MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: China-Backed Hackers Used Microsoft Flaw in Attacks, Defenders Say
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$65,808.00-3.75%
  • ethereumEthereum(ETH)$1,983.40-2.94%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$609.01-2.56%
  • rippleXRP(XRP)$1.32-1.78%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$82.33-4.27%
  • tronTRON(TRX)$0.309624-0.29%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.38%
  • dogecoinDogecoin(DOGE)$0.089957-1.15%
Interviews

China-Backed Hackers Used Microsoft Flaw in Attacks, Defenders Say

Last updated: July 22, 2025 8:50 am
Published: 8 months ago
Share

Hackers connected to the Chinese government were behind at least some of the widespread attacks in the past few days on organizations that use collaboration software from Microsoft, defenders working on the intrusions said in interviews.

The breaches in the United States and other countries took advantage of a disastrous security flaw that drew attention this month, after Microsoft issued a patch that fixed only part of the problem in SharePoint, which is widely used to coordinate work on documents and projects.

“We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor,” said Charles Carmakal, chief technology officer of Google’s Mandiant Consulting.

Another researcher, who, like others, spoke on the condition of anonymity because the inquiry is still underway, said federal investigators have evidence of U.S.-based servers linked to compromised SharePoint systems connecting to internet protocol addresses inside China on Friday and Saturday.

The FBI, the White House, and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency declined to comment Monday.

Two other responders working with the U.S. government said they had identified early attacks from China as well. The Chinese Embassy in Washington did not immediately respond to a request for comment.

The attacks allowed hackers to extract cryptographic keys from servers run by Microsoft clients. Those keys, in turn, would let them install anything, including back doors that they could use to return. Federal and state agencies were affected, researchers previously told The Washington Post, but it remains unclear which of them were vulnerable to follow-up attacks.

Only versions of SharePoint that are hosted by the customer, not those in the cloud, are vulnerable. Microsoft issued effective patches for the last of the exposed versions by Monday.

While installing the patches should prevent new intrusions, customers also need to change the machine’s digital keys, apply anti-malware software and hunt for any breaches that have already occurred, Microsoft said.

Some of the early targets of the attack were entities that would interest the Chinese government, two of the responders said. But a wide range of attackers were now trying similar grabs, others said, looking to steal corporate secrets or install ransomware that encrypts key files until payments are made.

“It’s critical to understand that multiple actors are now actively exploiting this vulnerability. We fully anticipate that this trend will continue, as various other threat actors, driven by diverse motivations, will leverage this exploit as well,” Carmakal said.

Piet Kerkhofs, CTO and co-founder of Europe-based Eye Security, said the SharePoint breaches share characteristics with other compromises that security researchers have attributed to China-based hackers.

For instance, hackers this month exploited a vulnerability in Citrix’s NetScaler virtual desktop that some researchers saw being used by Chinese actors, Kerkhofs said. That hack was similar to the SharePoint compromise in that it turned a freshly discovered vulnerability into an “exploit” or weapon – in “extremely fast” order, “hours to days,” he said.

Another instance was China’s global compromise of Microsoft Exchange email servers in early 2021. That case involved hackers sponsored by the Chinese government conducting widespread exploitation of core Microsoft software – its Exchange email server software.

That breach has been attributed to group that Microsoft calls Silk Typhoon, which is linked to China’s Ministry of State Security. It is one of the most technically advanced hacking groups in the world and has been striking sensitive U.S. targets at an increased rate in the past year, The Post reported last week.

Silk Typhoon has broken into multiple U.S. federal agencies in the past and more recently hit multiple ministries in Europe, The Post reported.

Read more on japannews.yomiuri.co.jp

This news is powered by japannews.yomiuri.co.jp japannews.yomiuri.co.jp

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Gold sales hit three-year high in October, silver sales surge 83% in a month – Perth Mint
Currency crisis haunts listed firms
Political leaders confront security concerns — and fear — after Kirk’s assassination
This actor was trolled for starting new life in old age – OrissaPOST
Android Interview Mastery: 15 Essential Questions About Kotlin Flow and Parallel Execution

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Criticism of
Next Article NewsBusters Podcast: Our PBS/NPR Victory Lap, Leftist Bias Defunded – Conservative Angle
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d