Friday, August 26, 2005

Time Teaser: Inside the Chinese Hack Attack

Nathan Thornburgh writes yesterday (25 Aug. 2005) in a Time.com online teaser:

Hackers breaking into official U.S. networks are not just using Chinese systems as a launch pad, but are based in China, sources tell TIME. Their story: Sometime on November 1st, 2004, hackers sat down at computers in southern China and set off once again on their daily hunt for U.S. secrets. Since 2003 the group had been conducting wide-ranging assaults on U.S. government targets to steal sensitive information, part of a massive cyberespionage ring that U.S. investigators have codenamed Titan Rain. On this particular night, the hackers' quarry was military data, and they were armed with a new weapon to reach out across cyberspace and get it.

This was a scanner program that "primed the pump," according to a former government network analyst who has helped track Titan Rain, by searching vast military networks for single computers with vulnerabilities that the attackers could exploit later. As with many of their tools, this was a simple program, but one that had been cleverly modified to fit their needs, and then used with ruthless efficiency against a vast array of U.S. networks. After performing the scans, the source says, it's a virtual certainty that the attackers returned within a day or two and, as they had on dozens of military networks, broke into the computers to steal away as much data as possible without being detected.

They hit hundreds of computers that night and morning alone, and a brief list of scanned systems gives an indication of the breadth of the attacks. At 10:23 p.m. pacific standard time (PST), they found vulnerabilities at the U.S. Army Information Systems Engineering Command at Fort Huachuca, Arizona. At 1:19 am PST, they found the same hole in computers at the military's Defense Information Systems Agency in Arlington, Virginia. At 3:25 am, they hit the Naval Ocean Systems Center, a defense department installation in San Diego, California. At 4:46 am PST, they struck the United States Army Space and Strategic Defense installation in Huntsville, Alabama. As with prior attacks, the targeted networks were unclassified systems; the military's classified networks are not connected directly to the Internet. But even unclassified systems store sensitive information and provide logistics support throughout the armed forces. Government analysts say the attacks are ongoing, and increasing in frequency. But whether the Titan Rain hackers are gathering industrial information or simply testing their ability to infiltrate a rival nation's military systems, the U.S. government is taking the threat very seriously.

[In next week's magazine, available at Time.com on Sunday and on the newsstands Monday, TIME presents the Titan Rain investigation in depth — what they stole, how they stole it, and what the United States is doing to stop them.]

Monday, March 05, 2007

Titan Rain: Sandia Tried to Keep Probe of Breach Quiet

Jaikumar Vijayan writes on ComputerWorld:

Last month, a jury in New Mexico awarded Shawn Carpenter $4.3 million as part of a wrongful termination lawsuit against Sandia National Laboratories, where he had worked as a network intrusion- detection analyst.

Carpenter was fired in early 2005 after he shared information about a network compromise with the FBI and the U.S. Army. Sandia, which is run by a subsidiary of Lockheed Martin Corp. under a contract with the U.S. Department of Energy, claimed that Carpenter had inappropriately disclosed confidential information. But Carpenter said he did so for national security reasons after using reverse-hacking techniques to find evidence that the perpetrators of the May 2004 breach at Sandia belonged to a Chinese hacking group called Titan Rain.

Carpenter worked at the U.S. Department of State’s Cyber Threat Analysis Division until Feb. 23, when he left to take a job as a principal research analyst at NetWitness Corp., a network security start-up in Herndon, Va. He discussed the incident at Sandia in an interview with Computerworld that was conducted via e-mail last month.

More here.

Wednesday, November 23, 2005

Security Experts Reveal Details on 'Titan Rain'

Tom Espiner writes in C|Net News:

Security experts have revealed details about a group of Chinese hackers who are suspected of launching intelligence gathering attacks against the U.S. government.

The hackers, believed to be based in the Chinese province of Guangdong, are thought to have stolen US military secrets, including aviation specifications and flight-planning software.

The U.S. government has coined the term "Titan Rain" to describe the hackers.

"From the Redstone Arsenal, home to the Army Aviation and Missile Command, the attackers grabbed specs for the aviation mission-planning system for Army helicopters, as well as Falconview 3.2, the flight-planning software used by the Army and Air Force," said Alan Paller, director of the SANS Institute, on Tuesday.

Sunday, August 28, 2005

Titan Rain: The Invasion Of The Chinese

Following up on the "teaser" that Time posted last week, here is an excerpt of the full article available today.

Nathan Thornburgh writes on Time.com:

It was another routine night for Shawn Carpenter. After a long day analyzing computer-network security for Sandia National Laboratories, where much of the U.S. nuclear arsenal is designed, Carpenter, 36, retreated to his ranch house in the hills overlooking Albuquerque, N.M., for a quick dinner and an early bedtime. He set his alarm for 2 a.m. Waking in the dark, he took a thermos of coffee and a pack of Nicorette gum to the cluster of computer terminals in his home office. As he had almost every night for the previous four months, he worked at his secret volunteer job until dawn, not as Shawn Carpenter, mid-level analyst, but as Spiderman—the apt nickname his military-intelligence handlers gave him—tirelessly pursuing a group of suspected Chinese cyberspies all over the world. Inside the machines, on a mission he believed the U.S. government supported, he clung unseen to the walls of their chat rooms and servers, secretly recording every move the snoopers made, passing the information to the Army and later to the FBI.

The hackers he was stalking, part of a cyberespionage ring that federal investigators code-named Titan Rain, first caught Carpenter's eye a year earlier when he helped investigate a network break-in at Lockheed Martin in September 2003. A strikingly similar attack hit Sandia several months later, but it wasn't until Carpenter compared notes with a counterpart in Army cyberintelligence that he suspected the scope of the threat. Methodical and voracious, these hackers wanted all the files they could find, and they were getting them by penetrating secure computer networks at the country's most sensitive military bases, defense contractors and aerospace companies.

Carpenter had never seen hackers work so quickly, with such a sense of purpose. They would commandeer a hidden section of a hard drive, zip up as many files as possible and immediately transmit the data to way stations in South Korea, Hong Kong or Taiwan before sending them to mainland China. They always made a silent escape, wiping their electronic fingerprints clean and leaving behind an almost undetectable beacon allowing them to re-enter the machine at will. An entire attack took 10 to 30 minutes. "Most hackers, if they actually get into a government network, get excited and make mistakes," says Carpenter. "Not these guys. They never hit a wrong key."

Thursday, July 15, 2010

Talk on Chinese Cyber Army Pulled From Black Hat

Dennis Fisher writes on ThreatPost:

A talk on China's state-sponsored offensive security efforts scheduled for the Black Hat conference later this month has been pulled from the conference after concerns were raised by some people within the Chinese and Taiwanese government about the talk's content.

The presentation was to be delivered by Wayne Huang, CTO of Armorize, an application security company with R&D operations in Taiwan. The talk was billed as an in-depth, historical look at the offensive capabilities and operations of China's so-called cyber-army. The description of the presentation on the Black Hat site promises an interesting presentation.

"Operation Aurora, GhostNet, Titan Rain. Reactions were totally different in the US and in Asia. While the US media gave huge attention, Asia find it unbelievable and interesting, that cyber warfare and government-backed commercial espionage efforts that have been well established and conduced since 2002, and have almost become a part of people's lives in Asia, caused so much "surprise" in the US. Here we'll call this organization as how they've been properly known for the past eight years as the "Cyber Army," or "Wang Jun" in Mandarin. This is a study of Cyber Army based on incidences, forensics, and investigation data since 2001. Using facts, we will reconstruct the face of Cyber Army (CA), including who they are, where they are, who they target, what they want, what they do, their funding, objectives, organization, processes, active hours, tools, and techniques."

Caleb Sima, Armorize's CTO and co-founder, said on his Twitter feed yesterday that the talk had been pulled. "I had to pull our blackhat talk. Taiwanese gov is prohibiting it due to sensitive materials. Unreal."

More here.

Thursday, January 14, 2010

Alleged China Attacks Could Test U.S. Cyber Security Policy

Jaikumar Vijayan writes on ComputerWorld:

The attacks on Google and more than 30 other Silicon Valley companies by agents allegedly working for China is focusing renewed attention on the issue of state-sponsored cyber attacks and how the U.S. government should respond to them.

The U.S. has no formal policy for dealing with foreign government-led threats against U.S. interests in cyberspace. With efforts already under way to develop such a policy, the recent attacks could do a lot shape the policy and fuel its passage through Congress.

In a revelation that was surprising for its boldness, Google on Tuesday said that agents possibly working on behalf of the Chinese government had hacked into its computers -- and those of more than 30 other multi-national companies.

This is not the first time Beijing has been accused of state-sponsored espionage. Over the past five years, China has been implicated in dozens of attacks involving U.S. commercial, government and military targets. The most sensational of these involved a Chinese hacking group called Titan Rain, which in the early 2000s is believed to have stolen U.S. military and nuclear information.

More here.

Friday, November 28, 2008

UK Institute for Public Policy Research: IT Is A Key Terrorist Tool

Tom Young writes on Computing:

The embedding of IT in the UK's critical national infrastructure, and the country's increasing reliance on that infrastructure, poses serious national security concerns for the country, according to one of the Labour Party's favourite think tanks.

In addition to forming the backbone of the communications infrastructure, IT is now also heavily embedded in the running of more traditional infrastructures such as water, power and transport systems.

"The significance of this is all the greater when one considers the extent to which we have become an infrastructure-reliant society more generally," says a report by the Institute for Public Policy Research (IPPR).

Over the last decade, companies around the world have taken steps to adopt a lean approach to business operations.

Ast a consequence, the supply chains of businesses have become globally stretched. This has increased efficiency but it also comes with a downside in terms of an increased reliance on a smoothly functioning set of infrastructures in energy, transportation and communications.

"In other words, the more efficiently we operate, the less slack there is in the system to cope with major disruption," says the IPPR report.

The Titan Rain campaign of coordinated cyber attacks on US computer systems since 2003 and attacks on Estonian financial infrastructure in May 2007 have highlighted the dangers of cyber warfare.

More here.

Wednesday, September 05, 2007

Titan Rain UK: How Chinese Hackers Targeted Whitehall

Richard Norton-Taylor writes in The Guardian (UK):

Chinese hackers, some believed to be from the People's Liberation Army, have been attacking the computer networks of British government departments, the Guardian has learned.

The attackers have hit the network at the Foreign Office as well as those in other key departments, according to Whitehall officials.

The Ministry of Defence declined yesterday to say whether it had been hit. An incident last year that shut down part of the House of Commons computer system, initially believed to be by an individual, was discovered to be the work of an organised Chinese hacking group, officials said.

Security and defence officials are coy about what they know of specific attacks. However, they say several Whitehall departments have fallen victim to China's cyberwarriors. One expert described it as a "constant ongoing problem".

More here.

Tuesday, February 13, 2007

Sandia 'Back-Hacker' Wins $4.3M Judgment Against Sandia Labs - UPDATE

Bob Brewin writes on FCW.com:

Shawn Carpenter, who was fired by Sandia National Laboratories in January 2005 for conducting backhacking operations against intruders he discovered on Sandia networks, won a $4.3 million wrongful discharge suit against the labs today. Backhacking occurs when networks are attacked and someone on the hacked network responds with a counterhack or attack.

Carpenter, who worked in Sandia’s computer security operations organization, started detecting attacks against Sandia networks in 2002, according to court records in the 2nd District Court of New Mexico. Carpenter brought the attacks to the attention of Sandia and other government agencies, including the Army Research Laboratory and the FBI.

More here.

Background: "Titan Rain: The Invasion Of The Chinese"

UPDATE: 11:24 PST 02/15/2007: Time.com also has an update on this story here.

Friday, May 26, 2006

U.S. DoD: China Fielding Cyberattack Units

Remeber all the hoopla on "Titan Rain'?

Josh Rogan writes on FCW.com:

China is stepping up its information warfare and computer network attack capabilities, according to a Defense Department report released this week.

The Chinese People’s Liberation Army (PLA) is developing information warfare reserve and militia units and has begun incorporating them into broader exercises and training. Also, China is developing the ability to launch pre-emptive attacks against enemy computer networks in a crisis, according to the document, “Annual Report to Congress: Military Power of the People’s Republic of China 2006.”

The Chinese approach centers on using civilian computer expertise and equipment to enhance PLA operations, the DOD report states.

More here.

Tuesday, December 13, 2005

Hacker Attacks in U.S. Linked to Chinese Military

I've provided a pointer to an extensive article in Time on "Titan Rain" here on the blog bacl in late August 2005. I see that the topic has cropped up once again...

An AFP newswire article, via PhysOrg.com, reports that:

A systematic effort by hackers to penetrate US government and industry computer networks stems most likely from the Chinese military, the head of a leading security institute said.

The attacks have been traced to the Chinese province of Guangdong, and the techniques used make it appear unlikely to come from any other source than the military, said Alan Paller, the director of the SANS Institute, an education and research organization focusing on cybersecurity.

"These attacks come from someone with intense discipline. No other organization could do this if they were not a military organization," Paller said in a conference call to announced a new cybersecurity education program.

In the attacks, Paller said, the perpetrators "were in and out with no keystroke errors and left no fingerprints, and created a backdoor in less than 30 minutes. How can this be done by anyone other than a military organization?"

Thursday, August 25, 2005

Hackers Attack Via Chinese Networks

Bradley Graham writes in The Washington Post:

Web sites in China are being used heavily to target computer networks in the Defense Department and other U.S. agencies, successfully breaching hundreds of unclassified networks, according to several U.S. officials.

Classified systems have not been compromised, the officials added. But U.S. authorities remain concerned because, as one official said, even seemingly innocuous information, when pulled together from various sources, can yield useful intelligence to an adversary.

"The scope of this thing is surprisingly big," said one of four government officials who spoke separately about the incidents, which stretch back as far as two or three years and have been code-named Titan Rain by U.S. investigators. All officials insisted on anonymity, given the sensitivity of the matter.

Whether the attacks constitute a coordinated Chinese government campaign to penetrate U.S. networks and spy on government databanks has divided U.S. analysts. Some in the Pentagon are said to be convinced of official Chinese involvement; others see the electronic probing as the work of other hackers simply using Chinese networks to disguise the origins of the attacks.