasury could have done to help prevent this hack:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first and main one is performing External Attack Surface Management (EASM). This is where the company looks at all outward facing endpoints and entry points into the company\u2019s network (mapping their attack surface) and catalogues it to understand what\u2019s viewable to the public. From there, the company needs to figure out which of these endpoints should be visible and why each endpoint is needed. If it&#8217;s not needed they need to get rid of it. After confirming the essential endpoints that are needed, known vulnerabilities should be scanned for and if any are found they should be patched. Having a EASM team and processes at a company helps the security team understand how they can be attacked and helps prevent future easily preventable attacks from happening.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-src=\"https:\/\/cdn.prod.website-files.com\/5ff66329429d880392f6cba2\/67850a0a9796ad81abd9d631_65fac05dc6d836748217c099_414-min.jpeg\" alt=\"\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The second thing the US Treasury could have done is better patch management and communicating to their service provider BeyondTrust the importance of this. Making sure that patches are rolled out regularly and quickly ensures known vulnerabilities get addressed as quickly as possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">References:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">[1] <a href=\"https:\/\/www.csoonline.com\/article\/3632744\/chinesische-hacker-attackieren-us-finanzministerium.html\">https:\/\/www.csoonline.com\/article\/3632744\/chinesische-hacker-attackieren-us-finanzministerium.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/chinese-hackers-accessed-yellens-computer-us-treasury-breach-bloomberg-news-2025-01-17\/\">https:\/\/www.reuters.com\/technology\/cybersecurity\/chinese-hackers-accessed-yellens-computer-us-treasury-breach-bloomberg-news-2025-01-17\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] <a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/chinese-hackers-infiltrated-us-treasury-secretarys-pc-attackers-had-access-to-over-400-pcs\">https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/chinese-hackers-infiltrated-us-treasury-secretarys-pc-attackers-had-access-to-over-400-pcs<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] <a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/chinese-hackers-target-us-treasury-computers-used-for-sanctions-committee-on-foreign-investment-specifically-targeted\">https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/chinese-hackers-target-us-treasury-computers-used-for-sanctions-committee-on-foreign-investment-specifically-targeted<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[5] <a href=\"https:\/\/www.yahoo.com\/news\/treasury-hackers-focused-sanctions-intelligence-015705689.html\">https:\/\/www.yahoo.com\/news\/treasury-hackers-focused-sanctions-intelligence-015705689.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[6] <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/us-treasury-dept-issues-sanctions-related-salt-typhoon-hack-2025-01-17\/\">https:\/\/www.reuters.com\/technology\/cybersecurity\/us-treasury-dept-issues-sanctions-related-salt-typhoon-hack-2025-01-17\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[7] <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/us-treasury-dept-issues-sanctions-related-salt-typhoon-hack-2025-01-17\/\">https:\/\/www.reuters.com\/technology\/cybersecurity\/us-treasury-dept-issues-sanctions-related-salt-typhoon-hack-2025-01-17\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[8] <a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2024-12356\/\">https:\/\/www.cvedetails.com\/cve\/CVE-2024-12356\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[9] <a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2024-12686\/\">https:\/\/www.cvedetails.com\/cve\/CVE-2024-12686\/<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[10] https:\/\/attack.mitre.org\/groups\/G0125\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What Happened: It was reported on January 10th that the US Treasury department was victim of a hack that occurred a month earlier on December 8th. The US Treasury has since called it a \u2018Major Incident\u2019 and called in the Cybersecurity and Infrastructure Security Agency (CISA), FBI and other intelligence organizations for help in containing &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/01\/25\/us-treasury-hacked-by-chinese-sponsored-hackers\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;US Treasury Hacked by Chinese Sponsored Hackers&#8221;<\/span><\/a><\/p>\n","protected":false},"author":680,"featured_media":1529,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[38,6,37,40,39],"class_list":["post-1527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chinese-hacker","tag-data-breach","tag-hack","tag-isec-611","tag-ustreasury","entry"],"featured_image_src":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/us_treasury_department_releases_proposed_carried_-600x400.png","featured_image_src_square":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/01\/us_treasury_department_releases_proposed_carried_-600x600.png","author_info":{"display_name":"Hayden McNally","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/hayden-mcnally\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/680"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=1527"}],"version-history":[{"count":4,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1527\/revisions"}],"predecessor-version":[{"id":1535,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1527\/revisions\/1535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media\/1529"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=1527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=1527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=1527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}