Mar 4 • 10:40 UTC 🇫🇮 Finland Iltalehti

Google warns of Chinese spies – Dozens of states targeted by breaches

Google reports that a cyber espionage campaign linked to China has breached dozens of telecommunications operators and state agencies in many countries.

Google has issued a warning about a cyber espionage campaign linked to China, highlighting that dozens of telecommunications operators and state agencies across 42 different countries have been targeted. The company's Threat Intelligence Group has been active in disrupting the activities of these spies since the disruptions came to light earlier this year. This campaign, identifiable by the designation UNC2814, has been exploiting vulnerabilities in servers and edge devices, raising concerns about the expansive reach of this espionage effort.

The campaign, which has reportedly been ongoing since at least 2023, has involved the use of sophisticated tools, including a backdoor known as Gridtide, which is written in the C programming language and operates with a high level of stealth. The malware utilizes Google Sheets as a programming interface to transmit commands and data, accessing services through a hardcoded Google Service Account key. This innovative method of command and control significantly complicates the detection and mitigation of the malware by affected organizations and cybersecurity professionals.

Such revelations not only underscore the vulnerabilities of national and telecommunications infrastructure to foreign espionage but also complicate the geopolitical landscape, particularly as nations assess their cybersecurity measures in the face of rising threats. The implications for international relations could be significant as countries may respond by intensifying scrutiny on cyber capabilities and defensive collaborations, reflecting the urgency to bolster their defenses against such geopolitical cyber threats.

📡 Similar Coverage