# Disruptive Chinese malware, Storm-0558 fallout and SEC cyber rules

By [Nathaniel Mott](https://readme.synack.com/author/nathaniel-mott)

Published:  
July 30, 2023

###### Harold Mendoza / Unsplash

_Welcome to Changelog for 7/30/23, published by_ [_Synack_](/content/site-root.html) _! Nathaniel Mott here, still parsing the New York Times’_ [_blockbuster report_](https://www.nytimes.com/2023/07/29/us/politics/china-malware-us-military-bases-taiwan.html) _Saturday citing intelligence that China “has hidden deep inside the networks controlling power grids, communications systems and water supplies that feed military bases in the United States and around the world.” It’s not that China doesn’t pose a pervasive cyberthreat to U.S. interests — I’ve just seen threats to power grids overstated in the past, so I’m not sure what to make of “Volt Typhoon.” But speaking of China:_

## The payload

U.S. senators don’t like it when Chinese hackers [access government emails](https://readme.security/top-cyber-takeaways-from-the-intelligence-and-national-security-summit-ec03f624220d).

A quick refresher: Microsoft [said](https://blogs.microsoft.com/on-the-issues/2023/07/11/mitigation-china-based-threat-actor/) on July 11 that a China-linked group it’s tracking as Storm-0558 had “gained access to email accounts affecting approximately 25 organizations.” That included the U.S. State Department and Department of Commerce, among others, and now over a dozen senators want more information about the hack.

_Newsweek_ [reported](https://www.newsweek.com/microsoft-china-state-department-email-hack-antivirus-senators-cybersecurity-1814665) on July 26 that a bipartisan group of 14 senators had sent a letter to State Department Chief Information Officer Kelly Fletcher “asking for details of the extent of the breach, and the timeline on which it was fixed,” along with a Sept. 6 deadline for her response. (A copy of the letter can be found [here](https://d.newsweek.com/en/file/466662/senators-write-state-department-about-outlook-hack.pdf).)

A day later, Sen. Ron Wyden (D-Ore.) sent a [letter](https://www.wyden.senate.gov/imo/media/doc/wyden_letter_to_cisa_doj_ftc_re_2023_microsoft_breach.pdf) to U.S. Cybersecurity and Infrastructure Security Agency director Jen Easterly, FTC chair Lina Khan and Attorney General Merrick Garland “to request that your agencies take action to hold Microsoft responsible for its negligent cybersecurity practices, which enabled a successful Chinese espionage campaign against the United States government.”

_The Wall Street Journal_ [reported](https://www.wsj.com/articles/microsoft-faces-mounting-scrutiny-over-china-linked-email-hack-7a028523) that Microsoft “is working with government agencies and is committed to sharing information about the hack,” according to a company spokesperson, who told the outlet that “this incident demonstrates the evolving challenges of cybersecurity in the face of sophisticated attacks.”

I’d say incurring the wrath of the Senate Finance Committee Chairman also counts as “challenges.”

## The week, compiled

Google [published](https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html) on July 27 its breakdown of the zero-days exploited throughout 2022. (An initial summary was [published](https://googleprojectzero.blogspot.com/2022/06/2022-0-day-in-wild-exploitationso-far.html) in June 2022; now we have the full report.)

The company said last June that 18 of these vulnerabilities had been detected and disclosed. In the final version of the report, that number has grown to 41, which is a 40% drop from the number of zero-days publicly revealed in 2021. But that doesn’t necessarily mean it’s time to pop some champagne.

“Both positive and negative changes can influence the number of in-the-wild 0-days to both rise and fall. We therefore can’t use this number alone to signify whether or not we’re progressing in the fight to keep users safe. Instead we use the number to analyze what factors could have contributed to it and then review whether or not those factors are areas of success or places that need to be addressed.”

Mitchell Luo / Unsplash

Google said that some of the decline in detected zero-days can be attributed to threat actors being able to exploit known (“n-day”) vulnerabilities on Android due to long patch cycles and the proliferation of hard-to-detect zero-click exploits. These factors bring down the number of zero-days exploited throughout the year, but they’re hardly cause for celebration. (At least on the defenders’ side.)

The company also noted that 17 of the vulns were “variants of previously reported vulnerabilities” from 2020 or 2021, and that “2022 brought more frequent reports of attackers using the same vulnerabilities as each other, as well as security researchers reporting vulnerabilities that were later discovered to be used by attackers.” The former is also a bummer, but at least the latter is a net positive.

Some other stories that caught my attention last week:

[_AP:_](https://apnews.com/article/sec-cybersecurity-breach-disclosure-risk-hacking-bb6252463637793bfdc8ace5bfcbe7df) The Securities and Exchange Commission voted 3–2 along party lines to require publicly traded companies to disclose “material” cybersecurity breaches within four days, a move that drew pushback from some corners of the U.S. business community. “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors,” SEC Chair Gary Gensler said.

[_TechCrunch_](https://techcrunch.com/2023/07/27/hackers-are-infecting-call-of-duty-players-with-a-self-spreading-malware/): “Call of Duty: Modern Warfare 2” was taken offline last week following the discovery of a worm that infects the systems of people still playing the 14-year-old game. (The 2022 title bearing the same name doesn’t appear to be affected.) As for why someone developed malware for such an old game, well, that isn’t clear yet.

[_BleepingComputer_](https://www.bleepingcomputer.com/news/security/alphv-ransomware-adds-data-leak-api-in-new-extortion-strategy/): Ransomware gangs are diversifying their leak methods. BleepingComputer [reported](https://www.bleepingcomputer.com/news/security/clop-now-leaks-data-stolen-in-moveit-attacks-on-clearweb-sites/) on July 23 that Cl0p had started leaking data stolen by exploiting vulnerabilities in MOVEit Transfer to clearweb sites, and on July 26, it reported that ALPHV’s leak site now provides an API to make finding data easier.

[_The Record_](https://therecord.media/more-than-900000-mikrotik-routers-vulnerable-to-new-bug): More than 900,000 MikroTik routers remained susceptible to a vulnerability (CVE-2023–30799) nearly a week after the company released a patch for it, according to VulnCheck, which told The Record that exploits for the underlying security flaw have been publicly available since at least June 2022.

## Flash memory

Wired senior writer Andy Greenberg has a thing for letting security researchers hack a vehicle while he’s driving it — and for publishing the reports based on these proof of concept exploits some time in late July.

The first report, published by [_Forbes_](https://www.forbes.com/sites/andygreenberg/2013/07/24/hackers-reveal-nasty-new-car-attacks-with-me-behind-the-wheel-video/?sh=4ce520ae228c) in July 2013, was fairly tame. Greenberg said that security researchers Charlie Miller and Chris Valasek “sent commands from their laptops that killed power steering, spoofed the GPS and made pathological liars out of speedometers and odometers” to a Ford Escape and Toyota Prius while he drove around an abandoned parking lot. That’s frightening, sure, but fairly safe.

Then a followup arrived in July 2015. Greenberg opens that report, which was published by [_Wired_](https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/), with the line “I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.” (Talk about not burying the lede, Andy!) That’s terrifying even before you reach this snippet:

“To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. Instead, they merely assured me that they wouldn’t do anything life-threatening. Then they told me to drive the Jeep onto the highway.”

Reader, I can guarantee that my response would have been a “no” so colorful _The New York Times_ would refuse to print it. But not Greenberg, and we’re all better off for it, because this coverage of [Miller and Valasek’s research](https://www.wired.com/2016/08/jeep-hackers-return-high-speed-steering-acceleration-hacks/) has prompted vehicle makers to start taking cybersecurity at least a little more seriously than before.

## Local files

[_The Register_](https://www.theregister.com/2023/07/27/nato_investigates_hack/): NATO is investigating SiegedSec’s claim that it “broke into the military alliance’s unclassified information-sharing and collaboration IT environment, stole information belonging to 31 nations, and leaked 845 MB of compressed data,” as The Register put it.

[_CyberScoop_](https://cyberscoop.com/kids-online-safety-act-senate-privacy/): The Senate Commerce Committee is moving forward with two bills — the Children and Teens’ Online Privacy Protection Act and the Kids Online Safety Act — despite widespread criticism regarding the data collection the bills would require and the risks they would pose to youths who are already in unsafe situations.

[_Reuters_](https://www.reuters.com/world/china/china-says-wuhan-earthquake-centre-attacked-by-overseas-hackers-2023-07-26/): China accused the U.S. of hacking an earthquake monitoring center in Wuhan on July 26 and said the breach threatened its national security. It’s not clear why the U.S. would hack this equipment, however, or how exactly doing so would threaten China even if such an operation had taken place.
