Chinese hackers and Operation F**k Me

Bloomberg reportsย (porous paywall):

A Chinese government-linked hacking group that was thought to be dormant has been quietly targeting companies and government agencies for the last two years, harvesting data after stealing passwords and circumventing two-factor authentication intended to prevent such attacks, according to researchers.

Fox-IT, a security company based in the Netherlands, said in a report published Thursdayย that the groupโ€™s attacks have extended to 10 countries, including the U.S., the U.K., France, Germany and Italy.

The Chinese hackers carried out a global espionage campaign that targeted industries including aviation, construction, finance, health care, insurance, gambling and energy, the firm said.

The hackers likely belong to a group known as APT20, according to the researchers, who said they had โ€œhigh confidence that the actor is a Chinese group and that they are likely working to support the interests of the Chinese government.โ€

Fox-IT calls the groupโ€™s activities Operation Wocao (ๆˆ‘ๆ“ โ€œwว’ caฬ„o โ€” literally โ€œI f**kโ€ but used more like โ€œshit,โ€ โ€œdamn,โ€ or โ€œf**k meโ€). Bloomberg explains:

Perhaps the most striking indicator [that the hackers were Chinese] came after the hackers found out they had been caught. Fox-IT moved to shut them out of a compromised network and watched as the group typed in a series of commands to try and regain access to the computers.

When it became clear that they had been locked out, one of the hackers, apparently frustrated, bashed out the word โ€œwocaoโ€ on his keyboard.

โ€”Jeremy Goldkorn