US Cyber Weapon Can 'Frame Other Countries' For Its Own Espionage Operations
China claims that US intelligence agencies crafted the Volt Typhoon narrative “to win public support and pressure policymakers to allow the extension of invasive US surveillance powers.” Beijing also blames the US for widespread cyber espionage, disinformation operations around the world, and even “choking the internet.”-MK3
A Chinese national cyber defense agency has released a third document in a series accusing the US of false flag operations and claiming that the Volt Typhoon is a work of fiction crafted by the US.
A recent report on Volt Typhoon has surfaced, shedding light on alleged cyber espionage operations. The document, released in multiple languages including Chinese, English, French, German, and Japanese, is the third in a series published by the National Computer Virus Emergency Response Center and the National Engineering Laboratory for Computer Virus Prevention Technology. This report further details the cyber espionage activities targeting China, Germany, and other countries, allegedly conducted by the US and its Five Eyes allies.
The Allegations and Counter-Claims
On May 24, 2023, cybersecurity authorities from the Five Eyes countries (the US, UK, Australia, Canada, and New Zealand) issued a joint cybersecurity advisory. They claimed to have discovered a cluster of activity associated with a “China state-sponsored cyber actor” known as Volt Typhoon, which they said affected networks across US critical infrastructure sectors.
However, the National Computer Virus Emergency Response Center, along with the National Engineering Laboratory for Computer Virus Prevention Technology and 360 Digital Security Group, released two earlier reports in April and July. These reports disputed the US government’s narrative, asserting that the claims about Volt Typhoon were fabricated. According to these reports, the US government agencies, in an effort to maintain control over warrantless surveillance rights, conduct indiscriminate monitoring of global telecommunications and internet users. This is purportedly done to fabricate non-existent Chinese cyberattack threats, thereby enabling related interest groups to gain political and economic benefits.
The research fellow from the National Computer Virus Emergency Response Center told the Global Times that more than 50 cybersecurity experts from the US, Europe, Asia, and other regions have contacted them. These experts expressed skepticism about the US government and Microsoft’s attribution of Volt Typhoon to the Chinese government, citing a lack of concrete evidence.
The Tools and Tactics
The US, as the world’s largest arms dealer, possesses a sophisticated arsenal of cyber weapons. The National Computer Virus Emergency Response Center has previously disclosed various types of cyber weapons developed by the National Security Agency (NSA) and Central Intelligence Agency (CIA).
The latest report reveals information about a customized stealth “toolkit” codenamed “Marble.” This toolkit, developed by US agencies, is designed to cover up Computer Network Exploitation (CNE) operations, mislead attribution analysis, and shift the blame onto other countries. The toolkit can be integrated with other cyber weapon development projects, assisting developers in obfuscating identifiable strings in program code, effectively erasing the “fingerprints” of the cyber weapon developers.
The “Marble” framework also includes a “dirty” feature, allowing the insertion of strings in other languages, such as Chinese, Russian, Korean, Persian, and Arabic. This is intended to mislead investigators and defame China, Russia, North Korea, Iran, and Arab countries. According to the report, the “Marble” framework was identified as a secret weapon development program, not to be shared with any foreign country, starting no later than 2015. This secret weapon was tailored by US intelligence agencies for their own use, even kept a secret from so-called ally countries.
False Flag Operations
A “False Flag” operation is a deceptive act or operation carried out to make it appear as if it was conducted by another party. The “Marble” framework, according to the report, exposes the indiscriminate and extensive cyber espionage activities carried out by US intelligence agencies. These agencies are accused of using “false flag” operations to mislead investigators and researchers, framing “adversary countries.”
The anonymous researcher stated that hackers from US cyber forces and intelligence agencies disguise themselves in cyberspace, pretending to come from other countries to carry out cyberattacks and espionage activities. The “False Flag” operation is an important component of the US intelligence agency’s “EFFECTS Operation,” known as “Online Covert Action” in the UK. The secret documents from the US and Five Eyes Alliance show that the “EFFECTS Operation” includes two broad categories: “Information Operations” and “Technical Disruption Operations.”
The internal documents of the US and Five Eyes Alliance clearly indicate that the implementation of this “EFFECTS Operation” must adhere to four main principles: “Deny,” “Disrupt,” “Degrade,” and “Deceive.” These principles precisely cover all the core elements of the Volt Typhoon operation, according to the report.
Subsea Cable Tapping Sites
According to top-secret files from the NSA, the US controls some of the world’s most important internet “choke points,” such as the Atlantic and Pacific subsea cables. The US has constructed at least seven full-traffic tapping sites, operated by the NSA, FBI, and NCSC from the UK. Each packet passing through these sites is intercepted and deeply inspected indiscriminately.
The NSA is not content with merely focusing on specific areas covered by submarine cables, and the data intercepted by these surveillance systems falls short of meeting its intelligence needs. Therefore, the US has conducted CNE operations on specific targets located in the “blind spots” of its surveillance systems.
Top-secret documents from the NSA show that the Office of Tailored Access Operation (TAO) of the NSA has launched massive CNE operations around the world, implanting more than 50,000 spyware implants. Victims are mainly concentrated in Asia, Eastern Europe, Africa, the Middle East, and South America. Internal documents of the NSA showed that almost all major cities in China are within the scope of NSA’s operations, and a large number of entities and their network assets have been compromised.
Spying on Allies
The report also cites instances of the US conducting surveillance on countries such as France, Germany, and Japan. From 2004 to 2012, the US carried out a long-term espionage operation against France, monitoring the movements of the French government on policy, diplomacy, finance, international exchanges, infrastructure construction, business, and trade. Some important intelligence was authorized by the US to be shared with the other “Five Eyes” countries, showing that the countries of the “Five Eyes” alliance are also beneficiaries of US espionage operations.
The Global Surveillance Network
The US global Internet surveillance programs and stations are described as ubiquitous “snoopers” in cyberspace, stealing user data from the global internet in real time. This eavesdropping capability has become an indispensable foundation of the US efforts to build the “Empire of Hacking” and the “Empire of Surveillance.”
To maintain such a vast surveillance program, the annual funding budget is substantial. With the explosive growth of internet data, the demand for funding is bound to rise. This is one of the main reasons why the US government conspired with its intelligence agencies to plan and promote the Volt Typhoon operation, according to the report.
Politicizing Cybersecurity
Over the years, the US government has politicized the issue of cyberattack attribution, serving its own self-interests. Companies like Microsoft and CrowdStrike have been influenced by the desire to appeal to US politicians, government agencies, and intelligence agencies, as well as to enhance commercial interests. They have used various names with geo-political features to describe hacking groups, such as “Typhoon,” “Panda,” and “Dragon,” often without sufficient evidence and rigorous technical analyses.
The Need for International Collaboration
In its concluding remarks, the report emphasizes the importance of international collaboration in the cybersecurity industry, especially as the geopolitical landscape grows increasingly complex. It calls for cybersecurity firms and research institutes to focus on the research of cybersecurity threat prevention technology and to provide users with higher-quality products and services. This, the report suggests, will help keep the internet developing in a healthy way, in line with the progress of human society.
Conclusion
The Volt Typhoon report adds another layer to the complex and contentious issue of cyber espionage. While the US and its allies assert that Volt Typhoon is a state-sponsored cyber actor from China, the counter-narrative presented by the National Computer Virus Emergency Response Center and its partners paints a different picture. The report highlights the use of sophisticated tools and tactics, false flag operations, and extensive surveillance, suggesting a broader and more nuanced understanding of the cyber landscape. As the debate continues, the need for transparent and collaborative approaches to cybersecurity becomes increasingly evident.



