- Joined
- Jun 4, 2022
I'm not gonna pretend I know everything but here are some rumors / things I read / things I think.Do state-backed cybercriminals, for instance ones from China or Iran, ever interact with the Western ones that are described here? If so do they have any thoughts on each other?
I ask because we hear of CCP and Iranian hackers doing various things to US government institutions and so forth, and yet when that happens it feels as if it's nothing other than routine geopolitics regardless of its technical impressiveness. There's far less of a crazy story behind them. I mean, when was the last time you heard the real drama and details of a Chinese hacking group?
It shouldn't be possible for parties involved in cybercrime to tell if they're dealing with a state-backed entity or just another cybercrime group. If you expose yourself as a state-backed group to anyone you risk drawing the attention of professional counterintelligence groups. Or I've heard rumors of people deliberately trying to scam state backed groups with fake data / nonexistent entries into networks. If you're dealing with a real state backed threat they would potentially be willing to cough up a lot of money for valuable material and if less experienced in these circles, would be more prone to getting scammed.
A note on Chinese state backed groups. The way I understand it, there are only a small handful of "official" state entities working directly on government orders, way more prevalent is an industry of private Chinese hacking contractors. Imagine a lot of smaller Chinese NSO-groups etc. These companies will get/compete for government contracts to (e.g.) develop malware or obtain data. I think the main reason why you don't hear a lot of details or drama from these groups is simply because they are encouraged not to be very public (not to establish a long term presence) lest you face some regime imposed consequence.