A hacker group linked to Chinese espionage is illicitly installing software at telecommunications companies to steal text messages from specific users and regarding specific topics, according to cybersecurity firm FireEye.

The big picture: While Chinese espionage is often linked to intellectual property theft, the targets in this case appear to be more linked to traditional espionage, including senior political and military figures and topics that could be of interest to Chinese policymakers.

The backdrop: The hacking group identified in this campaign, known as APT 41, is believed to have been active for nearly a decade.

  • They are interesting among Chinese spy groups because they appear to both spy for the government and commit cybercrime on the side to supplement their own incomes.

The big picture: FireEye has discovered "multiple" telecoms infected with the newly discovered malware, which they have dubbed Messagetap, Steven Stone, the firm's director of advanced practices, told Axios.

  • It assumes that many more will soon be discovered.
  • "We're at the front end of this discovery," he said, noting that the company decided publishing a speedy warning was more important than taking time to assess the campaign's scope. "I'd be really surprised if they just used this against one nation."

What's happening: Messagetap installs onto telecommunication company-specific hardware.

  • While APT 41 and other spy groups have hacked telecoms in the past to search for information on individuals, weeding out targets is usually done one at a time. This software automates the process, allowing spies to search for thousands of identifiers at the same time.
  • FireEye told Axios that the software they discovered was searching for text messages to or from at least 7,000 different phone numbers or individual phone identifiers, known as IMSI numbers.

Go deeper: China-linked group hacked 10 international cellphone providers

Go deeper

11 hours ago - Health

15 states broke single-day coronavirus records this week

Data: Compiled from state health departments by Axios; Map: Danielle Alberti/Axios

At least 15 states broke their single-day novel coronavirus infection records this week, according to state health department data reviewed by Axios.

The big picture: The number of coronavirus cases increased in the vast majority of states over the last week, and decreased in only two states plus the District of Columbia, Axios' Andrew Withershoop and Caitlin Owens report.

Updated 12 hours ago - Politics & Policy

Coronavirus dashboard

Illustration: Aïda Amer/Axios

  1. Global: Total confirmed cases as of 3 p.m. ET: 11,143,945 — Total deaths: 527,681 — Total recoveries — 6,004,593Map.
  2. U.S.: Total confirmed cases as of 3 p.m. ET: 2,818,588 — Total deaths: 129,584 — Total recoveries: 883,561 — Total tested: 34,213,497Map.
  3. States: Photos of America's pandemic July 4 ICU beds in Arizona's hot spot reach near capacity.
  4. Public health: U.S. coronavirus infections hit record highs for 3 straight days.
  5. Politics: Trump extends PPP application deadlineKimberly Guilfoyle tests positive.
  6. World: Mexican leaders call for tighter border control as infections rise in U.S.
  7. Sports: 31 MLB players test positive as workouts resume.
  8. 1 📽 thing: Drive-in movie theaters are making a comeback.
12 hours ago - Health

In photos: America celebrates July 4 during global pandemic

Photo: Francine Orr/Los Angeles Times/Getty Images

The U.S. has already celebrated Easter, graduations and so much more during the coronavirus pandemic, and now it can add July 4 to the list.

The state of play: Axios' Stef Kight writes public parades and fireworks displays around much of the country are being canceled to prevent mass gatherings where the virus could spread. Hot-dog contests and concerts will play to empty stands and virtual audiences — all while American pride treads an all-time low.