Categories: IntelligenceSecurity

Chinese Hackers Spying on European Diplomats

Security experts at FireEye discovered a cyber espionage operation conducted by Chinese hackers on the computer at the foreign ministries of the Czech Republic, Portugal, Bulgaria, Latvia and Hungary.

Security experts at FireEye have revealed that they were able to track Chinese hackers spying on EU foreign ministries for about a week. The hackers have targeted the computers belonging at least five European foreign ministries during the G20 meeting, a total of nine computers had been compromised.

FireEye has omitted to reveal the identity of the ministries, but confirmed the cyber espionage operation targeted participants to the annual summit of the G20 group of nations in St Petersburg in September. The New York Times has reported the name of the countries victims of the attacks … Czech Republic, Portugal, Bulgaria, Latvia and Hungary.

The Chinese group campaign behind the campaign was codenamed the “Ke3chang” due the names of one of the files used in its malicious code.

The method of attack is usually, a spear phishing attack tried to lure victims to open the attachment containing a malware. To deceive the recipient, the attackers used attachments pretending to provide details on a possible US military intervention in Syria. Let’s consider that the principal argument of the talks during the G20 was the civil war in Syria.

On August, FireEye researchers had the opportunity to monitor one of the 23 computer servers used by the Chinese hackers for the attacks, during the week the attackers operated without stealing any documents, security experts believe that the incursion was part of a network reconnaissance as confirmed by Narottama Villeneuve, a senior FireEye researcher.

“At that stage it appeared to be about network reconnaissance,” “they appeared to be specifically targeting foreign ministries” said Mr Villeneuve.

The researchers also revealed that his team was able to monitor the Chinese hackers for a limited period of time, a week spent by the group of hackers to “shift” the architecture.

“When they shift infrastructure, the servers are open. I just happened to check the servers when they weren’t secured,” he said.

The principal problem in this case is the attribution of the attack, despite it is clear the origin of the group it is quite difficult to link it to a state-sponsored hacking strategy.

“The hackers were based in China but it is difficult to determine from a technology point of view how or if it is connected to a nation state,” he added.

The Ke3chang group is an old acquaintance for FireEye, in the past the group targeted energy and aerospace companies and has conducted malware-based attacks against government organizations and hi-tech companies.

The Ke3chang group in 2012 adopted the same method of attack using a London Olympics themed mail and a “year earlier used emails purporting to show nude pictures of the then French president’s wife, Carla Bruni,”.

This is just last act of cyber dispute between China and the West.

Pierluigi Paganini

(Security Affairs –  Chinese hackers, FireEye)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Security Affairs newsletter Round 563 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

9 minutes ago

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

20 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

22 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

This website uses cookies.