China, North Korea pursue new targets while honing cyber capabilities

China North Korea pursue new targets while honing cyber capabilities
Over the past year, China has developed a new capability to automatically generate images for influence operations, aiming to replicate US voters' views across the political spectrum and stir controversy on racial, economic, and ideological fronts.

This capability is fuelled by artificial intelligence, striving to create high-quality content with the potential to go viral on US and other democratic nation's social networks. These images are likely generated using diffusion-powered image generators, employing AI not only to produce compelling visuals but also to enhance them gradually.

Today, the Microsoft Threat Analysis Center (MTAC) releases "Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness," as part of an ongoing report series on the threat landscape posed by influence operations and cyber activities, pinpointing specific sectors and regions with heightened vulnerabilities.

We have observed China-affiliated entities employing AI-generated visual content in a comprehensive campaign that primarily centres on politically divisive topics, including gun violence, as well as disparaging US political figures and symbols. This technology produces more visually striking content compared to the awkward digital drawings and stock photo collages used in previous campaigns. China is likely to refine and expand the use of this technology in the future, although the scale and timing remain uncertain.

As highlighted in Microsoft's recent report, "Governing AI: A Blueprint for the Future," public and private institutions must collaboratively address the weaponization of technology, including AI, by cyber and influence threat actors. We report on digital threats, including AI usage, to inform policymakers, security professionals, and the public about potential threats to information integrity and democracy, both current and emerging. We will continue sharing our insights and urge our partners to do the same, as part of our broader blueprint to foster transparency and guide AI governance.

In their cyber operations, multiple Chinese state-affiliated threat actors have focused on cyberattacks in the South China Sea region, engaging in intelligence collection and malware deployment against regional governments and industries. Other actors have targeted the US defense industry and infrastructure in pursuit of competitive advantages to bolster their strategic military objectives.

Starting in May 2023, Storm-0558, a threat actor based in China, gained access to Microsoft customer email accounts from around 25 organizations, including US and European government entities. Microsoft assesses that this activity was likely conducted for espionage purposes and has successfully thwarted this campaign.

The report also outlines China's ongoing global efforts to disseminate state-sponsored propaganda and improve its international image. The Chinese government allocates resources to communicate with audiences in multiple languages on various platforms while refining its techniques. For instance, China employs over 230 state media employees and affiliates who pose as independent social media influencers across major Western platforms.

These influencers, trained, promoted, and funded by China Radio International (CRI) and other Chinese state media organisations, adeptly disseminate localized CCP propaganda, effectively engaging audiences worldwide, amassing a collective following of at least 103 million people on numerous platforms, spanning over 40 languages.

Despite China's development and use of impressive cyber capabilities and influence operations, we have not observed China combining cyber and influence as frequently as Iran and Russia, who regularly employ hack-and-leak campaigns.

Beyond China, North Korea poses a credible cyber threat, focusing on intelligence gathering and cryptocurrency theft to generate state revenue. Multiple North Korean threat actors have targeted the maritime and shipbuilding sectors, signifying its high-priority area for the North Korean government. Furthermore, several North Korean threat actors have recently targeted the Russian government and defense industry, likely for intelligence collection, while concurrently supporting Russia in its conflict with Ukraine.

The report also anticipates future actions by China and North Korea in the coming months, driven by increasing geopolitical tensions that spawn new threat priorities and adversarial strategies. With upcoming elections in 2024, both Taiwan and the United States are expected to remain top targets for China.

No technology platform, including Microsoft's, is infallible. However, as nation-state actors continue to exploit vulnerabilities and disseminate harmful narratives globally, we believe it is imperative to share intelligence, such as this report, and foster cross-industry collaboration to address these critical issues.

Editor’s note: As part of an ongoing series, Microsoft has published "Sophistication, scope, and scale: Digital threats from East Asia increase in breadth and effectiveness" today. These semi-annual updates on nation-state actors aim to alert our customers and the global community to the threat posed by influence operations and cyber activity, identifying specific sectors and regions at heightened risk. For previous reports on Russia and Iran, please refer to our earlier publications.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.