黑客新闻国际新闻.新闻其他视频美国新闻视频

一个偷来的超信任钥匙 在被制裁的上海运营商Yin Kecheng之前 打开了美国国库工作站

The breach did not begin on a Treasury desk. It began with a key that belonged to a vendor. On December 8, 2024, BeyondTrust told the U.S. Department of the Treasury that an attacker had taken a credential used to secure a cloud service for remote technical support. With that key, the intruder could override the service’s own checks, open sessions on certain Departmental Offices workstations, and read unclassified documents those employees kept on the machines. Treasury Assistant Secretary for Management Aditi Hardikar put that chain in a letter to Senate banking leaders on December 30 and called the intrusion a major cybersecurity incident, the label the department uses when it attributes an attack to an advanced persistent threat.

Hardikar wrote that available indicators pointed to a China state-sponsored actor. A Treasury spokesperson, Michael Gwin, told reporters the access covered several user workstations and certain unclassified documents maintained by those users. The compromised remote-support service was taken offline. As of the date of the letter, the department said it had no evidence the actor still had access. The FBI and the Cybersecurity and Infrastructure Security Agency were brought in. What the letter did not do, and what no public inventory has done since, is list the documents page by page. The public record is an access path, an attribution, and a later name. It is not a catalog of what was copied.

在乔治亚州约翰斯溪的 超越信任 路透社( 路透社) 它在12月初查明了一起涉及其远程支助产品的安全事件,通知了有限的受影响客户,并支持调查。 公司告诉 网络库 it noticed anomalous activity on December 2, confirmed on December 5 that a limited number of Remote Support SaaS customers were affected, posted an advisory on December 8, and had patched the identified instances by December 16. Later technical accounts described the stolen secret as an infrastructure API key for that cloud service. A key like that is not a phishing email. It is a way to impersonate the support system itself.

一个辅助工具变成了前门

Remote-support software exists so a technician can see a user’s screen and fix a machine without walking to the desk. That convenience is also the risk. If an attacker holds the vendor’s key, the session looks like help. Treasury’s Departmental Offices are the policy core of the building: the people who draft sanctions, watch financial flows, and brief the secretary. Unclassified does not mean harmless. Draft designation lists, email about a pending action, notes on a foreign bank, and calendars of who is working a file can all sit on a workstation without ever being stamped secret. Espionage services collect exactly that kind of material because it shows intent before a public announcement.

信后几天与记者交谈的高级官员将这次行动描述为间谍活动,而不是企图安装可以关闭付款系统或付款系统的密码。 电网. 纽约时报 reported that distinction explicitly. The Chinese Embassy in Washington rejected the allegation. A spokesperson told Reuters that Beijing opposed what it called smear attacks made without a factual basis. That denial is the standard reply. It does not answer the narrower question Hardikar’s letter actually raised: who held the BeyondTrust key between December 2 and December 8, and which workstations it opened.

盐台风是最响亮的,不是这个

The Treasury disclosure landed while Washington was still absorbing Salt Typhoon, the China-linked campaign against U.S. telecommunications companies that reached call records and, in some cases, the content of calls placed by senior officials and political figures. A White House official said in late December 2024 that nine telecom companies had been confirmed affected. The timing made it easy to fold every China-attributed intrusion into one brand name. The public sanctions that followed show why that merge is a mistake.

2025年1月17日,财政部外出资产管制处对同日的两个不同目标以及不同行为进行了制裁. 这个 新闻稿 named Yin Kecheng, a Shanghai-based cyber actor whom OFAC described as affiliated with China’s Ministry of State Security and associated with the compromise of the Departmental Offices network. The same release sanctioned Sichuan Juxinhe Network Technology Co., Ltd., which OFAC tied to Salt Typhoon’s work against telecom and internet providers. Deputy Treasury Secretary Adewale Adeyemo said the department would keep using its sanctions tools against actors who target Americans, American companies, and the U.S. government, including those who had targeted Treasury itself. The two designations share a press release. They do not share a break-in.

Yin, OFAC said, had worked as a cyber actor for more than a decade. The sanctions, issued under a cyber executive order, block U.S. persons from dealing with him and freeze any property he has in U.S. jurisdiction. They are not a conviction. They are a financial quarantine based on an intelligence judgment. Readers who want the department’s parallel move against a different Beijing-linked company can compare it with the 几天前宣布了对北京网络安全公司的制裁 以国家资助的活动为主。

3月的指控,被没收的域,以及一个名字太多的团体

On March 5, 2025, the Justice Department unsealed charges against Yin and another Shanghai-based operator, Zhou Shuai, also known as Coldface. Prosecutors and the FBI described the pair as linked to a contractor-style hacking operation tracked in public reporting as APT27, Silk Typhoon, Emissary Panda, and Threat Group 3390. An FBI review cited by 银行信息安全 concluded that Yin in particular was responsible for the Treasury intrusion, which investigators placed between about September 2 and December 6, 2024. That window starts months before BeyondTrust’s December alarm, which fits a patient espionage job better than a one-day smash.

Authorities seized four domains used in phishing and virtual-private-server infrastructure tied to the broader activity: ecoatmosphere.org, newyorker.cloud, heidrickjobs.com, and maddmail.site. Investigators said a server leased by Yin held configuration files for Evilginx, a tool used to sit in the middle of a login and steal credentials, including multifactor challenges. OFAC also sanctioned Zhou and Shanghai Heiying Information Technology, a company prosecutors said he majority-owned and used to broker stolen data to the Chinese state. A reward offer was posted through the government’s Rewards for Justice program. None of that puts either man in a U.S. courtroom. Both remain in China, where an American indictment is a press statement unless a government decides to hand someone over, which Beijing does not do in cases it treats as state work.

卖家对信件有疑问

The durable lesson is not a new slogan about China. It is that a support contract can carry the same privilege as a system administrator. Treasury did not have to be phished if the company paid to fix its computers could be used as a tunnel. That pattern shows up again and again in public breach files: a remote-monitoring tool, a help-desk key, a contractor laptop. The 推动远程管理恶意软件的IRS-印花运动 进入收件箱时使用了同一个想法的表弟,欺骗人们自己安装了地道. 国库案漏出诡计. 隧道已经获得许可.

CISA said in early January 2025 that it was working with Treasury and BeyondTrust and that it had no indication the same path had been used against other federal agencies. That sentence is easy to over-read. It means investigators had not, at that moment, traced this key into a second department. It does not mean other agencies are free of vendor-key risk. Privileged-access companies sell to banks, hospitals, and governments because those customers want one pane of glass. One stolen pane is enough.

What remains unpublished is the only list that would tell the public how serious the December sessions were: which offices, which files, and whether any sanction that later became public was visible to the intruder while it was still a draft. Until Treasury or a court filing produces that list, the accurate account is the one Hardikar signed. A stolen BeyondTrust key opened several Departmental Offices workstations. Unclassified documents on those machines were exposed. The department attributed the intrusion to a China-sponsored operator, later named Yin Kecheng, and said it had cut the access off. Salt Typhoon was the telecom campaign running in parallel. Mixing the two makes a cleaner headline and a worse history.

相关文件收集于 黑客新闻, 技术,以及 美国新闻一个单独的突破,这个针对一个中国超级计算中心,而不是美国内阁部的突破,被涵盖在报告 盗取超级计算机数据的鬼故事.

杰弗里·柴尔斯
记者,编辑,网络安全与计算机科学专家,社交媒体管理,屋顶承包商.

相关条款

One Comment

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

Back to top button