谷歌警告称,中国和俄罗斯黑客正在攻击美国的国防公司。
Google Warns Chinese And Russian Hackers Are Targeting US Defense Companies

原始链接: https://www.zerohedge.com/technology/google-warns-chinese-and-russian-hackers-are-targeting-us-defense-companies

## 网络攻击瞄准美国国防工业 谷歌威胁情报部门的一份最新报告显示,来自中国、俄罗斯和朝鲜的网络攻击针对美国国防工业基础激增。中国被确定为最活跃的威胁,持续以多种策略为目标国防和航空航天公司,经常利用网络“边缘设备”进行初始访问。中国组织还利用复杂的ORB网络进行侦察。 俄罗斯专注于支持在乌克兰战争中使用的技术公司,特别是那些参与无人机技术研发的公司。俄罗斯国家支持的黑客和黑客行动主义者都在试图入侵国防承包商。值得注意的是,攻击者甚至利用谷歌自身的人工智能工具Gemini进行情报收集。 朝鲜的威胁通过冒充IT人员渗透与国防相关的组织而增加,已经出现敏感数据被盗的事件。该报告强调了一种日益增长的趋势,即国家支持的黑客利用先进工具和欺骗性策略来获取对关键基础设施和数据的访问权限。

相关文章

原文

Authored by Jack Phillips via The Epoch Times,

An analysis released by Google this month showed that the U.S. defense industrial base—a network of public and private entities used to develop or maintain military weapons systems—has sustained cyberattacks from groups and criminal organizations from China, Russia, and North Korea in recent months.

The report, released on Feb. 10 by Google Threat Intelligence, found that the Chinese regime and associated groups continue “to represent by volume the most active threat to entities in the defense industrial base,” which it said can pose “significant risk to the defense and aerospace sector.”

Google’s report added that it “has observed more China-nexus cyber espionage missions directly targeting defense and aerospace industry than from any other state-sponsored actors over the last two years,” as such groups have “used a broad range of tactics in operations.”

“But the hallmark of many operations has been their exploitation of edge devices to gain initial access,” it said, referring to hardware components positioned at the edge of a network.

“We have also observed China-nexus threat groups leverage ORB networks for reconnaissance against defense industrial targets, which complicates detection and attribution.”

Late last year, Canadian and U.S. officials warned that Chinese state-backed hacking groups have targeted U.S. government entities and private companies, gaining long-term access to their systems.

In July 2025, Microsoft also warned it had observed two China-based hacking groups, Linen Typhoon and Violet Typhoon, using vulnerabilities in SharePoint, Microsoft’s collaboration software.

As for Russia, Google said in its report that groups associated with Moscow have focused on defense companies that support technologies used in the Russia–Ukraine war, namely companies linked to drones.

“As next-generation capabilities are being operationalized in this environment, Russia-nexus threat actors and hacktivists are seeking to compromise defense contractors alongside military assets and systems, with a focus on organizations involved with unmanned aircraft systems (UAS),” the tech giant said.

“This includes targeting defense companies directly, using themes mimicking their products and systems in intrusions against military organizations and personnel.”

State-sponsored hackers, meanwhile, have leveraged Google’s own AI tool, Gemini, during cyberattacks, it found.

One Chinese-linked organization known as “UNC2970” has frequently targeted defense companies and impersonated corporate recruiters in hacking campaigns, Google said.

They’ve used Gemini to conduct open-source intelligence to “profile high-value targets to support campaign planning and reconnaissance,” including searches for relevant information on defense and cybersecurity companies, it said.

The threat posed by North Korea has grown since 2019 as officials in the regime have attempted to pose as IT workers to apply for jobs at defense-related organizations, Google said.

Last July, the Department of Justice announced it had disrupted an operation that included searches of 29 locations in more than a dozen states suspected of being connected to laptops used, in part, to obtain remote jobs at more than 100 American companies.

In one instance, North Korea-linked actors stole sensitive data from a California defense company that was involved in AI development, according to Google.

In a separate incident, a Maryland-based individual was sentenced to 15 months in prison for facilitating a North Korean-linked scheme and coordinating with an alleged regime IT worker. The person, Minh Phuong Ngoc Vong, was hired by a Virginia-based company to perform software development for a defense contractor, it added.

Loading recommendations...

联系我们 contact @ memedata.com