Friday, April 03, 2009

'Tenuous' Trail Leads From GhostNet to Hacker

Rob Lemos writes on SecurityFocus:

A telltale e-mail address in the GhostNet report led two researchers to the online home of a seemingly low-level Chinese hacker, according to an analysis posted on Thursday, but an author of the original report stressed that the cyber criminal is likely only related to a lesser piece of malware.

The latest analysis follows the online trail from an e-mail address turned up by researchers as part of their investigation into GhostNet, a cyber espionage network that spanned 1,295 compromised systems including computers belonging to embassies and dissident groups. The e-mail address led to a twenty-something Chinese hacker born in Chengdu City in the Chinese province of Sichuan, according to a blog post by Scott Henderson, a blogger who follows the Chinese hacking community.

However, the e-mail address was found only on two of the computers analyzed for the investigation, said Nart Villeneuve, a researcher at the CitizenLab and one of the authors of the GhostNet report. Both computers had been infected with a second piece of malware, separate from the gh0st remote access tool (gh0stRAT) that formed the backbone of the surveillance network, he said.

"That is a valid piece of malware but it is not the one related to the malware that connected to the admin interface for the gh0stRAT," Villeneuve said.

More here.

Sunday, March 29, 2009

Meet The Canadians Who Busted GhostNet

Omar El Akkad writes in The Globe and Mail:

Against the backdrop of humming computers in the underground lab in Toronto's Munk Centre for International Studies, a screen flickered, and the most politically explosive cyber-spy network in the world began to reveal itself.

It was March 6, 12:33 p.m., and Nart Villeneuve was getting frustrated. The 34-year-old international relations student and part-time tech geek had tried everything to track down a piece of malicious software that had infected computers around the world, including those in the offices of the Dalai Lama.

Finally, he turned to the ultimate hacker's tool: He entered some of the code from those infected computers into Google. Just like that, he found one of the cyber-spy network's control servers, then another, and another. From that Eureka moment came a flood of information, almost all of it suggesting the ring originated in China.

A team of Canadian researchers revealed this weekend a network, dubbed GhostNet, of more than 1,200 infected computers worldwide that includes such “high-value targets” as Indonesia's Ministry of Foreign Affairs and the Indian Embassy in Kuwait, as well as a dozen computers in Canada.

More here.

GhostNet In The Machine

Paul Maidment writes on Forbes.com:

The Information Warfare Monitor, a Canadian cyber-espionage watchdog, goes to pains not to point the finger of blame at the Chinese government for a massive China-based cyberspy ring it has uncovered. "While our analysis reveals that numerous politically sensitive and high-value computer systems were compromised in ways that circumstantially point to China as the culprit," it writes in a report issued March 29, "we do not know the exact motivation or the identity of the attacker(s), or how to accurately characterize this network of infections as a whole."

Beijing has always officially denied undertaking such electronic espionage. But given that the IWM has identified at least 1,295 computers in 103 countries, mostly in the foreign ministries or embassies of various Asian governments; that its investigation was triggered by a request from Beijing's adversary, exiled Tibetan leader the Dalai Lama, who was concerned the computers of his network had been hacked; and past accusations that Beijing has engaged in cyberspying, including against the U.S., the old suspicions will not only be reawakened but intensified.

More here.

Thursday, July 15, 2010

Talk on Chinese Cyber Army Pulled From Black Hat

Dennis Fisher writes on ThreatPost:

A talk on China's state-sponsored offensive security efforts scheduled for the Black Hat conference later this month has been pulled from the conference after concerns were raised by some people within the Chinese and Taiwanese government about the talk's content.

The presentation was to be delivered by Wayne Huang, CTO of Armorize, an application security company with R&D operations in Taiwan. The talk was billed as an in-depth, historical look at the offensive capabilities and operations of China's so-called cyber-army. The description of the presentation on the Black Hat site promises an interesting presentation.

"Operation Aurora, GhostNet, Titan Rain. Reactions were totally different in the US and in Asia. While the US media gave huge attention, Asia find it unbelievable and interesting, that cyber warfare and government-backed commercial espionage efforts that have been well established and conduced since 2002, and have almost become a part of people's lives in Asia, caused so much "surprise" in the US. Here we'll call this organization as how they've been properly known for the past eight years as the "Cyber Army," or "Wang Jun" in Mandarin. This is a study of Cyber Army based on incidences, forensics, and investigation data since 2001. Using facts, we will reconstruct the face of Cyber Army (CA), including who they are, where they are, who they target, what they want, what they do, their funding, objectives, organization, processes, active hours, tools, and techniques."

Caleb Sima, Armorize's CTO and co-founder, said on his Twitter feed yesterday that the talk had been pulled. "I had to pull our blackhat talk. Taiwanese gov is prohibiting it due to sensitive materials. Unreal."

More here.

Saturday, March 28, 2009

Vast Electronic Spy System Loots Computers in 103 Countries

John Markoff writes in The New York Times:


A vast electronic spying operation has infiltrated computers and has stolen documents from hundreds of government and private offices around the world, including those of the Dalai Lama, Canadian researchers have concluded.

In a report to be issued this weekend, the researchers said that the system was being controlled from computers based almost exclusively in China, but that they could not say conclusively that the Chinese government was involved.

The researchers, who are based at the Munk Center for International Studies at the University of Toronto, had been asked by the office of the Dalai Lama, the exiled Tibetan leader whom China regularly denounces, to examine its computers for signs of malicious software, or malware.

Their sleuthing opened a window into a broader operation that, in less than two years, has infiltrated at least 1,295 computers in 103 countries, including many belonging to embassies, foreign ministries and other government offices, as well as the Dalai Lama’s Tibetan exile centers in India, Brussels, London and New York.

The researchers, who have a record of detecting computer espionage, said they believed that in addition to the spying on the Dalai Lama, the system, which they called GhostNet, was focused on the governments of South Asian and Southeast Asian countries.

More here.