06 Apr 2010
Security researchers in Canada have uncovered a new targeted malware network controlled by servers in China which has compromised computer systems in the Office of the Dalai Lama, Indian government, business and academic organisations and even the United Nations.
University of Toronto researcher Nart Villeneuve highlighted the main findings of the new Shadows in the Cloud report, revealing a "complex and tiered command-and-control infrastructure".
"The attackers misused a variety of services, including Twitter, Google Groups, Blogspot, Baidu Blogs, blog.com and Yahoo Mail, in order to maintain persistent control over the compromised computers," he said in a blog post yesterday.
"This top layer directed compromised computers to accounts on free web hosting services, and as the free hosting servers were disabled, to a stable core of command-and-control servers located in China."
Any concrete link with the Chinese authorities is unproven, but the report has managed to link the network with two individuals living in Chengdu and to the underground hacking community in China.
The report, which was compiled by Shadowserver Foundation and the Information Warfare Monitor, also claimed that the network had been involved in stealing countless documents marked 'secret' or 'confidential', and that over 1,500 letters sent from the Dalai Lama's office last year had been compromised.
"The nature of the data stolen by the attackers does indicate correlations with the strategic interests of the Chinese state. But we were unable to determine any direct connection between these attackers and elements of the Chinese state," wrote Villeneuve.
"However, it would not be implausible to suggest that the stolen data may have ended up in the possession of some entity of the Chinese government."
The new attack network bears several similarities to the GhostNet system uncovered by the same team of researchers about a year ago which heavily implicated China in cyber snooping activities.
The Chinese government is reported to have issued a stock denial of any such activities, claiming that they had been "stirred up" to cause trouble.
"We resolutely oppose all forms of cyber crime including hacking," China foreign ministry spokeswoman Jiang Yu is reported to have told a press conference.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
A client, a major financial services organisation, is...
Sharepoint Administrator, Sharepoint 2010, Sharepoint...
Proteus Europe, operating as an employment business...
Salesforce.com Senior Consultants and Leads Salesforce...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
China implicated in another major hacking attack
This is not the first time when china is attacking on Important Network sites of various of countries such as Canada and India .Chinese hackers are prompting by their Government. Although it is not the first and last time but it is now time to show a united protest against t China because they are trying to Hack GOOGLE Network now they are coming punishable.
Posted by: Robbin Smith 21 Apr 2010
China state-sponsored hacking
Anyone who was born and raised in China knows, of course, this is a state-sponsored hacking. This is a culture of Chinese government.
Posted by: Noone 20 Apr 2010
Great Firewall of China
With the way things are going between China and the rest of the world, perhaps we need to consider creating our own Great Firewall of China to protect the rest of the world! Seriously though, it is becoming clear that state funded hackers have the ability to compromise just about any system. It makes me wonder though, how much of the supposedly secure systems on the internet have been compromised by Western Governments with better knowledge and tools at their service? Or are we perhaps just being informed of hacks that the governments want us to hear about?
Posted by: BigT 07 Apr 2010