Tuesday, February 25, 2025
HomeCyber Security NewsUS Charged Chinese Hackers for Exploiting Thousands of Firewall

US Charged Chinese Hackers for Exploiting Thousands of Firewall

Published on

SIEM as a Service

Follow Us on Google News

The US Treasury Department’s Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence Information Technology Company and its employee Guan Tianfeng for their involvement in the April 2020 global firewall compromise, which targeted numerous US critical infrastructure companies. 

The Department of Justice has also indicted Guan for the same cybercrime, and the State Department has offered a $10 million reward for information on the individuals involved, highlighting the US government’s commitment to combating Chinese cyber threats and holding malicious actors accountable.

Zero-day Vulnerability Exploited

Guan Tianfeng exploited a zero-day vulnerability in a firewall product to compromise approximately 81,000 firewalls worldwide, including 36 critical infrastructure systems in the US, which aimed to steal sensitive data and deploy the Ragnarok ransomware. 

It could have potentially disabled security measures and encrypted critical systems, leading to severe consequences, such as oil rig malfunctions and potential loss of life, while timely detection and mitigation of the attack prevented significant damage.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Guan, a Chinese cybersecurity researcher affiliated with Sichuan Silence, a Chinese government contractor, exploited a zero-day vulnerability to compromise a US firewall in April 2020 by leveraging tools and techniques provided by Sichuan Silence, enabling access to sensitive US networks. 

Sichuan Silence, known for its involvement in cyber espionage and offensive cyber operations, has been sanctioned by the US Office of Foreign Assets Control (OFAC) for these malicious activities, which pose a significant threat to US national security.

OFAC has imposed sanctions on designated persons, blocking their U.S. assets and prohibiting transactions with them, as entities 50% or more owned by blocked persons are also subject to these restrictions. 

Transactions involving sanctioned individuals or entities are not permitted to be pursued by individuals or entities based in the United States. 

Financial institutions and other persons involved in such transactions may face sanctions or enforcement actions, as OFAC’s sanctions aim to induce behavioral change and may be lifted under specific conditions.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free 

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

LightSpy Malware Expands With 100+ Commands to Target Users Across All Major OS Platforms

The LightSpy surveillance framework has significantly evolved its operational capabilities, now supporting over 100...

Critical RCE Vulnerability in MITRE Caldera – Proof of Concept Released

A critical remote code execution (RCE) vulnerability has been uncovered in MITRE Caldera, a...

CISA Alerts: Oracle Agile Vulnerability Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding...

Hackers Evade Outlook Spam Filters to Deliver Malicious ISO Files

A newly discovered technique allows threat actors to circumvent Microsoft Outlook’s spam filters to...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

LightSpy Malware Expands With 100+ Commands to Target Users Across All Major OS Platforms

The LightSpy surveillance framework has significantly evolved its operational capabilities, now supporting over 100...

Critical RCE Vulnerability in MITRE Caldera – Proof of Concept Released

A critical remote code execution (RCE) vulnerability has been uncovered in MITRE Caldera, a...

CISA Alerts: Oracle Agile Vulnerability Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding...