Report: Chinese state-sponsored hacking group highly active

Advertisement

Advertise with us

BANGKOK (AP) — A Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China's government and security services, a private American cybersecurity firm said in a new report Thursday.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 30/03/2023 (1274 days ago), so information in it may no longer be current.

BANGKOK (AP) — A Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services, a private American cybersecurity firm said in a new report Thursday.

The hacking group, which the report calls RedGolf, shares such close overlap with groups tracked by other security companies under the names APT41 and BARIUM that it is thought they are either the same or very closely affiliated, said Jon Condra, director of strategic and persistent threats for Insikt Group, the threat research division of Massachusetts-based cybersecurity company Recorded Future.

Following up on previous reports of APT41 and BARIUM activities and monitoring the targets that were attacked, Insikt Group said it had identified a cluster of domains and infrastructure “highly likely used across multiple campaigns by RedGolf” over the past two years.

FILE - The flags of the U.S. and Chinese are displayed together on top of a trishaw in Beijing on Sept. 16, 2018. American cybersecurity firm says a Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services.(AP Photo/Andy Wong, File)
FILE - The flags of the U.S. and Chinese are displayed together on top of a trishaw in Beijing on Sept. 16, 2018. American cybersecurity firm says a Chinese hacking group that is likely state-sponsored and has been linked previously to attacks on U.S. state government computers is still “highly active” and is focusing on a broad range of targets that may be of strategic interest to China’s government and security services.(AP Photo/Andy Wong, File)

“We believe this activity is likely being conducted for intelligence purposes rather than financial gain due to the overlaps with previously reported cyberespionage campaigns,” Condra said in an emailed response to questions from The Associated Press.

China’s Foreign Ministry denied the accusations, saying, “This company has produced false information on so-called ‘Chinese hacker attacks’ more than once in the past. Their relevant actions are groundless accusations, far fetched, and lack professionalism.”

Chinese authorities have consistently denied any form of state-sponsored hacking, instead saying China itself is a major target of cyberattacks.

APT41 was implicated in a 2020 U.S. Justice Department indictment that accused Chinese hackers of targeting more than 100 companies and institutions in the U.S. and abroad, including social media and video game companies, universities and telecommunications providers.

In its analysis, Insikt Group said it found evidence that RedGolf “remains highly active” in a wide range of countries and industries, “targeting aviation, automotive, education, government, media, information technology and religious organizations.”

Insikt Group did not identify specific victims of RedGolf, but said it was able to track scanning and exploitation attempts targeting different sectors with a version of the KEYPLUG backdoor malware also used by APT41.

Insikt said it had identified several other malicious tools used by RedGolf in addition to KEYPLUG, “all of which are commonly used by many Chinese state-sponsored threat groups.”

In 2022, the cybersecurity firm Mandiant reported that APT41 was responsible for breaches of the networks of at least six U.S. state governments, also using KEYPLUG.

In that case, APT41 exploited a previously unknown vulnerability in an off-the-shelf commercial web application used by 18 states for animal health management, according to Mandiant, which is now owned by Google. It did not identify which states’ systems were compromised.

Mandiant called APT41 “a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.”

Cyber intelligence companies use different tracking methodologies and often name the threats they identify differently, but Condra said APT41, BARIUM and RedGolf “likely refer to the same set of threat actor or group(s)” due to similarities in their online infrastructure, tactics, techniques and procedures.

“RedGolf is a particularly prolific Chinese state-sponsored threat actor group that has likely been active for many years against a wide range of industries globally,” he said.

“The group has shown the ability to rapidly weaponize newly reported vulnerabilities and has a history of developing and using a large range of custom malware families.”

Insikt Group concluded that the use of KEYPLUG malware through certain types of command and control servers by RedGolf and similar groups is “highly likely to continue” and recommended that clients ensure they are blocked as soon as they are detected.

Report Error Submit a Tip

More Stories

Today’s horoscope

Georgia Nicols 4 minute read Preview

Today’s horoscope

Georgia Nicols 4 minute read Yesterday at 2:00 AM CDT

MOON ALERT: Caution. Avoid shopping (except food and gas) and important decisions from 3 a.m. until 10:55 p.m. After that, the moon moves from Aquarius into Pisces.

ARIES (March 21-April 19)

There’s a moon alert all day so restrict spending to food and gas, and postpone important decisions. However, you are the artisan of the zodiac, and a moon alert is an excellent time for socializing and making art.

TAURUS (April 20-May 20)

Read
Yesterday at 2:00 AM CDT

Oilers stymie Jets again

Ken Wiebe 6 minute read Preview

Oilers stymie Jets again

Ken Wiebe 6 minute read Tuesday, Sep. 22, 2026

Were this a game that actually counted in the standings, the reaction from Winnipeg Jets head coach Scott Arniel probably wouldn’t have been nearly as composed.

The video evidence suggests the Edmonton Oilers had at least four players on the ice during a line change that turned into a two-on-one rush that finished with Zack Hyman setting up Viljami Marjala for a goal at 1:26 of overtime.

That left the Jets on the receiving end of a 2-1 overtime loss to sit with a pre-season record of 1-1-1.

“It was a pretty good jump,” said Arniel, who was more concerned about the shot from defenceman Dylan Samberg that helped spring the Oilers on the odd-man rush. “I’m not real keen on the slapper missing the net and going all the way down. I’m more concerned about that. It is what it is. Tough one for (Jets goaltender) Dom (DiVincentiis), because he was fantastic.”

Read
Tuesday, Sep. 22, 2026

You’d only regret not acting on longtime crush

Maureen Scurfield 4 minute read 2:00 AM CDT

DEAR MISS LONELYHEARTS: For years I had a big crush on my older sister’s hot-looking best friend who was often over at our house. My sister found out about my crush and told me, “I’ll kill you, if you go after my friend!” I was crushed at the time, and kept my distance, although I still had erotic dreams about that girl a lot.

This fall my sister is going to university out of province, and her friend is still here in Winnipeg, going to the same college as I am. I ran into her recently at a mall. She looked me up and down and said, “Wow!” Was she teasing me like a little boy or was she actually flirting with me now my sister’s out of the way?

More importantly, do I need my sister’s permission to ask out this friend of hers now she lives in Ontario? Please help!

— Still Awkward, But Interested, North Kildonan

BRANDON — A western Manitoba potash producer could generate as much as $450 million in annual sales if it expands operations over the next five years under an ambitious mining plan touted by the provincial government.

The Potash Agri Development Corp. of Manitoba (PADCOM) expansion plays a vital role in the province’s move to increase its critical mineral output, company president Daymon Guillas said this week.

“PADCOM, without a doubt, can double, triple, quadruple our production in the next five years.”

PADCOM, Manitoba’s first and only potash mine, located near Harrowby in the Municipality of Russell-Binscarth, produces about 250,000 tonnes annually, with its product sold in Canada and shipped through the Port of Churchill.

If you feel stuck on repeat, reach out for advice

Maureen Scurfield 5 minute read Yesterday at 2:00 AM CDT

DEAR MISS LONELYHEARTS: My ex-mother-in-law and I ran into each other at a political do and had a great old time. I like her much better now than when I was married to her daughter. But she enjoyed mentioning that her daughter is now much happier in her new marriage to someone other than me. That’s rude, but I was actually happy to hear it.

Then she had the nerve to ask me if I felt better-suited to my new wife, and I said, “No, because she’s a lot like your daughter.” That was an awful thing for me to finally realize fully, and in front of my ex-mother-in-law.

Is it true people keep marrying the same type of person over and over again, and just keep trying to do better each time?

— Lying Awake, Tuxedo

Well-known Brandon-born rock drummer Sutherland dies at age 58

Rylee Gerrard 3 minute read Preview

Well-known Brandon-born rock drummer Sutherland dies at age 58

Rylee Gerrard 3 minute read Yesterday at 7:19 PM CDT

Chris (Suds) Sutherland, a Brandon-born drummer who was the driving force behind many top artists in the Canadian music industry, has died at 58.

Sutherland is widely praised throughout North America as a talented percussionist with an extensive discography.

He performed with such Canadian music legends as Kim Mitchell, Randy Bachman, Burton Cummings, Streetheart and others.

Sutherland brought presence and “plow” when he played, Tina Faye said about her husband.

Read
Yesterday at 7:19 PM CDT