• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

I wrote that Boomers were choking America’s economy. Their responses to me were revealing

2

If Elon Musk merges SpaceX with Tesla he'll create a $3.4 trillion behemoth—with zero profits

3

U.S. says deals with Iran for safe Hormuz transit are prohibited

1

I wrote that Boomers were choking America’s economy. Their responses to me were revealing

2

If Elon Musk merges SpaceX with Tesla he'll create a $3.4 trillion behemoth—with zero profits

3

U.S. says deals with Iran for safe Hormuz transit are prohibited
TechCybersecurity

Hackers From China Could Be Behind Ransomware Cyber Attacks in the U.S.

By
Reuters
Reuters
Down Arrow Button Icon
By
Reuters
Reuters
Down Arrow Button Icon
March 15, 2016, 4:53 PM ET
590855833
Photograph by Bill Hinton Photography—Getty Images/Moment Open

Hackers using tactics and tools previously associated with Chinese government-supported computer network intrusions have joined the booming cyber crime industry of ransomware, four security firms that investigated attacks on U.S. companies said.

Ransomware, which involves encrypting a target’s computer files and then demanding payment to unlock them, has generally been considered the domain of run-of-the-mill cyber criminals.

But executives of the security firms have seen a level of sophistication in at least a half dozen cases over the last three months akin to those used in state-sponsored attacks, including techniques to gain entry and move around the networks, as well as the software used to manage intrusions.

“It is obviously a group of skilled of operators that have some amount of experience conducting intrusions,” said Phil Burdette, who heads an incident response team at Dell SecureWorks.

Burdette said his team was called in on three cases in as many months where hackers spread ransomware after exploiting known vulnerabilities in application servers. From there, the hackers tricked more than 100 computers in each of the companies into installing the malicious programs.

The victims included a transportation company and a technology firm that had 30% of its machines captured.

 

 

Security firms Attack Research, InGuardians and G-C Partners, said they had separately investigated three other similar ransomware attacks since December.

Although they cannot be positive, the companies concluded that all were the work of a known advanced threat group from China, Attack Research Chief Executive Val Smith told Reuters.

The ransomware attacks have not previously been reported. None of the companies that were victims of the hackers agreed to be identified publicly.

Asked about the allegations, China’s Foreign Ministry said on Tuesday that if they were made with a “serious attitude” and reliable proof, China would treat the matter seriously.

But ministry spokesman Lu Kang said China did not have time to respond to what he called “rumors and speculation” about the country’s online activities.

The security companies investigating the advanced ransomware intrusions have various theories about what is behind them, but they do not have proof and they have not come to any firm conclusions.

[fortune-brightcove videoid=4503529281001]

 

Most of the theories flow from the possibility that the Chinese government has reduced its support for economic espionage, which it pledged to oppose in an agreement with the United States late last year. Some U.S. companies have reported a decline in Chinese hacking since the agreement.

Smith said some government hackers or contractors could be out of work or with reduced work and looking to supplement their income via ransomware.

It is also possible, Burdette said, that companies which had been penetrated for trade secrets or other reasons in the past were now being abandoned as China backs away, and that spies or their associates were taking as much as they could on the way out. In one of Dell’s cases, the means of access by the team spreading ransomware was established in 2013.

The cyber security experts could not completely rule out more prosaic explanations, such as the possibility that ordinary criminals had improved their skills and bought tools previously used only by governments.

Dell said that some of the malicious software had been associated by other security firms with a group dubbed Codoso, which has a record of years of attacks of interest to the Chinese government, including those on U.S. defense companies and sites that draw Chinese minorities.

PAYMENT IN BITCOIN

Ransomware has been around for years, spread by some of the same people that previously installed fake antivirus programs on home computers and badgered the victims into paying to remove imaginary threats.

In the past two years, better encryption techniques have often made it impossible for victims to regain access to their files without cooperation from the hackers. Many ransomware payments are made in the virtual currency Bitcoin and remain secret, but institutions including a Los Angeles hospital have gone public about ransomware attacks.

Ransomware operators generally set modest prices that many victims are willing to pay, and they usually do decrypt the files, which ensures that victims will post positively online about the transaction, making the next victims who research their predicament more willing to pay.

Security software companies have warned that because the aggregate payoffs for ransomware gangs are increasing, more criminals will shift to it from credit card theft and other complicated scams.

The involvement of more sophisticated hackers also promises to intensify the threat.

InGuardians CEO Jimmy Alderson said one of the cases his company investigated appeared to have been launched with online credentials stolen six months earlier in a suspected espionage hack of the sort typically called an Advanced Persistent Threat, or APT.

“The tactics of getting access to these networks are APT tactics, but instead of going further in to sit and listen stealthily, they are used for smash-and-grab,” Alderson said.

About the Author
By Reuters
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Data centers could help determine who wins the next war, and a shortage of compute would be ‘catastrophic,’ retired general says
AIMilitary
Data centers could help determine who wins the next war, and a shortage of compute would be ‘catastrophic,’ retired general says
By Jason MaMay 31, 2026
8 hours ago
A Gen Z YouTube mogul’s $10 million horror movie almost beat Star Wars at the box office this weekend
Arts & EntertainmentMovies
A Gen Z YouTube mogul’s $10 million horror movie almost beat Star Wars at the box office this weekend
By Lindsey Bahr and The Associated PressMay 31, 2026
9 hours ago
AI will make the ‘tech bro’ class even richer, Nobel laureate Joe Stiglitz says, just as it can take your job
AIJobs
AI will make the ‘tech bro’ class even richer, Nobel laureate Joe Stiglitz says, just as it can take your job
By Catherina GioinoMay 31, 2026
11 hours ago
peter thiel
AIskills
Forget the STEM safety net. Peter Thiel warns AI is a bigger threat to technical roles than to creative thinkers
By Jake AngeloMay 31, 2026
11 hours ago
CEOs blame AI for layoffs, but an MIT professor says it fits a long-running pattern to find a cover story. ‘They’ve been saying that for 20 years’
AIthe future of work
CEOs blame AI for layoffs, but an MIT professor says it fits a long-running pattern to find a cover story. ‘They’ve been saying that for 20 years’
By Marco Quiroz-GutierrezMay 31, 2026
12 hours ago
Experimental pill nearly doubles survival time for people with advanced pancreatic cancer. ‘I actually started crying’
HealthHealth
Experimental pill nearly doubles survival time for people with advanced pancreatic cancer. ‘I actually started crying’
By Lauran Neergaard and The Associated PressMay 31, 2026
12 hours ago

Most Popular

I wrote that Boomers were choking America’s economy. Their responses to me were revealing
Personal Finance
I wrote that Boomers were choking America’s economy. Their responses to me were revealing
By Nick LichtenbergMay 31, 2026
17 hours ago
If Elon Musk merges SpaceX with Tesla he'll create a $3.4 trillion behemoth—with zero profits
Investing
If Elon Musk merges SpaceX with Tesla he'll create a $3.4 trillion behemoth—with zero profits
By Shawn TullyMay 31, 2026
21 hours ago
U.S. says deals with Iran for safe Hormuz transit are prohibited
Politics
U.S. says deals with Iran for safe Hormuz transit are prohibited
By Jack Wittels and BloombergMay 30, 2026
2 days ago
Ex–Google CEO Eric Schmidt warns U.S. tech workers: Competing with China’s grueling 12-hour workdays means sacrificing work-life balance
Future of Work
Ex–Google CEO Eric Schmidt warns U.S. tech workers: Competing with China’s grueling 12-hour workdays means sacrificing work-life balance
By Marco Quiroz-GutierrezMay 30, 2026
1 day ago
When loyalty is rewarded: Top earners who stay in their jobs get much larger pay increases than those who switch
Future of Work
When loyalty is rewarded: Top earners who stay in their jobs get much larger pay increases than those who switch
By Jacqueline MunisMay 30, 2026
2 days ago
Meet the Black women on Fortune's Most Powerful Women list shaping business leadership
MPW
Meet the Black women on Fortune's Most Powerful Women list shaping business leadership
By Cheyann HarrisMay 29, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.