The Register Home Page

back to article Microsoft: Another Chinese cyberspy crew targeting US critical orgs 'as of yesterday'

A Chinese government-linked group that Microsoft tracks as Storm-2077 has been actively targeting critical organizations and US government agencies as of yesterday, according to Redmond's threat intel team. The new-ish crew has been around since at least January, and while Microsoft declined to enumerate Storm-2077's victim …

  1. Sceptic Tank
    Big Brother

    Flood the market

    So here's now how you put all the generative AI to good use: let it generate authentic looking documents by the warehouse full, spin up an armada of honeypots serving up those documents, and make it impossible for the spies to tell the paydirt from the hogwash. A lot of them have such poor English skills that it won't even matter if the AI bot starts hallucinating badly at times.

    1. amanfromMars 1 Silver badge

      Re: The markets and media are already flooded with hogwash and bullshit, delusion and deceit

      Hallucinatory rhetoric masqerading as sterling oratory is already infesting and distressing markets with AI nowhere to be found and available to be blamed on the scene? Take a gander at the most recent of the torrents of nonsense from a Primed UKGBNI Janus and Puppet Mannequin? ....... PM speech on Plan for Change: 5 December 2024

      One just have to accept and realise that some folk presenting themselves as Prime Ministerial material are just not up to the task of providing assurance and displaying leadership and things are then naturally, logically, destined to get a great worse rather than better.

      Are you going to deny and dislike the evidence and common sense clearly enough shared in that private opinion based upon a general observation of a rapidly disintegrating public situation and thus give false hope and the succour of a poisoned chalice to chancers and usurpers in offices of state and ministries of government?

      :-) Best Give AI a Chance at delivering Peace and Prosperity with IT in Remote Command and Virtual Control of Universal Safety and Future Security ...... for when AI and IT are minded to, if ever you try to stop it there will be for leading opposing parties painful personal consequences and catastrophic party repercussions to suffer and deal with.

      1. Anonymous Coward
        Anonymous Coward

        Re: The markets and media are already flooded with hogwash and bullshit, delusion and deceit

        Let's stick to the topic and also avoid whatabouterism by not remarking that the US has been doing this for years with active support from the other Five Eyes nations.

        Bad China! Bad!

        Is that enough, US overlords?

        /s

    2. Kevin McMurtrie Silver badge

      Re: Flood the market

      So, pretty much Google search results.

  2. Irongut Silver badge

    > they really do embody the activity of persistence

    WTF is that supposed to mean?

    Is this DeGrippo a real person? All their quotes sound like a marketting LLM that can't string words together into a coherent sentence.

    1. Anonymous Coward
      Anonymous Coward

      Advanced Persistent Threat

      She's referring to the term Advanced Persistent Threat (APT), which is "a stealthy threat actor, typically a state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period."

      The whole quote is "They're a significant threat, particularly because they really do embody the activity of persistence," which means Storm-0227 in the embodiment of an APT.

      1. stiine Silver badge

        Re: Advanced Persistent Threat

        That wasn't the question. We were citicizing her attrocious grammar.

    2. Wang Cores Silver badge

      Sounds more like a person trying to copy without copying someone else's words.

  3. vtcodger Silver badge

    Maybe it's time to rethink this Connected World thing.

    It seems to me that the problem is simply that, for uses beyond entertainment and everyday commerce, the internet simply is not very secure. Further, contrary to the belief (more accurately -- forlorn hope) of way too many, it seems likely that there is no simple fix. If there were, it would have been implemented 25 years ago. Encryption and two factor authentication have their place. But they really are not universal solutions -- especially for the physically handicapped, those who lack reliable cell phone coverage (lots of us in rural America) and not loaded on top of the truly awful user interface on smartphones where they are likely to be a substantial usability issue for many of us.

    Truth of the matter is that if you are going to behave as the worlds' Protector General (liberals and many moderates) or the world's biggest and toughest bully (many conservatives) you simply can't put command and control of critical infrastructure on today's internet. Sooner or later you're going to annoy someone into retaliating, And retaliation via today's internet is quite inexpensive. Not to mention the ransomware problem.

    The only solution I'm aware of is that used by the military and some parts of government three decades ago when last I worked in that world. Physically completely separate installations for secure and non-secure work. Even that isn't secure if an employee leaks data or engages in sabotage -- but that's a different issue. The trouble with dual networks/critical data partitioning/etc is that it's quite expensive. My guess is that in many/most cases, the costs of operating that way would exceed any savings from operating online.

    I'm sure I'll garner a bunch of downvotes from those who don't want to hear what I'm saying. But kindly do me a favor, If you disagree, by all means downvote. But also compose a brief reply and explain why you disagree.

    1. Anonymous Coward
      Anonymous Coward

      Re: Maybe it's time to rethink this Connected World thing.

      I have to agree that the internet was not originally designed with security in mind. I disagree about the simple fix though. Everyone knows the fix: make security a priority. Make security as high a priority as profit and spend the time and money required. Employ enough staff who only deal with security, listen to them and pay for what they recommend. Even if it reduces profit or makes logging on take 30 seconds longer. Additionally, punish company leaders who don't do this. Most security breaches result in no more than the cost of getting back up and some, quickly forgotten, reputation damage. If a company handles the data of customers then there should be laws mandating minimum security measures and 3 months in prison for the CEO. Also, mandatory reporting of any breach, including the cause.

      If you are connected to the internet then there is risk but how many breaches do you hear about that would have been impossible to defend against? They must be very rare. Even Solarwinds/supply chain attacks can be somewhat defended against and the effects lessened. Especially if we had laws about how software updates are deployed (looking at you Crowdstrike). If you always assume that your network will be breached (while making sure that it's tough to do that) then you can maximise the monitoring and partitioning that you do.

      1. amanfromMars 1 Silver badge

        Re: Everyone knows the fix: make security a priority. @Bendacious

        Actually, virtually the only true fix is to do no evil, but the likely chance of humans pulling off that marvel are absolutely zero, therefore ........ you’re all certainly fated to be ever cursed with bullshitters and carpetbaggers, rogues and charlatans peddling their nonsense and vapourware as the real thing it is impossible to do without, and which delivers a constantly ignorant and toxic stream of arrogant and sad and certifiably mad suckers to outrageous misfortune to the very bitterest of ignominious ends.

        Who’s gonna like that and imagine it fixes anything anywhere anytime?

      2. Anonymous Coward
        Anonymous Coward

        Re: Maybe it's time to rethink this Connected World thing.

        What security measures? Just remember that you can't ever change your answer.

    2. Anonymous Coward
      Anonymous Coward

      Re: Maybe it's time to rethink this Connected World thing.

      The only solution I'm aware of is that used by the military and some parts of government three decades ago when last I worked in that world. Physically completely separate installations for secure and non-secure work. Even that isn't secure if an employee leaks data or engages in sabotage -- but that's a different issue. The trouble with dual networks/critical data partitioning/etc is that it's quite expensive. My guess is that in many/most cases, the costs of operating that way would exceed any savings from operating online.

      Actually, no. But you have to be willing to take some rather big steps.

      You also need to know how to play the political game to keep politicians out of it until you're absolutely sure it's ready for deployment.

  4. heyrick Silver badge

    Now, there's a question that all of this raises

    Are Chinese hackers really that much cleverer, or have many years of cost cutting efforts made "security" (note the scare quotes) absolutely shit and now the chickens are coming home to roost?

  5. Anonymous Coward
    Anonymous Coward

    Its still so weird to see fucking GirlVinyl of all people be important for one, and that Microsoft seems blissfully unaware of her "work" at ED for two.

  6. Groo The Wanderer Silver badge

    Yeah, well, at least the Chinese aren't trying to install NSA spyware like "Recall" on everyone's system and trying to pretend it would be useful.

    Migration of all personal projects to an Ubuntu 24.04 boot partition is complete. The only thing installed now under Wintendo is games.

    I don't trust recall for anything else.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like