Chinese Hackers Using Everyday Devices to Target UK Firms
Chinese Hackers Using Everyday Devices to Target UK Firms

British businesses are being urged to step up vigilance against a China-linked hacking ploy that uses everyday devices for espionage. The UK’s National Cyber Security Centre (NCSC) and agencies in nine other countries have warned of persistent attempts by Beijing-backed groups to hack equipment such as wifi routers to launch cyber-attacks.

Known as “covert networks” or “botnets”, these attacks typically target vulnerable equipment – such as devices that have not had a software update or are old – as a base for activities including surveillance and data theft. The NCSC said the technique was used by the majority of China-linked hackers.

Richard Horne, the centre’s chief executive, said on Wednesday that China’s intelligence and military agencies had an “eye-watering level of sophistication in their cyber-operations”. Speaking at the NCSC’s annual conference in Glasgow, he said: “We face more than just a capable cyber-threat but a peer competitor in cyberspace.”

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

The advisory notice from the NCSC and cyber-agencies in countries including the US, Australia, Canada and Germany warns there has been a “major shift” in Chinese tactics to using internet-connected devices as a means of obscuring where an attack comes from. The most commonly hijacked devices are routers, but printers and web cameras are also vulnerable.

Security officials compare routers to virtual private networks, which allow web users to obscure their location. They say a household’s wifi router could be used as a conduit for attacking an unrelated major company. While the NCSC guidance is not directed at members of the public, it urges companies to take steps such as mapping out IT systems, using multifactor authentication, and limiting network connections to external devices.

The centre said in the advisory notice published on Thursday: “The NCSC believes that the majority of China-nexus threat actors are using these networks, that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors.” A China-backed group, dubbed Volt Typhoon, has been flagged as a user of covert networks and has burrowed into key US infrastructure including rail, aviation and water systems.

Pickt after-article banner — collaborative shopping lists app with family illustration