Article 767QY Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate

Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate

by
from www.theregister.com - Articles on (#767QY)
Story ImageMultiple reports indicate that Chinese operatives continue using every tech tool at their disposal - including American AI - to amass data on and manipulate everyone from security-clearance holders to everyday US citizens. And they're trying to influence public opinion on building datacenters for AI, albeit without success so far. One of these reports found a significant resurgence" of a botnet linked to Chinese government-backed goons, including Volt Typhoon, which previously used a covert network of connected devices to burrow deep into critical US networks and preposition for future destructive attacks. In January 2024, the FBI said it killed Volt's KV-botnet, comprised of hundreds of end-of-life routers and other internet-connected devices. At the time, KV-botnet consisted of four clusters, with the KV cluster primarily being used as a covert data transfer network, and the JDY cluster used for scanning and reconnaissance. In a Wednesday report, Lumen's Black Lotus Labs said that while the KV cluster became largely defunct after the law enforcement takedown, the JDY cluster remains an active threat, and has since surged to more than 1,500 compromised routers and IoT devices. Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors," the threat intel team wrote. This targeted focus has been observed across a range of sectors, with the US military and associated entities as the most prominent." While the botnet resurgence poses the most pressing threat, and the security shop recommends all enterprises implement CISA and NCSC guidance for mitigating Volt Typhoon activity and defending against China-nexus covert networks of compromised devices, another report indicates that China's attempts at influence operations haven't died down, either. Using American AI for covert ops about ... American AI OpenAI in a Wednesday report said it banned ChatGPT accounts likely originating from China after they used the American AI company's models to generate content for covert operations about - wait for it - American AI. While neither of the two clusters seemed to have much success in sowing chaos or swaying opinions, the fact that they tried at all is significant, according to Ben Nimmo, principal investigator on OpenAI's Intelligence and Investigations team. Neither campaign appears to have gained much authentic engagement," Nimmo told reporters. They're important for what they reveal about the intentions of influence operators from China and the narratives they're testing and seeking to amplify." The first cluster used ChatGPT to generate social media content and images for an operation claiming datacenters and AI applications are increasing electricity demand and causing higher costs for ordinary Americans. For example, they asked for comic strips about a power grid operator's capacity auction prices based on reporting from a legitimate regional paper," the report says. They asked ChatGPT to focus the comments on rising capacity prices as a consequence of peak electricity demand, framing the new demand as coming from data centers and AI applications and argued that these costs were ultimately passed to ordinary households." The operators then posted these comments and images on X, likely using fake accounts, with links to real news stories about datacenters. OpenAI suspects the operators are part of a social-media team at a private Chinese tech company that provides services for Chinese provincial-level government clients. This was not a case of an influence operation creating a debate," Nimmo said. The debate existed already. This was an influence operation from China trying to interfere in it. We didn't see any signs that they succeeded." The second cluster of banned ChatGPT accounts also likely originated in China and used OpenAI's models to write comments and draw political cartoons criticizing US tech policies and tariffs. Interestingly, the operators specified in their prompts that the content should not include cartoons of Xi Jinping in the output and should only include President Trump," Nimmo said. These accounts, all writing prompts in simplified Chinese and using VPNs to access the AI systems, also used ChatGPT to edit work reports and help design social media monitoring systems. This isn't the first time that we've seen actors in China trying to come up with ideas for social media monitoring," Nimmo said. In February, OpenAI said it banned ChatGPT accounts believed to be linked to Chinese government entities attempting to use AI models to surveil individuals and social media accounts. If AI doesn't work, bribery might? If Chinese agents can't use AI systems to unearth sensitive information, there are always fake websites and job offers promising cash for state secrets. We've seen Beijing-linked government snoops use these tactics in the past, and according to the US Justice Department, they're still using this scam (because it works). On Wednesday, the feds said they obtained a warrant for and seized 13 fake consulting company websites used to target US persons, including current and former security clearance holders with access to classified and sensitive government information. The domains include centrikglobalconsulting.com, rightinfoconsult.com, finnaclevesperconsulting.com, cydfconsulting.com, pulsewaveglobal.com, catalystglobalsolutions.com, thehorizzen.com, geoindopacific.com, gpf-ina.org, safesec-group.com, thetruthinfo.com, Vandercons.com, and gulfpeace.org. Since November 2023, these websites and associated job postings on social media, LinkedIn, and other hiring platforms advertised consulting" jobs, including Senior Analyst" and International Affairs Consultant" positions. Suspected PRC operatives used the sites and job listings to recruit applicants and bribe them for sensitive information, DOJ alleges. The conspirators have encouraged applicants and recruits to share confidential and sensitive information in violation of their official duties and of particular interest to the People's Republic of China (PRC) government," according to the court documents. The recruiters pressured candidates to share confidential information and reports from insider sources' in violation of their official duties." The court documents allege the conspirators then paid the recruits for these reports using online accounts in the names of fictitious individuals, and cryptocurrency to hide their identities and the source of the payments. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments