Jul 11, 2018

Evidence surfaces of China spying on Cambodian elections

Supporters of GDP seen on a vehicle. Photo: Enric Catala Contreras/SOPA Images/LightRocket via Getty Images

Researchers at FireEye found evidence that a Chinese hacker group known as TEMP.Periscope spied on both sides of the Cambodian election, according to a new report.

What they're saying: Benjamin Read, FireEye senior manager for cyber espionage analysis said in a statement: "China is heavily surveilling all parts of the upcoming Cambodian elections. We have not seen any evidence of activity beyond intelligence collection, but Cambodia is a key ally, so any change in ruling party would be of interest to China."

The details: TEMP.Periscope was previously only known for espionage on maritime targets. The election targets show a new interest in geopolitics.

  • The attack leveraged Airbreak, Homefry, Murkytop, HTran, and Scanbox malware already attributed to the group, as well as two new families of malware: a backdoor FireEye dubbed Eviltech and a credential harvesting program it dubbed Dadbod.
  • Airbreak malware, which is used to install other malware programs, was affixed to lure documents related to Cambodian politics.

Targets of the attack include:

    • The National Election Commission, Ministry of the Interior, Ministry of Foreign Affairs and International Cooperation, Cambodian Senate, Ministry of Economics and Finance.
    • A Member of Parliament representing the ruling Cambodia National Rescue Party.
    • Multiple human rights advocates in opposition to the ruling party.
    • Two Cambodian diplomats serving overseas.
    • Multiple Cambodian media outlets.
    • Monovithya Kem, deputy director-general of public affairs of the Cambodia National Rescue Party.
    • The daughter of imprisoned Cambodian opposition party leader Kem Sokha.

The attack provided new evidence that TEMP.Periscope is a Chinese group from FireEye, which monitored a control server from the attack.

  • While the attackers usually used location-hiding anonymity measures, the one connection that didn't was located in Hainan, China.
  • Computers that connected to the server had Chinese language settings.

Go deeper

Deadly clashes erupt in Delhi ahead of Trump's visit

Rival protesters over the Citizenship Amendment Act in Delhi, India, on Monday. Photo: Yawar Nazir/ Getty Images

Delhi Chief Minister Arvind Kejriwal called for calm Tuesday as deadly clashes erupted in the city's northeast between supporters and opponents of India's controversial new citizenship law.

Why it matters: Per the BBC, a police officer and six civilians "died in the capital's deadliest day" since last year's passing of the Citizenship Amendment Act — which allows religious minorities but excludes Muslims from nearby countries to become citizens if they can show they were persecuted for their religion — hours before President Trump and members of the U.S. first family were due to visit the city as part of their visit to India.

Go deeper: India's citizenship bill continues Modi's Hindu nationalist offensive

South Carolina paper The State backs Buttigieg for Democratic primary

Democratic presidential candidate and former South Bend Pete Buttigieg speaks at an event in Charleston, South Carolina on Monday. Photo: Win McNamee/Getty Images

South Carolina newspaper The State endorsed former Southbend Mayor Pete Buttigieg on Monday night for the state's Democratic primary.

Why it matters: It's a welcome boost for Buttigieg ahead of Tuesday's Democratic debate in South Carolina and the state's primary on Saturday.

White House requests $2.5 billion to fight coronavirus as U.S. cases rise

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC, and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens.

The Trump administration sent a letter to Congress Monday requesting a funding commitment of at least $2.5 billion to help combat the spread of the novel coronavirus, as the number of confirmed cases in the U.S. rose to 53.

The big picture: As South Korea and Italy stepped up emergency measures in efforts to thwart the spread of the virus, WHO expressed concern about infections with no clear link to China. COVID-19 has killed at least 2,699 people and infected more than 80,000 others, with all but 27 deaths occurring in mainland China.

Go deeperArrowUpdated 2 hours ago - Health