Showing posts with label Chinese Hackers. Show all posts
Showing posts with label Chinese Hackers. Show all posts

Thursday, February 10, 2011

DTN News - BREAKING NEWS: Oil Firms Hit By Hackers From China, Report Says

DTN News - BREAKING NEWS: Oil Firms Hit By Hackers From China, Report Says
Source: DTN News - - This article compiled by Roger Smith from reliable sources By NATHAN HODGE And ADAM ENTOUS - The Wall Street Journal
(NSI News Source Info) TORONTO, Canada - February 10, 2011: Hackers who appear to be based in China have conducted a "coordinated, covert and targeted" campaign of cyber espionage against major Western energy firms, according to a report expected to be issued Thursday by cybersecurity firm McAfee Inc.

Law-enforcement agencies said they are investigating the incidents, which McAfee said have been going on at least since late 2009 but may have started as early as 2007. The company said the attacks, which they dubbed "Night Dragon," were still occurring.

McAfee said the hackers targeted five multinational firms, but wouldn't identify the companies by name because some of them are clients. McAfee said it was sharing the findings "to protect those not yet impacted and to repair those who have been." Asked if they were victims of the hacking, BP PLC and ExxonMobil Inc., among other large oil companies, declined to comment. Chevron Corp. said it wasn't aware of any successful hacks into the company's data systems by Night Dragon.

Sensitive Internal Documents Taken

According to McAfee, the cyberattacks successfully took gigabytes of highly sensitive internal documents, including proprietary information about oil- and gas-field operations, project financing and bidding documents. And that pattern of espionage, the company said, should raise fresh alarms in the corporate world about information theft.

"While Night Dragon attacks focused specifically on the energy sector, the tools and techniques of this kind can be highly successful when targeting any industry," the report states.

McAfee and its competitors have an incentive for publicizing threats like Night Dragon because they are in the business of selling cybersecurity services. The company has informed the FBI of its report, which said it was investigating the attacks and took the matter seriously.

U.S. intelligence agencies have warned in recent years that China is developing sophisticated cyber warfare strategies which could be used to attack governments and key industries. China, the second-largest economy after the U.S., is keenly interested in competing for energy resources around the world to fuel domestic growth.

"It's important to get this out in public discussion, so companies can identify that kind of threat," said Ron Plesco, CEO of the National Cyber Forensic Training Alliance Foundation, a group that tracks cybercrime threats. "And sharing information adds toward the ultimate goal of mitigation."

The Night Dragon attacks used hacking tools that exploited Microsoft Corp. operating systems and remote administration tools to copy and extract information, according to McAfee. It appears to have been designed purely for spying. "We saw no evidence of sabotage activities" in these attacks, said Dmitri Alperovitch, vice president of threat research at McAfee.

Trail Leads Back to China

Mr. Alperovitch said researchers were able to trace data taken from those companies back to Chinese Internet addresses in Beijing. The hacking tools used were mainly of Chinese origin, he said and the hackers didn't take steps to cover their tracks.

"These individuals almost seemed like company worker bees," he said. "They operated on a strict weekdays, nine-to-five Beijing time-zone schedule."

Through forensic research, McAfee identified one individual who appeared to provide the external servers used by the hackers. McAfee identified this individual as Song Zhiyue, based in Heze City, Shandong Province, China. It is unclear to what extent Mr. Song might have been aware of the espionage. McAfee believes many actors participated in these attacks.

Mr. Alperovitch said it was unclear if the attacks were done with any official sanction. "The facts point to Chinese hacker activity that is organized, so [it is] potentially directed either by the private sector or the public sector. But it's impossible for me to know for sure which one," he said.

Wang Baodong, a spokesman for the Chinese embassy in Washington, said he had no knowledge of the report, but added that past allegations about Chinese hacking had been raised unfairly. "China has very strict laws against hacking activities, and China is also a victim of such activity," he said.

A 2010 Defense Department report to Congress on Chinese military capabilities said computer systems around the world, including U.S. government networks, had been the target of intrusions that appear to originate from China. The report added that it was unclear if those intrusions were done at the behest of the Chinese military of elements of the Chinese government.

Early last year, Google Inc. took the unusual step of complaining publicly about sophisticated cyberattacks that it claimed had originated in China. McAfee investigated those attacks, which it dubbed Operation Aurora. Leaked U.S. diplomatic cables collected by the WikiLeaks website included allegations that the attacks were ordered by top Chinese leaders.

© Copyright (c) DTN News Defense-Technology News

  • Sunday, April 11, 2010

    DTN News: Indian Army Braces For Cyber Attacks

    DTN News: Indian Army Braces For Cyber Attacks Source: DTN News / Int'l Media (NSI News Source Info) NEW DELHI, India - April 12, 2010: After the real world, the armed forces are on a red alert in the virtual world as well. Even as they tackle Chinese troop intrusions on the ground, they are grappling with a sharp increase in online espionage attacks from across the Line of Actual Control as well. Top sources say the Army-CERT (computer emergency response team) recently issued the high alert to all military formations and installations to guard against “focussed large-scale cyber attacks” that are being planned on “internet facing” government organisations, prominent brands and corporate groups. Quoting “reliable” information, the alert ominously warns the cyber-attacks are likely to be launched from this month onwards. The date mentioned, in fact, is March 31. Effective measures must be taken to protect networks from data-thefts, “distributed denial-of-service attacks”, paralysing computer viruses and the like, it says. Sources said several military establishments, including the Defence Services Staff College at Wellington, had even refrained from using computers directly connected to internet modems for three-four days over the last week as a precaution. Though the alert holds the cyber-attacks can originate from any country across the world, the suspicion is firmly on Chinese hackers. This comes even as a group of Canadian and American cyber-security researchers in the new report, `Shadows in the Cloud’, held that China-based online espionage gangs have accessed classified documents from several Indian defence and security establishments. The defence ministry preferred to remain quiet, only saying that it was “studying the report” which had “lot of grey areas”. Blasting this “clueless state of affairs”, experts said Indian agencies really needed to bolster cyber-security measures as well as sharpen their own cyber-warfare or information warfare skills. China, in particular, has made cyber-warfare one of its topmost military priorities, with Chinese hackers regularly breaking into sensitive computer networks of countries like US, UK, Germany and India. In December last year, for instance, Chinese online espionage agents had even tried to penetrate computers in the Indian national security adviser’s office. The new report, for instance, says the researchers came across one Indian encrypted diplomatic correspondence, two documents marked `secret’, six as `restricted’ and five as `confidential’ which were accessed by the Chinese hackers. Moreover, the “affected” institutions ranged from National Security Council Secretariat and several Indian embassies to the 21 Mountain Brigade in Assam and the Air Force Station at Race Course in New Delhi, which is bang opposite the PM’s official residence. Apart from files related to India’s surface-to-air missiles systems and Shakti artillery command and control systems, the people `compromised’ included even an officer of the directorate-general of military intelligence. “Cyber-warfare can be even more destructive than missile strikes, crippling as they can economic, communication and strategic networks and infostructure,” said a senior officer.

    Tuesday, April 06, 2010

    DTN News: China Cyber-Espionage Eyes Indian Defense

    DTN News: China Cyber-Espionage Eyes Indian Defense Source: DTN News / Int'l Media (NSI News Source Info) NEW DELHI, India - April 7, 2010: Sensitive security information linked to India's missile and armament systems may have been compromised by Chinese hackers believed to have broken into top secret files of the Indian Defense Ministry. The allegation stems from a report published by a group of U.S. and Canadian computer security researchers who monitored a spying operation, observing the trails of the hackers as they pilfered classified and restricted documents from India's Defense Ministry. Among the systems believed to have been hacked is the Shakti, the newly introduced artillery combat and control system of the Indian army, and the Iron Dome, the country's mobile missile defense system, local media reported. According to the report, researchers based at the Munk School of Global Affairs at the University of Toronto managed to provide a detailed account of the spying operation called Shadow Network, documenting not only what material had been hacked but accessing confidential documents, also, about India's relations in West Africa, Russia and the Middle East. While the identity and designs of the intruders have yet to be determined, the researchers traced the spy operation to computer servers in Chengdu, western China. The findings of the report have sparked concern within the ranks of the government in India, which said earlier this week that it was investigating the allegations. "This is a serious issue and we are looking into it," Sitansu Kar, a spokesman for the ministry, was quoted as saying in Business Week report. The allegations follow a move by Google Inc. to redirect users of its Chinese Web site to Hong Kong "to avoid the nation's censorship laws after the U.S. company said it had detected cyberattacks from mainland on human-rights activists," Business Week reported. At the time, the case underscored mounting concerns over the growing trend of cyber espionage. Ahead of the report's publication, India stopped short of acknowledging that government networks had been attacked by China, saying that "no one attempt had been successful." Chinese officials have since then rebuffed any allegation of involvement. "The Chinese government considers hacking a cancer to the whole of society," said Ye Lao, a state official in Western China. The Dalai Lama's office was also part of the research. "From what we are seeing, the people attacking our computers have a very systematic approach to reading our private communications," said Tenzin Takhla, the exiled Tibetan leader's secretary. "What the experts have told us is that they these are coming out of China, and that makes sense."

    Tuesday, August 04, 2009

    DTN News: Hacker Training Has Become An Industry In China

    DTN News: Hacker Training Has Become An Industry In China
    *Source: DTN News / Int'l Media
    (NSI News Source Info) BEIJING, China - August 4, 2009: In the last year, China has suffered a loss of a billion dollars because of hackers, and what has left authorities in Beijing very worried is a report that the training of hackers has become an industry, and generated an estimated income of 238 million Yuan in the same period.
    According to a China Daily report, hackers have stolen people's bank account numbers and passwords and damaged the Internet users' computers and servers.
    The National Computer Network Emergency Response Technique Team/Coordination of China warns that a large numbers of hacker schools have been set up-mostly online-around China. (The exact number remains unknown.)
    "Lots of hacker schools only teach students how to hack into unprotected computers and steal personal information. They then make a profit by selling users' information," said Wang Xianbing, a security consultant for hackerbase.com. For investing hundreds of yuan in hacker school, students could obtain the skills to make a fortune, Wang said.
    "Hacker school is a bit like driving school - they teach you how to drive but it's up to you if you are going to drive safely or kill someone," said Wang.
    "Instructing people on how to hack into other people's computers to make profit is clearly a crime," said Li Xuxi, a lawyer from Beijing Zi Guang law firm.
    Such hacker schools should be closed and those responsible, should be punished, said Li.

    Wednesday, April 08, 2009

    Chinese 'Spying' Rattles Australia

    Chinese 'Spying' Rattles Australia
    (NSI News Source Info) April 8, 2009: Hackers reportedly sought access to Prime minister Rudd's emails last year, raising concerns about corporate takeovers. Australia has tightened its security control on communication with Beijing after Chinese spies reportedly hacked the phone and computer of Australian Prime Minister Kevin Rudd during his trip to China, and targeted Rio Tinto in the early stage of Chinalco’s bid. The invisible attacks from Chinese hackers will further intensify Sino-Australian tensions, sparked by Canberra’s moves to delay and oppose mutibillion-dollar Chinese investment proposals in Australia’s resources sector. Chinese authorities had tried to access the laptop computers and mobile phones used by Kevin Rudd and other government officials during the Prime Minister’s trip to China in August last year, newspaper The Australian reported Friday, citing unnamed intelligence sources. Beijing's electronic espionage as well as other repeated attempts to break into the internet networks of the Australian government, private businesses, and foreign embassies based in Canberra, led to a further tightening of communications security procedures for senior government figures travelling to China, the newspaper added. Officials at the Chinese embassy in Canberra could not be immediately reached for comment, with phone calls unanswered. The growing suspicion of Chinese espionage has triggered tightened scrutiny of recent Chinese investments in various Australian miners. Australia's Foreign Investment Review Board last month extended the investigation into Chinalco’s plan to purchase iron ore, copper, bauxite, alumina and aluminum assets from Rio Tinto for $12.3 billion, in addition to buying $7.3 billion worth of convertible notes that could double its equity stake in Rio Tinto to 18.0%. Shortly after putting the Chinalco-Rio Tinto deal on hold, Australia’s Treasury last Friday rejected an $1.8 billion bid by Chinese state-owned Minmetals' for OZ Minerals because the company's prized Prominent Hill mine was near a military weapons-testing range in the deserts of outback Australia.