Report: Chinese state-sponsored hacking group highly active

Advertisement

Advertise with us

BANGKOK (AP) — A Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China's government and security services, a private American cybersecurity firm said in a new report Thursday.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 30/03/2023 (1275 days ago), so information in it may no longer be current.

BANGKOK (AP) — A Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services, a private American cybersecurity firm said in a new report Thursday.

The hacking group, which the report calls RedGolf, shares such close overlap with groups tracked by other security companies under the names APT41 and BARIUM that it is thought they are either the same or very closely affiliated, said Jon Condra, director of strategic and persistent threats for Insikt Group, the threat research division of Massachusetts-based cybersecurity company Recorded Future.

Following up on previous reports of APT41 and BARIUM activities and monitoring the targets that were attacked, Insikt Group said it had identified a cluster of domains and infrastructure “highly likely used across multiple campaigns by RedGolf” over the past two years.

FILE - The flags of the U.S. and Chinese are displayed together on top of a trishaw in Beijing on Sept. 16, 2018. American cybersecurity firm says a Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services.(AP Photo/Andy Wong, File)
FILE - The flags of the U.S. and Chinese are displayed together on top of a trishaw in Beijing on Sept. 16, 2018. American cybersecurity firm says a Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services.(AP Photo/Andy Wong, File)

“We believe this activity is likely being conducted for intelligence purposes rather than financial gain due to the overlaps with previously reported cyberespionage campaigns,” Condra said in an emailed response to questions from The Associated Press.

China’s Foreign Ministry denied the accusations, saying, “This company has produced false information on so-called ‘Chinese hacker attacks’ more than once in the past. Their relevant actions are groundless accusations, far fetched, and lack professionalism.”

Chinese authorities have consistently denied any form of state-sponsored hacking, instead saying China itself is a major target of cyberattacks.

APT41 was implicated in a 2020 U.S. Justice Department indictment that accused Chinese hackers of targeting more than 100 companies and institutions in the U.S. and abroad, including social media and video game companies, universities and telecommunications providers.

In its analysis, Insikt Group said it found evidence that RedGolf “remains highly active” in a wide range of countries and industries, “targeting aviation, automotive, education, government, media, information technology and religious organizations.”

Insikt Group did not identify specific victims of RedGolf, but said it was able to track scanning and exploitation attempts targeting different sectors with a version of the KEYPLUG backdoor malware also used by APT41.

Insikt said it had identified several other malicious tools used by RedGolf in addition to KEYPLUG, “all of which are commonly used by many Chinese state-sponsored threat groups.”

In 2022, the cybersecurity firm Mandiant reported that APT41 was responsible for breaches of the networks of at least six U.S. state governments, also using KEYPLUG.

In that case, APT41 exploited a previously unknown vulnerability in an off-the-shelf commercial web application used by 18 states for animal health management, according to Mandiant, which is now owned by Google. It did not identify which states’ systems were compromised.

Mandiant called APT41 “a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.”

Cyber intelligence companies use different tracking methodologies and often name the threats they identify differently, but Condra said APT41, BARIUM and RedGolf “likely refer to the same set of threat actor or group(s)” due to similarities in their online infrastructure, tactics, techniques and procedures.

“RedGolf is a particularly prolific Chinese state-sponsored threat actor group that has likely been active for many years against a wide range of industries globally,” he said.

“The group has shown the ability to rapidly weaponize newly reported vulnerabilities and has a history of developing and using a large range of custom malware families.”

Insikt Group concluded that the use of KEYPLUG malware through certain types of command and control servers by RedGolf and similar groups is “highly likely to continue” and recommended that clients ensure they are blocked as soon as they are detected.

Report Error Submit a Tip

More Stories

Relief, reproach from law school staff after disgraced ex-dean’s arrest in France

Maggie Macintosh 5 minute read Preview

Relief, reproach from law school staff after disgraced ex-dean’s arrest in France

Maggie Macintosh 5 minute read Wednesday, Sep. 23, 2026

The overseas arrest of a disgraced former law dean who defrauded the University of Manitoba out of more than $600,000 is being met both with relief and renewed frustration in the local legal community.

Read
Wednesday, Sep. 23, 2026

Province hires 17 psychiatrists to work in Winnipeg, Selkirk

Free Press staff 2 minute read 2:35 PM CDT

The province has hired 17 psychiatrists this year in an attempt to alleviate pressure on hospital emergency rooms.

“Too often, people in crisis end up in the emergency room because they have nowhere else to turn,” Premier Wab Kinew said in a news release. “By hiring new psychiatrists, we’re improving access to care for patients.”

Of the 17 psychiatrists, 14 will work primarily in Winnipeg and three at the Selkirk Mental Health Centre. The additions increase capacity to assess and treat more patients, strengthen access to psychiatric care across the system and help reduce pressure on emergency departments, the premier noted.

The psychiatrists will work across hospital and community-based mental-health services, supporting assessment, treatment and followup care for Manitobans with a range of mental-health needs.

Firefighter admits to conditional sentence breach

Dean Pritchard 4 minute read Preview

Firefighter admits to conditional sentence breach

Dean Pritchard 4 minute read Yesterday at 2:01 AM CDT

A Winnipeg firefighter previously jailed for criminally harassing two different women has been released from custody after admitting to breaching a conditional sentence order.

Christopher Goethals, 59, was arrested July 21 after an alert from his ankle monitor six days earlier showed he had driven within 400 metres of the workplace of a former girlfriend he had been ordered to have no contact with.

Goethals pleaded guilty Wednesday to not being in possession of a copy of his conditional sentence order, a requirement of his sentence.

Crown attorney Amanda Heslop withdrew a breach charge related to Goethals’ electronic monitoring conditions and stayed a third charge of disobeying a court order.

Read
Yesterday at 2:01 AM CDT

Three wait times, one patient: resources matter

Rafiq Andani 5 minute read Preview

Three wait times, one patient: resources matter

Rafiq Andani 5 minute read 2:00 AM CDT

Manitoba announced at least $127 million for a 60-bed hospital, with expanded emergency and surgical space, dialysis and chemotherapy. It will serve surrounding communities and a town with more than 5,600 residents of Neepawa.

Read
2:00 AM CDT

Portage Avenue stabbing victim stumbled into nearby store for help

Morgan Modjeski and Malak Abas 3 minute read Preview

Portage Avenue stabbing victim stumbled into nearby store for help

Morgan Modjeski and Malak Abas 3 minute read 12:27 PM CDT

A 46-year-old man stabbed on Portage Avenue Wednesday afternoon is in hospital after stumbling into a downtown Dollarama and receiving medical care.

Police say the man had been confronted by several people on the 300 block of Portage and was stabbed with an unknown weapon at about 5:45. He found his way into the nearby Dollarama.

He was rushed to hospital in unstable condition but has since been upgraded to stable, the Winnipeg Police Service said in a Friday morning news release, noting it was unclear whether the attack was random.

Viv Ketchum, who works as the Indigenous ambassador for Impact Security stationed at the Dollarama located at 295 Portage, said she was in the rear of the shop when she heard a loud “groaning and moaning” through the store.

Read
12:27 PM CDT

Voter turnout suggests most of us don’t care who makes decisions about city services that affect our daily lives

Tom Brodbeck 5 minute read Preview

Voter turnout suggests most of us don’t care who makes decisions about city services that affect our daily lives

Tom Brodbeck 5 minute read 1:07 PM CDT

How bad would things have to get in Winnipeg to improve voter turnout in municipal elections?

Read
1:07 PM CDT