Chinese Hackers Have Pillaged Taiwan’s Semiconductor Industry
A campaign called Operation Skeleton Key has stolen source code, software development kits, chip designs, and more.
TAIWAN HAS FACED existential conflict with China for its entire existence and has been targeted by China’s state-sponsored hackers for years. But an investigation by one Taiwanese security firm has revealed just how deeply a single group of Chinese hackers was able to penetrate an industry at the core of the Taiwanese economy, pillaging practically its entire semiconductor industry.
At the Black Hat security conference today, researchers from the Taiwanese cybersecurity firm CyCraft plan to present new details of a hacking campaign that compromised at least seven Taiwanese chip firms over the past two years. The series of deep intrusions—called Operation Skeleton Key due to the attackers’ use of a “skeleton key injector” technique—appeared aimed at stealing as much intellectual property as possible, including source code, software development kits, and chip designs. And while CyCraft has previously given this group of hackers the name Chimera, the company’s new findings include evidence that ties them to mainland China and loosely links them to the notorious Chinese state-sponsored hacker group Winnti, also sometimes known as Barium, or Axiom.
“This is very much a state-based attack trying to manipulate Taiwan’s standing and power,” says Chad Duffy, one of the CyCraft researchers who worked on the company’s long-running investigation. The sort of wholesale theft of intellectual property CyCraft observed “fundamentally damages a corporation’s entire ability to do business,” adds Chung-Kuan Chen, another CyCraft researcher who will present the company’s research at Black Hat today. “It’s a strategic attack on the entire industry.”
CyCraft concedes it can’t determine what the hackers are doing with the stolen chip design documents and code. And the more likely motivation of the hacking campaign is simply to give China’s own semiconductor makers a leg up over their rivals. “This is a way to cripple a part of Taiwan’s economy, to hurt their long-term viability,” Duffy says. “If you look at the scope of this attack, pretty much the entire industry, up and down the supply chain, it seems like it’s about trying to shift the power relationship there. If all the intellectual property is in China’s hands, they have a lot more power.”
Correction 8/7/2020 10:30 AM EST: This story has been updated to more accurately explain the skeleton key injection technique.