Suspected Chinese hackers manipulated common software distributed by a small Canadian customer service companyanother example of a “supply chain compromise” that became infamous with the hack of the American grid company SolarWinds.
That says the American cybersecurity company CrowdStrike in an upcoming blog post, seen by the agency Reuterswho had discovered malware distributed by Comm100based in Vancouver, which provides customer service products such as chatbots and social media management tools to a number of clients around the world.
The scope and scope of the hack were not immediately clear. In a message, Comm100 said it had already fixed its software on Thursday and more details would follow. The company did not immediately respond to requests for information.
CrowdStrike researchers they think the malware was circulating for a few daysbut they declined to say how many businesses were affected, stating only that “entities from a range of industries” were affected.
Comm100 said on its website that it is more than 15,000 customers in some 80 countries.
CrowdStrike executive Adam Meyers said in a phone interview that the hackers involved were suspected to be Chinese, citing the hackers’ behavior patterns, the language in the code and the fact that one of the victims of the hacking had been repeatedly hit in the past. attacked by Chinese hackers. .
The Chinese embassy in Washington did not immediately return messages seeking comment. Beijing mostly denies these allegations.
Supply chain attacks – in which a common computer program is manipulated to hack its users – have become a growing problem since suspected Russian hackers broke in and IT management company SolarWinds Corp. from Texas as a springboard to US government agencies and a number of private companies.
Meyers — whose company was among those responding to the SolarWinds hack — said the Comm100 finding was a reminder that other countries were using the same techniques. China carries out supply chain attackssaid.
(By Raphael Satter and Christopher Bing – Reuters)
Keep reading: