Intelligence

FBI warns US companies on the use of Chinese Tax Software

The FBI has issued an alert to warn US organizations of the risk associated with the use of Chinese tax software that could be infected with malware.

The Federal Bureau of Investigation has issued an alert to inform organizations in the United States of the risk associated with the use of Chinese tax software.

The alert aims at informing US companies in the healthcare, chemical, and
finance sectors of cyber espionage activity by the Chinese government against their business and branches operating in China.

“Compromise of the pharmaceutical supply chain provides malicious actors opportunities for theft of US intellectual property, while public disclosure can cause cascading effects including loss of public trust in both chemical and healthcare institutions.” reads the alert. “As previously highlighted in FBI PIN 20200521-001 released on 21 May 2020 and the US Department of Homeland Security’s joint advisory with Britain’s National Cyber Security Centre, hackers continue to “actively target organizations that include healthcare bodies, pharmaceutical companies, academia, medical research organizations, and local governments.”

At the end of June, the experts from Trustwave spotted GoldenSpy, a new backdoor, that is being distributed embedded in tax payment software (the Aisino Intelligent tax software) that some businesses operating in China are required to install.

The campaign is active since at least April 2020, but experts found some samples that suggest the attacks begun at least December 2016.

A few days after the publishing of the report, an uninstaller was pushed to compromised machines, to completely remove GoldenSpy implementing the removal procedure suggested by Trustwave in its initial report.

Anyway, researchers were able to discover another piece of malware, dubbed GoldenHelper, that was delivered with the same mechanism. GoldenHelper was bundled in the Golden Tax Invoicing Software (Baiwang Edition), which Chinese banks require their clients to install.

This second malware is completely different from GoldenSpy, experts noticed that although it is called “Baiwang Edition”, GoldenHelper was digitally signed by NouNou Technologies, a subsidiary of Aisino Corporation.

According to the alert, at least two Western organizations doing business in China would install the backdoor.

“As early as March 2019, at least two Western companies operating in China detected malware that was delivered through Chinese vendors that were responsible for releasing tax software upgrades following changes in 2018 to China’s value-added tax (VAT).” the alert continues.”The malware launched a backdoor into victim systems, which the FBI assesses likely allows cyber actors to preposition to conduct remote code execution and exfiltration activities on the victim’s network.”

Feds believe that all foreign companies operating in China might be at risk due to the use of the software from Baiwang and Aisino, the two tax software service providers authorized to operate the value-added tax (VAT) system in China.

The alert also includes recommendations on how companies can mitigate the risk of hack intrusions. The FBI also published the indicators of compromise (IoC) for the threats.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, tax software)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

15 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

16 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

21 hours ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

1 day ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.