Vatican Computer Network Attacked By Chinese-Linked Hackers, Cybersecurity Firm Said

Hackers are always on the move, and they're constantly seeking for vulnerable systems they can attack in order to extract, or hold information as ransom.

This time, RedDelta, a hacker group linked to the Chinese government have infiltrated the computer networks at Vatican, and the Roman Catholic Church's Hong Kong-based representative, including the head of the Hong Kong Study Mission, who is seen as Pope Francis' de facto representative to China.

Computer systems at the Pontifical Institute for Foreign Missions (PIME) in Milan were also hacked.

That according to a report from Recorded Future, a U.S. firm that tracks state-backed cyberattacks.

Recorded Future said that RedDelta also targeted communications between the Hong Kong diocese and the Vatican using similar tools and methods previously identified with Chinese state-backed hacking groups.

A Vatican spokesperson had no immediate comment. The Hong Kong Study Mission did not respond to a request for comment.

Pope Francis having expressed on multiple occasions his desire to go to China
Pope Francis having expressed on multiple occasions his desire to go to China. (Credit: AFP)

Catholicism has been a problem for the Chinese government.

According to AP News, the country’s 12 million Catholics are split in half between a Chinese-backed sect and an underground church that remains loyal to the Pope.

And the deal here, is meant to unite the two factions.

The original agreement recognized the status of seven state-appointed bishops who hadn’t been approved by the Vatican, smoothing over relations between the two.

The moment was regarded as rare, marking the highest-level official encounter between the two sides in decades.

And here, the report said the attacks began in May 2020, meaning that it occurred as Beijing and the Vatican's foreign minister met in a meeting in Germany. It happened just when the relations between two have been improving, and they have been expected to renew the provisional two-year deal on the operation of the Catholic Church in China this September.

The attacks also came as the Chinese Communist Party wages a campaign to tighten its grip on all religious groups.

A Chinese delegation had been due to visit the Vatican as part of the two's continuing talks. But at this time, there are no indication if or when they would travel because of the 'COVID-19' coronavirus outbreak, said a senior Vatican.

[block:block=87]
Vatican lure document targeting the head of Hong Kong study mission to China
Vatican lure document the hacker group used to target the head of Hong Kong study mission to China. (Credit: Recorded Future)

Recorded Future, the firm that is based in Somerville, Massachusetts, believed that the cyberattacks carried out by RedDelta, were also an attempt to steal secrets and spy on the Vatican during talks over a controversial and secret provisional agreement signed by the Holy See and Beijing.

“The suspected intrusion into the Vatican would offer RedDelta insight into the negotiating position of the Holy See ahead of the deal’s September 2020 renewal,” wrote Recorded Futures in its report.

The hacker group hacked the computer systems by planting malware on them to lure users to open documents with counterfeit condolence message dated May 14, 2020, addressed to the head of the Hong Kong Study Mission and signed by Cardinal Pietro Parolin, the Vatican Secretary of State, and the sostituto, Archbishop Edgar Penã Parra.

Once the malware is planted and tricked its first victim, passwords and contacts can be stolen, data can be deleted, users and they locations can also be recorded.

China's Foreign Ministry spokesman Wang Wenbin, speaking at a daily news conference in Beijing, said that China is a "staunch defender" of cybersecurity, saying that ample evidence rather than conjecture is needed when investigating cyber events.

Just like many times before, Beijing denies that it engaged in any state-backed hacking attempts, and said that it is actually a victim of such threats.

It should be noted that the hacker group used some new techniques in the infiltrations, which makes it difficult to discern the source of the hack with 100% certainty.

This is why China called the accusation “groundless speculation.”