Security

Chinese government hackers targeted US internet providers with zero-day exploit, researchers say

Comment

A worker adjusts server cables at a data center inside the VK Company Ltd. office in Moscow, Russia, on Wednesday, Jan. 19, 2022.
Image Credits: Andrey Rudkov/Bloomberg / Getty Images

A group of hackers linked to the Chinese government used a previously unknown vulnerability in software to target U.S. internet service providers, security researchers have found. 

The group known as Volt Typhoon was exploiting the zero-day flaw — meaning the software maker was unaware of it before having time to patch — in Versa Director, a piece of software made by Versa Networks, according to researchers at Black Lotus Labs, which is part of cybersecurity firm Lumen.

Versa sells software to manage network configurations, and is used by internet service providers (ISPs) and managed service providers (MSPs), which makes Versa “a critical and attractive target” for hackers, the researchers wrote in a report published on Tuesday

This is the latest discovery of hacking activities carried out by Volt Typhoon, a group that is believed to be working for the Chinese government. The group focuses on targeting critical infrastructure, including communication and telecom networks, with the goal of causing “real-world harm” in the event of a future conflict with the United States. U.S. government officials testified earlier this year that the hackers aim to disrupt any U.S. military response in a future anticipated invasion of Taiwan.

The hackers’ goals, according to Black Lotus Labs’ researchers, were to steal and use credentials on downstream customers of the compromised corporate victims. In other words, the hackers were targeting Versa servers as crossroads where they could then pivot into other networks connected to the vulnerable Versa servers, Mike Horka, the security researcher who investigated this incident, told TechCrunch in a call. 

Contact Us

Do you have more information about Volt Typhoon, or other government-sponsored hacking activities? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

“This wasn’t limited to just telecoms, but managed service providers and internet service providers,” said Horka. “These central locations that they can go after, which then provide additional access.” Horka said these internet and networking companies are targets themselves, “very likely because of the access that they could potentially provide to additional downstream customers.”

Horka said he found four victims in the United States, two ISPs, one MSP and an IT provider; and one victim outside of the U.S., an ISP in India. Black Lotus Labs did not name the victims. 

Versa’s Chief Marketing Officer Dan Maier told TechCrunch in an email that the company has patched the zero-day identified by Black Lotus Labs.

“Versa confirmed the vulnerability and issued an emergency patch at that time. We have since issued a comprehensive patch and distributed this to all customers,” said Maier, adding that researchers warned the company of the flaw in late June.  

Maier told TechCrunch that Versa itself was able to confirm the flaw and observe the “APT attacker” taking advantage of it. 

Black Lotus Labs said it alerted the U.S. cybersecurity agency CISA of the zero-day vulnerability and the hacking campaign. On Friday, CISA added the zero-day to its list of vulnerabilities that are known to have been exploited. The agency warned that “these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.”

More TechCrunch

In an effort to improve its security measures, Lyft announced Tuesday a new rider verification pilot program to help drivers verify riders’ identities and ensure that they are indeed who they say…

Lyft follows in Uber’s footsteps with a rider verification program

Update: The Polaris Dawn launch has been pushed back a day and is now planned for Wednesday, August 28 after a helium leak was detected ahead of its takeoff. After…

Polaris Dawn will push the limits of SpaceX’s human spaceflight program — here’s how to watch it launch live

Meta will be shutting down Spark AR, its platform of third-party AR tools and content, effective January 14, 2025.

Creators are angered by Meta’s Spark AR shutdown, saying they’ll be out of work with little notice

Waymo said Tuesday it will start offering riders 24/7 access to curbside pickups and dropoffs at Phoenix Sky Harbor International Airport terminals 3 and 4 — yet another example of…

Waymo expands its curbside robotaxi service to Phoenix airport

Some believe open source AI is a way to break out of the familiar proprietary software quagmire that the technology has predictably fallen into. Hugging Face’s Irene Solaiman and AI2’s…

Is open source AI possible, let alone the future? Find out at TechCrunch Disrupt 2024

It’s back-to-school season, and that often means a surge in expenses. Or perhaps you’ve recently graduated and are navigating the job hunt. Either way, your wallet might be feeling the…

Students and recent grads: Save on TechCrunch Disrupt 2024 tickets

Snapchat is officially rolling out native support for iPad, the company announced in the app’s latest release notes. Since Snapchat’s launch in 2011, the social networking app has only been…

13 years later, Snapchat finally rolls out native support for iPads

At the end of the six-month effort, the startup is aiming to have prototype parts to show to NASA.

Whisper Aero is working with NASA to bring its ultra-quiet tech to outer space

A group of hackers linked to the Chinese government used a previously unknown vulnerability in software to target U.S. internet service providers, security researchers have found.  The group known as…

Chinese government hackers targeted US internet providers with zero-day exploit, researchers say
Image Credits: Andrey Rudkov/Bloomberg / Getty Images

Elon Musk’s X has already declared it aims to compete with LinkedIn for job listings and PayPal for payments. Now, it wants to take on the likes of Zoom, Google…

X is testing a video conferencing tool

San Francisco-based data infrastructure startup Cribl has raised $319 million in a Series E funding tranche led by new investor GV (Alphabet’s corporate venture arm) with participation from GIC, CapitalG,…

Data infrastructure startup Cribl raises $319M at a $3.5B valuation

Apple has struck a deal with Airtel to provide the Indian telecom giant’s subscribers with exclusive offers for its music streaming service. The partnership, announced on Tuesday, will also see…

Apple and Airtel partner for streaming deals in India

GrubMarket, the $3.6 billion food delivery and supply chain startup backed by Tiger Global, BlackRock and nearly 100 other investors, has snapped up another food delivery startup on its consolidation…

Food delivery is seeing more consolidation: GrubMarket snaps up FreshGoGo

Coined as the “Everyday Influencer” platform, Mavely is a social commerce app that enables users to earn commission by sharing and recommending products from more than 1,250 brands, including Adidas,…

Mavely’s platform for everyday influencers is taking off

Supio uses generative AI to automate bulk data collection and aggregation for legal teams. It emerged from stealth Tuesday with a $25 million investment.

Supio brings generative AI to personal injury cases

Planera, scheduling and planning software for commercial construction projects, has raised $13.5 million to expand its reach and help general contractors with more features.

Planera raises $13.5M to help solve the gnarly problem of scheduling for construction contractors

The world of metal 3D printing has been in-flux this past year, the most notable example being Nano Dimension’s acquisition of Desktop Metal.

Markforged adds metal printing to its industrial 3D printer

nOps sells software designed to “optimize” the budgets that businesses allocate to cloud products and services.

nOps lands $30M to optimize AWS customers’ cloud spend

When Pavel Durov, founder and CEO of messaging app Telegram, was arrested on August 24, French authorities did not respond to requests for comment. The secrecy of pre-trial investigations and…

Paris court explains why it’s arrested Telegram founder, Pavel Durov

Given India’s language diversity, digital content companies already face a challenge in trying to show and translate content accurately. Google is facing a similar problem with AI overviews recently rolled…

Google’s AI overviews in Hindi need a quality upgrade

Two of Africa’s largest B2B e-commerce platforms, Wasoko and MaxAB, have finally completed the continent’s much-talked-about merger.

African B2B e-commerce startups Wasoko and MaxAB complete merger: Interview with co-CEO Daniel Yu

Clockwise is changing up its interface with an AI-powered assistant called Prism that lets you manage calendar invites and scheduling with text prompts.

Calendar tool Clockwise adds new AI-powered interface called Prism

Many VC funds, especially recent vintages, have failed to return money to their investors. Swiss VC firm Redalpine is one exception, and this largely explains why its newly announced $200…

Science-heavy Swiss VC firm Redalpine raises fresh $200M fund for early-stage investments

Pavel Durov, the founder of the messaging platform Telegram, has been in the headlines since his arrest at a private airport near Paris on Saturday, reportedly in connection with an…

Wait, what? Pavel Durov says he has fathered more than 100 children

Elon Musk has come out in support of California’s SB 1047, a bill that requires makers of very large AI models to create and document safeguards against those models causing…

Elon Musk unexpectedly offers support for California’s AI bill

OpenAI, Adobe and Microsoft have thrown their support behind a California bill requiring tech companies to label AI-generated content, according to letters from the companies viewed by TechCrunch. The bill…

OpenAI, Adobe and Microsoft support California bill requiring watermarks on AI content

Hello and welcome back to TechCrunch Space. NASA leadership have made their decision: Starliner will be coming back to Earth — empty. More on that below. Want to reach out…

TechCrunch Space: The Starliner saga comes to a close — for now

Apple announced today that Chief Financial Officer Luca Maestri will step away from his executive role, effective January 1. Kevan Parekh, Apple’s current VP of Financial Planning, will be promoted…

Apple will replace CFO Luca Maestri next year

Generative AI models aren’t actually humanlike. They have no intelligence or personality — they’re simply statistical systems predicting the likeliest next words in a sentence. But like interns at a…

Anthropic publishes the ‘system prompts’ that make Claude tick

The arrest of Telegram founder and CEO Pavel Durov in France is starting to impact the app’s traction and ranking. On Saturday, the founder was arrested for allegedly allowing illegal…

Durov arrest boosts Telegram app downloads