دخل المخترقون الصينيون الذين ترعاهم الدولة إلى مصانع خزانة الولايات المتحدة من خلال مفتاح الدعم عن بعد

On December 30, 2024, the Treasury Department told Congress that Chinese state-sponsored hackers had remotely accessed workstations inside Departmental Offices and taken unclassified documents. Officials called it a major incident. The on-ramp was not a clever zero-day against a Treasury laptop. It was a third-party remote-support product and a stolen key.
BeyondTrust, a privileged-access vendor based in Johns Creek, Georgia, had already told customers that its remote support SaaS was under investigation. Treasury’s letter said the company alerted the department on December 8 that an attacker had obtained an API key used to secure a cloud service that lets technicians reach end-user machines. Once you own that key, you do not need to phish every analyst. You walk in as the help desk.
ويتعامل تحالف التحالف مع هذا الأمر على أنه فشل في الثقة بين البائعين والدولة القومية، وليس كغموض حول ما إذا كان لدى الصين جهاز استخبارات. الجزء المثير للاهتمام هو كيف القليل من كومة نهاية الوكالة الخاصة كان لا بُدَّ أنْ تَخْفقَ في الوثائقِ للمغادرة.

الرسالة والجدول الزمني
Assistant Secretary for Management Aditi Hardikar wrote Senate Banking Committee leaders Sherrod Brown and Tim Scott that a threat actor used the stolen key to override the remote-support service’s security, reach certain Departmental Offices workstations, and access unclassified documents those users kept. رويترز و الحارس نشر مادة الرسالة في نفس اليوم
BeyondTrust’s own incident page said suspicious activity on some remote-support SaaS instances was noticed around December 2, 2024, and confirmed days later. The company revoked the compromised key and shut down affected instances. Later summaries circulating among security shops put the haul in the range of roughly 100 workstations and more than 3,000 unclassified files. Treasury’s first letter to Congress did not lock those counts in public. Unclassified is not the same as unimportant. Sanctions drafts, vendor memos, personnel notes, and deliberative traffic all live below the classified line.
في السادس من يناير 2025 رابطة الدول المستقلة قالت it was working with Treasury and BeyondTrust and that it had no indication other federal agencies were hit through the same path. That sentence mattered. A remote-support SaaS used across government could have been a hallway into several buildings. CISA’s update narrowed the known federal victim set to one department, at least for that product instance.
الاسم خيانة وضعت على الممثل
في الجانوي 17، 2025، مكتب مراقبة الأصول الأجنبية سمّى يين كيتشنغ، خزينة مشغّلة مقرها شانغهاي وصفت بأنها منتسبة من وزارة أمن الدولة في تشينا مع أكثر من عقد في التجارة. بيان الخزينة وقال انه كان مرتبطا بالحل التوفيقي لمكاتب الإدارة. واستخدم نائب الأمين أديوال أدييمو هذا التعيين ليقول إن الإدارة ستستمر في استهداف الجهات الفاعلة التي تضرب الشركات الأمريكية وحكومة الولايات المتحدة، بما في ذلك الخزانة نفسها.
The same winter OFAC named other Chinese firms for other campaigns. Integrity Technology Group was designated on January 3, 2025, for infrastructure tied to Flax Typhoon. Sichuan Silence Information Technology and an employee were named in December 2024 over firewall exploits. Sichuan Juxinhe Network Technology was tied in the January 17 package to Salt Typhoon work against U.S. telecommunications companies. Those are separate campaigns. Readers should not mash them into one cartoon syndicate. They do show a pattern: Treasury writes sanctions with one hand and, in this case, had to explain a breach with the other.
تحالف (إيغس) غطي مجموعة تقنية النزاهة قصة جزاءات منفصلةهذان الملفان هما نفس الهيكل الذي شوهد من المكاتب المقابلة (واشنطن) يعامل المقاولين الصينيين كقطع الخدمات الصينية تعامل المقاولين الأمريكيين بنفس الطريقة

لماذا أداة مساعدة هو موضوع أمني وطني
Remote support exists because agencies cannot staff every laptop with a technician in the room. A cloud service that can override a workstation is, by design, a master key. If the vendor’s key store is weaker than the agency’s own identity stack, the agency inherits the weaker store. That is not a novel lesson. SolarWinds taught a version of it. MOVEit taught another. This incident taught it again with a smaller blast radius and a clearer attribution sentence.
Hardening endpoints does not save you if the tool that is allowed to reach those endpoints is already owned. Procurement language about “trusted vendors” is not a control. Cryptographic key hygiene, isolated admin paths, and the ability to cut a SaaS instance without cutting the department’s ability to work are controls. After December 2024, any agency still running privileged remote support as if it were a help-desk convenience is ignoring the letter Treasury had to send.
Third-party software remains the preferred on-ramp for an actor who does not want to fight an agency’s own endpoint team. Agencies can patch their laptops and still lose a week to a product they do not write. That is the procurement model. The useful signal is whether Treasury treats BeyondTrust as a partner with a bad month or as evidence that some classes of remote access should not sit in a vendor cloud at all.
ما هي مشكلة الوثائق في الواقع
No public inventory has listed the filenames. That absence will keep feeding speculation. Sanctions offices, the Committee on Foreign Investment in the United States staff work, and international-affairs shops all sit inside or near Departmental Offices. An unclassified folder in those shops can still tell an adversary who is being discussed, which licenses are under review, and which contractors have access. Espionage does not require a classified stamp to be worthwhile.
China has denied state responsibility in the usual terms. The U.S. government has not produced a courtroom exhibit for the public. Attribution in these cases is an intelligence judgment packaged for Congress. Readers can hold that judgment as the official U.S. position without pretending they have seen the packet. Beijing’s public line after incidents like this is that Washington is smearing Chinese researchers and firms. That line does not erase the BeyondTrust key, the Treasury letter, or the OFAC designation of Yin Kecheng. It also does not require readers to treat every Chinese engineer as an MSS officer.
The procurement aftershock is the part that will last longer than the headline. If a remote-support vendor can be turned into a hallway, then every agency that still buys that class of product as a convenience is betting the vendor’s key store is harder than a ministry of state security. That bet failed at Treasury in December 2024. Other agencies were lucky, according to CISA. Luck is not a control.
تشمل الملفات ذات الصلة في هذا المكتب موجة البرمجيات العنيفةو الذي استعمل إدماناً مختلفاً و موثوقاً به إدعاءات سرقة ضخمة من مركز حواسيب صينيجهات فاعلة مختلفة نفس الفئة: أيّاً كان من يحمل مساراً من بُعد فيتامين يمسك المبنى.
وسيبقي التحالف تركيزه على المفتاح، والبائع، والطريق غير المصنف، واسم الجزاءات في كانون الثاني/يناير. هذه موثقة كل شيء آخر هو إحاطة لم ينشرها أحد للمزيد في هذا الممر أخبار القراصنة, التكنولوجياو أخبار الولايات المتحدة.










لذا قامت وكالة المخابرات المركزية باختراق (فيد أوبنزي) باستخدام حواسيب المخترقين الصينيين