Hacker NewsInternationale nyhederNyhederAndre videoerUnited States NewsVideoer

Kinesiske statssponsorerede hackere gik ind i forenede stater finansstationer gennem en stjålet beyondtrust fjernsupport nøgle

Lige før Trump overtager, 'chinese hackere' stjæle papirer fra os statskasse dept: se, hvordan man 124; byde

On December 30, 2024, the Treasury Department told Congress that Chinese state-sponsored hackers had remotely accessed workstations inside Departmental Offices and taken unclassified documents. Officials called it a major incident. The on-ramp was not a clever zero-day against a Treasury laptop. It was a third-party remote-support product and a stolen key.

BeyondTrust, a privileged-access vendor based in Johns Creek, Georgia, had already told customers that its remote support SaaS was under investigation. Treasury’s letter said the company alerted the department on December 8 that an attacker had obtained an API key used to secure a cloud service that lets technicians reach end-user machines. Once you own that key, you do not need to phish every analyst. You walk in as the help desk.

AEGIS Alliance behandler dette som en vendor- trust fiasko med en national- stat knyttet, ikke som et mysterium om, hvorvidt Kina har en efterretningstjeneste. Det interessante er, hvor lidt af agenturets egen endpoint stak måtte mislykkes for dokumenterne at forlade.

Illustration anvendt af iscenesættelse alliance for de forenede stater statskassen beyonttrust remote-support brud.
Finansministeriet fortalte lovgiverne en stjålet BeyondTrust nøgle lade en angriber nå Department Office arbejdsstationer og uklassificerede filer.

Brevet og tidslinjen

Assistant Secretary for Management Aditi Hardikar wrote Senate Banking Committee leaders Sherrod Brown and Tim Scott that a threat actor used the stolen key to override the remote-support service’s security, reach certain Departmental Offices workstations, and access unclassified documents those users kept. Reuters og Vogteren blev offentliggjort samme dag.

BeyondTrust’s own incident page said suspicious activity on some remote-support SaaS instances was noticed around December 2, 2024, and confirmed days later. The company revoked the compromised key and shut down affected instances. Later summaries circulating among security shops put the haul in the range of roughly 100 workstations and more than 3,000 unclassified files. Treasury’s first letter to Congress did not lock those counts in public. Unclassified is not the same as unimportant. Sanctions drafts, vendor memos, personnel notes, and deliberative traffic all live below the classified line.

Den 6. januar 2025, CISA sagde it was working with Treasury and BeyondTrust and that it had no indication other federal agencies were hit through the same path. That sentence mattered. A remote-support SaaS used across government could have been a hallway into several buildings. CISA’s update narrowed the known federal victim set to one department, at least for that product instance.

Navnet skatkammer sat på skuespilleren

Den 17. januar 2025, Office of Kontrol med udenlandske aktiver udpeget Yin Kecheng, en baseret operatør finansministeriet beskrevet som et datterselskab af Kinas Ministry of State Security med mere end et årti i handelen. Finansministeriets frigivelse sagde, at han var tilknyttet departementskontorernes kompromis. Vicesekretær Adewale Adeyemo brugte betegnelsen til at sige, at afdelingen ville blive ved med at gå efter aktører, der ramte amerikanske virksomheder og USA 's regering, herunder finansministeriet selv.

The same winter OFAC named other Chinese firms for other campaigns. Integrity Technology Group was designated on January 3, 2025, for infrastructure tied to Flax Typhoon. Sichuan Silence Information Technology and an employee were named in December 2024 over firewall exploits. Sichuan Juxinhe Network Technology was tied in the January 17 package to Salt Typhoon work against U.S. telecommunications companies. Those are separate campaigns. Readers should not mash them into one cartoon syndicate. They do show a pattern: Treasury writes sanctions with one hand and, in this case, had to explain a breach with the other.

Organisation alliance dækkede integriteten tech pakke i en særskilt sanktionshistorieDisse to filer er den samme arkitektur set fra modsatte skriveborde. Washington behandler kinesiske entreprenører som udskæringer. Kinesiske tjenester behandler amerikanske entreprenører på samme måde.

Den anden illustration, der blev brugt af iscenesættelsen for finansministeriet, var brud på tilliden.
BeyondTrust sagde, at det tilbagekaldte den stjålne nøgle og lukkede ned kompromitterede fjernstøttesager efter hændelsen i december 2024.

Hvorfor et helpdesk værktøj er et nationalt sikkerhedsobjekt

Remote support exists because agencies cannot staff every laptop with a technician in the room. A cloud service that can override a workstation is, by design, a master key. If the vendor’s key store is weaker than the agency’s own identity stack, the agency inherits the weaker store. That is not a novel lesson. SolarWinds taught a version of it. MOVEit taught another. This incident taught it again with a smaller blast radius and a clearer attribution sentence.

Hardening endpoints does not save you if the tool that is allowed to reach those endpoints is already owned. Procurement language about “trusted vendors” is not a control. Cryptographic key hygiene, isolated admin paths, and the ability to cut a SaaS instance without cutting the department’s ability to work are controls. After December 2024, any agency still running privileged remote support as if it were a help-desk convenience is ignoring the letter Treasury had to send.

Third-party software remains the preferred on-ramp for an actor who does not want to fight an agency’s own endpoint team. Agencies can patch their laptops and still lose a week to a product they do not write. That is the procurement model. The useful signal is whether Treasury treats BeyondTrust as a partner with a bad month or as evidence that some classes of remote access should not sit in a vendor cloud at all.

Hvad dokumenterne faktisk er, er

No public inventory has listed the filenames. That absence will keep feeding speculation. Sanctions offices, the Committee on Foreign Investment in the United States staff work, and international-affairs shops all sit inside or near Departmental Offices. An unclassified folder in those shops can still tell an adversary who is being discussed, which licenses are under review, and which contractors have access. Espionage does not require a classified stamp to be worthwhile.

China has denied state responsibility in the usual terms. The U.S. government has not produced a courtroom exhibit for the public. Attribution in these cases is an intelligence judgment packaged for Congress. Readers can hold that judgment as the official U.S. position without pretending they have seen the packet. Beijing’s public line after incidents like this is that Washington is smearing Chinese researchers and firms. That line does not erase the BeyondTrust key, the Treasury letter, or the OFAC designation of Yin Kecheng. It also does not require readers to treat every Chinese engineer as an MSS officer.

The procurement aftershock is the part that will last longer than the headline. If a remote-support vendor can be turned into a hallway, then every agency that still buys that class of product as a convenience is betting the vendor’s key store is harder than a ministry of state security. That bet failed at Treasury in December 2024. Other agencies were lucky, according to CISA. Luck is not a control.

Relaterede filer på dette skrivebord omfatter den IRS- tema fjernstyring malware bølgeder har anvendt et andet trusted- tool misbrug, og påstande om et massivt tyveri fra et kinesisk supercomputing centerForskellige skuespillere. Samme kategori: Den, der holder den afsides admin sti holder bygningen.

AEGIS Alliance vil holde fokus på nøglen, sælgeren, den uklassificerede træk, og januar sanktioner navn. Det er dokumenteret. Alt andet er en briefing, nogen ikke har offentliggjort. For mere i denne bane se Hacker-nyheder, teknologi, og United States news.

Jeffrey Childers
Journalist, redaktør, ekspert i cybersikkerhed og datalogi, forvaltning af sociale medier, tagentreprenør.

Relaterede artikler

En kommentar

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *

Tilbage til øverste knap
Tilmeld dig vores nyheder og erindringer nyhedsbreve!

Nyhedsbrev form

Lister
close- link