China state-sponsored hackers hack ASEAN mail servers

Last updated on March 9th, 2023 at 02:27 pm

In February of last year, Chinese state-sponsored hackers breached the Association of Southeast Asian Nations (ASEAN) mail systems, taking a trove of data that may have contained crucial information about the economies and politics of member nations.

According to a vulnerability alert acquired by WIRED, hackers took over 30GB of data, including over 10,000 emails exchanged by member countries, by infiltrating computers in February 2022. The alert was sent to cybersecurity agencies and foreign affairs ministries, as well as other government entities, in all ten ASEAN member states, including Thailand, Malaysia, Singapore, and the Philippines.

The incident occurred a few weeks before US Vice President Joe Biden hosted ASEAN leaders at the White House for diplomatic meetings that addressed opposing China’s influence in the region. At the two-day meeting, Biden also offered $150 million to ASEAN nations for infrastructure, security, and pandemic response.

The Chinese threat actors apparently exploited “legitimate credentials” to breach the mail.asean.org and auto.discover.asean.org domains used by ASEAN’s Microsoft Exchange servers. In addition, they exploited four Microsoft Exchange vulnerabilities throughout the hack.

The notice states that this is not the first time Chinese hackers have hacked ASEAN, as the intergovernmental body was targeted in July 2021 and between May and October 2019 as well.

Analysts believe Chinese hackers continue to target ASEAN because the data it possesses is crucial to gauging political and economic sentiments in the region.

China has made substantial investments in the region through the Belt and Road Initiative, a program that creates economic corridors connecting the Asian giant to neighboring nations. Yet, this strategy also increases China’s economic and political influence, causing friction with its neighbors. The territorial disputes in the South China Sea, involving China, the Philippines, Indonesia, and Vietnam, are one example of the geopolitical conflict that may result from the Chinese government’s aggressive securitization approach.

The alert states, “The identified intrusion campaigns almost certainly support key strategic goals of the Chinese government, such as gathering intelligence on countries engaged in territorial disputes in the South China Sea or on projects and countries strategically important to the Belt and Road Initiative.”

In the past two years, Recorded Future, a cybersecurity company, has tracked ten Chinese-affiliated groups that target Southeast Asian nations. Throughout 2021, the company also identified 400 Southeast Asian servers communicating with malware infrastructure that was presumably deployed by Beijing-backed threat actors. Malaysia, Indonesia, and Vietnam were the ASEAN countries most frequently targeted.

Also Read:- Daylight Saving Time 2023: When Does the Time Change?

Noto

Jakarta-based Newswriter for The Asian Affairs. A budding newswriter that always keep track of the latest trends and news that are happening in my country Indonesia.

Recent Posts

Is Girigo App Safe? Why Cyber Experts are Warning You to Delete This Viral App Immediately

The Girigo App is the latest buzz app that has caught on in social media today (April 30, 2026). It…

April 30, 2026

How to Claim the New ‘Anime Apocalypse’ Soul Shards Before May 1?

Roblox's virtual world is currently experiencing an "End of the World" event, but for the players of the wildly popular…

April 30, 2026

Friendster is Back? The Original Social Media Giant Returns After Years; Can You Still See Your 2005 Testimonials?

The internet has been caught unawares with the re-entry of Friendster. By April 30, 2026, the formerly-legendary social networking platform…

April 30, 2026

Let Your Bot Do the Shopping: Visa Launches ‘Agentic Ready’ Program in Asia Pacific Today; When Your AI Will Start Paying Your Bills for You

Visa has just initiated a significant change to digital payments with Visa officially launching its Agentic Ready program in the…

April 30, 2026

No More Nicknames: PayNow to End Alias Option for All Users in June; Why Your Payment Handle Must Match Your Legal Name

Singapore PayNow is a popular instant payment system. Retail users will cease to use custom nicknames to transact on June…

April 30, 2026

Planning a Thai Vacation? Why Travel Agents are Slamming the New B1,000 Exit Tax

Southeast Asia's tourism sector is being jolted this morning. In an effort to boost the Thai economy, the country's government…

April 29, 2026

This website uses cookies.

Read More