Offshore wind farm in Taiwan Strait victim of phishing campaign by Bejing-backed hackers TA423/Red Ladon

Year

2022

Month

March

Reference number

20220301

Impact area

Offshore

Incident location

Taiwan Strait

Incident country

Taiwan

Victim country

Taiwan

Victim identity

Yunlin offshore wind farm

Victim Type

Offshore Wind Farm

Method

Phishing

Attacker country

China

Summary:

The Chinese state-aligned threat actor TA423 (aka Leviathan/APT40) is behind a sustained cyber-espionage (phishing) campaign, that lasted more than a year, against countries and entities operating in the South China Sea, including organizations involved in an offshore wind farm in the Taiwan Strait. TA423 has been active for almost 10 years, with its activity dovetailing with military and political events in the Asia-Pacific region. TA423's typical targets include defense contractors, manufacturers, universities, government agencies, legal firms involved in diplomatic disputes, and foreign companies involved with Australasian policy or South China Sea operations. TA423 is one of the most consistent advanced persistent threat (APT) actors in the threat landscape, supporting the Chinese government in matters related to the South China Sea, including during the recent tensions in Taiwan.

Reference URL

https://www.bloomberg.com/news/articles/2022-08-30/chinese-hackers-tied-to-attacks-on-south-china-sea-energy-firms
https://www.theedgemarkets.com/article/msian-companies-working-kasawari-gas-project-among-targets-beijingbacked-hackers-%E2%80%94-research
https://daijiworld.com/news/newsDisplay?newsID=994710
https://www.polygraph.info/a/fact-check-evidence-backs-up-beijing-link-to-south-china-sea-hackers/32014502.html
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea https://thediplomat.com/2023/04/phishing-in-the-south-china-sea/ https://ics-cert.kaspersky.com/publications/reports/2023/03/24/apt-attacks-on-industrial-organizations-in-h2-2022/