War 2.0: China Suspected in Massive Cyberattack on U.N., U.S. Gov't, and More
August 3, 2011 3:50 PM
China is suspected in a record setting hack, which affected many nations over the last five years.
(Source: Army Recognition)
The attack is believed to have done tremendous financial damage to those affected and given a financial boost to the attacker.
The attacks largely target the U.S. -- which has weak cyber-security, but also targeted Asian nations, Canada, and several European nations.
Attack "raped and pillaged" 72 organizations over 5 years
) subsidiary McAfee, has
just gone public
[declassified report] with an incredible study into what it says is the world's biggest organized computer hack in history. The attack, which it dubs "Operation Shady RAT" (RAT stands for remote access tool), began in mid-2006 and was still ongoing at the start of this year. And unsurprisingly, China -- arguably the world's foremost cyber-superpower -- is suspected as the guilty party.
I. U.S. and Others Get "Raped and Pillaged"
McAfee's vice president of threat research, Dmitri Alperovitch, in
, comments, "Companies and government agencies are getting raped and pillaged every day. They are losing economic advantage and national secrets to unscrupulous competitors. This is the biggest transfer of wealth in terms of intellectual property in history. The scale at which this is occurring is really, really frightening."
In his report he describes how a team of savvy hackers organized by a "state actor" infiltrated 72 carefully selected government and corporate systems around the world and began rapidly stealing valuable information.
Government victims included United States, Taiwan, India, South Korea, Vietnam, and Canada. A number of multinational organizations including the Association of Southeast Asian Nations (ASEAN), the International Olympic Committee (IOC), the World Anti-Doping Agency, and the United Nations. Numerous defense contractors and high-tech companies were also infiltrated in the U.S. and abroad.
In one of the highest profile attacks -- the infiltration of the United Nations' servers, the attacker gained access to systems belonging to the secretariat in Geneva in 2008 and then proceeded to lurk for two years, stealing valuable classified documents.
The longest attack appears to have targeted the Olympic committee of an unnamed South Asian nation, last 28 months. Many of the attacks were far briefer lasting only a month.
The sophisticated plot was discovered when McAfee researchers reviewing the server logs on affected U.S. contractors discovered that they were all communicating with common command-and-control servers in the unnamed attacker nation.
Mr. Alperovitch recalls the shock at this discovery, writing, "Even we were surprised by the enormous diversity of the victim organizations and were taken aback by the audacity of the perpetrators. What is happening to all this data ... is still largely an open question. However, if even a fraction of it is used to build better competing products or beat a competitor at a key negotiation (due to having stolen the other team's playbook), the loss represents a massive economic threat."
II. The Red Dragon
Unsurprisingly most suspect China, given who was attacked and the nation's long history of cyberaggression [
Neither China or McAfee have officially commented on this possibility. But the timing lines up remarkably.
The attacks on the IOC and Olympic committee were executed in 2008, right before
the Beijing Olympics
. Given China's obsessive interest in topping its foreign competitors in the medal counts, there's a clear motive for the hacks, as they could have filled in secret details on when the Olympic officials planned to conduct drug tests. In theory China could have used the data to game the system, obfuscating steroid use or other types of cheating.
The attacks also were very focused on southeast Asia. South Korea, Japan, and Taiwan -- key economic rivals of China were all targeted.
In Taiwan's case, the attack may have served a double purpose, as China views Taiwan as a rebel province and has long looked for ways to undermine it economically and politically.
Jim Lewis, a cyber expert with the Center for Strategic and International Studies, states, "Everything points to China. It could be the Russians, but there is more that points to China than Russia."
One unnamed briefed expert affirms that the classified version of the information McAfee presented points to China.
III. Preying on the Weak
If the attacks were indeed the work of the Chinese government or its contractors, it scored a massive win economically. It's unknown what if any sort of punishment can be brought against the nation, as even if the evidence points to China, in such matters it's hard to conclusively prove the origin of an attack.
Further, many of the affected nations like the U.S. owe vast amounts of debt to the Chinese government and depend on China to support their
rare mineral resource
Many view China's recent actions as the strong of cyberspace picking on the weak. The U.S. is among those that has been
perceived as a "cyberweakling"
Vijay Mukhi, a cyber-expert based in India, states, "I'm not surprised because that's what China does, they are gradually dominating the cyberworld. I would call it child's play (for a hacker to get access to Indian government data) ... I would say we're in the stone age."
The report, which coincided with the
annual Black Hat security convention
in Las Vegas, took many by surprise.
Taiwanese officials said they were not aware of being part of a broader attack, though they said they were aware of many attacks against their government servers. U.N. officials also reported being unaware of the intrusion, though they were investigating. And the government of India refused to comment on whether it was aware of the attack on its government servers.
Japan seemed the least surprised, indicating knowledge of the attack, while emphasizing the uncertainty about who was behind the attacks. They say that they are conducting and investigation and working on "finalizing some guidelines. We aim to raise the security level as a whole and build a partnership between private sector organizations where information can be shared to prevent such attacks."
McAfee has informed all 72 companies who were attacked. In its public version of the report, it redacted the affected corporate parties' names, though it mentioned what nation and what business sector they were in.
Full details of the record setting assault are still not available, and may never be available. If McAfee is to be believed, though, the financial impact is likely enormous. The attack likely puts the affected governments, including the U.S. in panic mode. The pressing question -- how to improve their security so these attacks don't happen, and how to bring to justice an attacker who wields tremendous international financial power, should a breach occur.
"It's okay. The scenarios aren't that clear. But it's good looking. [Steve Jobs] does good design, and [the iPad] is absolutely a good example of that." -- Bill Gates on the Apple iPad
Chinese Hackers Score Heist of 35 Million South Koreans' Personal Info
July 28, 2011, 9:43 AM
"Pwnies" are the Grammies of the Hacker World
July 27, 2011, 4:21 PM
Cheap Labor in China Coming to an End
June 20, 2011, 10:52 AM
China Threatens Google for Speaking Out Against Cyberattacks
June 6, 2011, 9:44 AM
Reports: Hackers Use Stolen RSA Information to Hack Lockheed Martin
May 30, 2011, 10:14 AM
Science & Environment
February 20, 2017, 6:37 AM
The USA’s newest weather satellite sends first photos.
January 24, 2017, 6:41 AM
Netflix took a decision to invest in original content
January 19, 2017, 7:00 AM
Amazon Airborne Fulfillment Center – Your Merchandise Drop-Shipped from the Clouds
December 29, 2016, 5:00 AM
Amazon is experimenting with a new kind of grocery stores, Amazon Go
December 8, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Most Popular Articles
What is the Apple’s iPhone 8 specifications and release date?
April 14, 2017, 5:43 AM
Meet the Smartphone with four cameras - Alcatel Flashphone
April 5, 2017, 11:20 AM
Vivo V5 Plus – the Selfie Softlight is on You.
April 17, 2017, 7:05 AM
Moto G4 Plus - Powerful Unlocked Convenience
April 12, 2017, 6:25 AM
Microsoft releases details of Project Scorpio console
April 7, 2017, 7:50 AM
Latest Blog Posts
Link your Brain to Your Computer – In Four Years…Maybe
Apr 22, 2017, 7:03 AM
Google Home can now identify users by their voice.
Apr 21, 2017, 7:15 AM
Amazon Lex – Now Available for Developers.
Apr 20, 2017, 6:58 AM
You can now use Instagram offline on your Android Smartphone
Apr 19, 2017, 8:00 AM
Now you can livestream to YouTube from your mobile device.
Apr 18, 2017, 8:05 AM
Google Home – Is It a Spy Device?
Apr 17, 2017, 7:30 AM
Apple added to self –driving test permit list
Apr 15, 2017, 6:21 AM
Project Scorpio – Coming on June 11
Apr 14, 2017, 6:20 AM
Looks Like Samsung Has Been Forgiven.
Apr 13, 2017, 6:50 AM
United Airlines - Blasted on China’s Social Network and the Stock Market
Apr 12, 2017, 6:50 AM
Amazon's Third-Party Sellers Hacked
Apr 11, 2017, 6:25 AM
Microsoft Surface Pro5 Details Revealed
Apr 9, 2017, 6:41 AM
Own An Android Phone? Then you could be hacked over Wi-FI
Apr 7, 2017, 6:47 AM
Apple confirms iOS 10.3 bug and its effect on iCloud Services
Apr 6, 2017, 6:30 AM
Apple Rolls Out New Version of Apple Music
Apr 5, 2017, 10:35 AM
Apple in the News
Apr 4, 2017, 9:03 AM
Apple iPhones Will Soon Feature Graphics Chips Designed BY Apple
Apr 3, 2017, 6:23 AM
AMD Ryzen Desktop Processors Performance
Apr 2, 2017, 6:30 AM
What makes a camera Lensless?
Apr 1, 2017, 7:45 AM
Google halts Android Wear 2.0 Update Due to Bug
Mar 31, 2017, 7:27 AM
Uber Technologies Inc Driverless Car hit by Human-driver
Mar 30, 2017, 8:00 AM
Android Creator and New Bezel-less Smartphone
Mar 29, 2017, 10:28 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information