$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

US Treasury Sanctions Chinese Cybersecurity Firm Over Global Ransomware Campaign

  • Last updated December 11, 2024
  • written by
    Writer

Washington, December 11, 2024 – The United States Department of the Treasury’s Office of Foreign Assets Control (OFAC) has imposed significant sanctions on Sichuan Silence Information Technology Company and its employee Guan Tianfeng for their involvement in a major cyber campaign that affected tens of thousands of businesses worldwide.

The sanctions target both the company and Tianfeng for their roles in a 2020 cyber operation that deployed malware to over 80,000 firewalls globally, with more than 23,000 of those located in the United States. Notably, 36 of these firewalls protected critical infrastructure entities during the attack, which took place between April 22 and 25, 2020. The Treasury Department has indicated that the potential for disruption from this campaign was catastrophic, particularly for an energy company engaged in oil rig drilling operations at the time, which could have resulted in significant loss of life.

The malware used in the campaign was designed to steal sensitive data and user credentials, while Guan Tianfeng also deployed the Ragnarok ransomware variant on affected networks. The Department of Justice has indicted Tianfeng for his involvement in these cyber activities.

“Today’s action underscores our commitment to exposing these malicious cyber activities – many of which pose significant risk to our communities and our citizens – and to holding the actors behind them accountable for their schemes,” stated Bradley T. Smith, acting Undersecretary of the Treasury for Terrorism and Financial Intelligence. He emphasized that the Treasury will continue to leverage its tools to disrupt malicious cyber actors targeting critical infrastructure.

Sichuan Silence, based in Chengdu province, is known to have connections with the People’s Republic of China intelligence services. Guan Tianfeng, known in the cybersecurity community as GbigMao, has participated in cybersecurity competitions and has been observed sharing exploits on hacking forums.

Under the new sanctions, all US-based assets associated with Sichuan Silence and Guan Tianfeng must be reported to OFAC, and all transactions with these entities are now prohibited. Cybersecurity firm Sophos played a key role in the investigation of the firewall campaign, revealing links between the attackers and Sichuan Silence’s Double Helix Research Institute.

“We are pleased that the Department of Justice has unsealed its indictment of GbigMao, aka Guan Tianfeng, and the Treasury has sanctioned Sichuan Silence. This is a positive step towards disrupting these attackers’ operations,” said Ross McKerchar, Sophos’ CISO.

The sanctions represent a critical effort by the US government to address and mitigate the risks posed by foreign cyber threats to national security and public safety.