Google Search

Showing posts with label Chinese. Show all posts
Showing posts with label Chinese. Show all posts

Sunday, August 18, 2013

Chinese Hacking Suspects 'Back In Business'

A group of Chinese hackers suspected of being behind a cyber attack on the New York Times earlier this year may be restarting its campaign.

BAE Systems, the defence contractor, says it has unearthed evidence that indicates the group is active for the first time since February, when the hackers were accused of being linked to a Chinese military unit in Shanghai .

Although the connection has not been proven, the hacking group went immediately quiet on the day the allegation was made. Now analysts believe the hackers are ready to strike again.

David Garfield, managing director of cyber security at Detica, a BAE Systems subsidiary, told Sky News: "The activity we have detected indicates that the espionage group was lying low until the attention around their activities died down, before getting back to 'business-as-usual'.

"Detica researchers have obtained a copy of malware that has all the hallmarks of being crafted by this espionage group.

"This malware was created in the last week and contains a PDF which contains the agenda of an upcoming US defence conference which is consistent with the mode of operation of these particular attackers.

"The conference, taking place at the end of this month, fits with the style of event which is commonly used as a 'lure' for this group, and others of its kind."

For four months, towards the end of 2012 and into early 2013, hackers repeatedly infiltrated the New York Times, obtaining staff passwords among other things.

Security consultants found that some of the attacks were being routed through US universities to divert the blame away from the source, a method commonly associated with Chinese hackers.

The newspaper said the attacks were probably motivated by work reporters had been carrying out concerning senior figures in the Chinese government.

In February the American computer security company Mandiant published several years of research which it claimed pinpointed the hacking to one building in the Pudong district of Shanghai.

The building was reportedly the headquarters of the People's Liberation Army Unit 61398.

Mandiant represents the cyber-security interests of several major multinational companies, all of whom believe they are the victims of Chinese hackers.

On Monday, the Chinese army's chief of the general staff, General Fang Fenghui, was asked about cyber security at a rare news conference with the visiting US chairman of the joint chiefs of staff, General Martin Dempsey.

General Fang issued an alarming warning on the dangers of hacking.

"Cybersecurity, if it is uncontrolled, the effects can be, and I don't exaggerate, at times no less than a nuclear bomb," he said.

General Fang also reiterated a longstanding Chinese government assertion that China is also a victim of cyber attacks and that it is "strongly against any kind of cyber attacks".

China is not the only country connected with cyber attacks - the US, Russia, Israel and Iran are all suspected of developing cyber weapons. Most Western countries are believed to be doing the same.

Both BAE Systems Detica and Mandiant have commercial interests in highlighting the dangers of cyber crime.

The Chinese government has not responded to the latest allegations.

:: The Syrian Electronic Army has made an uncorroborated claim that it hacked the Twitter feed of the Associated Press news organisation. On Tuesday, the AP feed falsely stated that an attack on the White House had left the US president injured.

:: Australian police have arrested the self-proclaimed leader of non-state global hacking group LulzSec, which its members have said was responsible for breaching the CIA's external website.


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here

Sunday, March 4, 2012

Chinese hackers took over NASA's Jet Propulsion Lab, Inspector General reveals

Chinese hackers gained control over NASA’s Jet Propulsion Laboratory (JPL) in November, which could have allowed them delete sensitive files, add user accounts to mission-critical systems, upload hacking tools, and more -- all at a central repository of U.S. space technology, according to a report released Wednesday afternoon by the Office of the Inspector General.

That report revealed scant details of an ongoing investigation into the incident against the Pasadena, Calif., lab, noting only that cyberattacks against the JPL involved Chinese-based Internet Protocol (IP) addresses. 

Paul K. Martin, NASA's inspector general, put his conclusions bluntly.

"The attackers had full functional control over these networks," he wrote.

JPL is a jewel in NASA's space technology crown.

Beyond a wealth of exploration programs, such as the recent GRAIL mission to study the moon and the upcoming Mars Science Laboratory, JPL manages the Deep Space Network, a network of antenna complexes on several continents that monitors both outer space and planet Earth.

Martin released written testimony about the attacks in the report "NASA Cybersecurity:  An Examination of the Agency’s Information Security," presented to the House Science, Space and Technology Committee investigations panel on Wednesday. It details a host of security lapses and breaches of protocol at the space agency.

"In 2010 and 2011, NASA reported 5,408 computer security incidents that resulted in the installation of malicious software on or unauthorized access to its systems," his report states. "These incidents spanned a wide continuum from individuals testing their skill to break into NASA systems, to well-organized criminal enterprises hacking for profit."

Other incidents "may have been sponsored by foreign intelligence services seeking to further their countries’ objectives,” he noted.

NASA offered a statement to FoxNews.com saying that there was never a threat to the International Space Station, but did not specifically address whether there was a threat to the Jet Propulsion Laboratory. 

"NASA has made significant progress to better protect the agency's IT systems and is in the process of implementing the recommendations made by the NASA Inspector General in this area," Michael Cabbage, NASA spokesman said. 

The office of the Inspector General declined to offer further details, telling FoxNews.com it could not comment on the ongoing investigation. A spokesman for the Jet Propulsion Laboratory did not respond to requests for more details about the incident.

It's not known how the number and scope of computer security breaches at NASA compare to other federal agencies because NASA's Office of the Inspector General is the only OIG that regularly conducts international network intrusion cases, Discovery News reported Thursday.

In another successful attack against a NASA agency detailed in the OIG report, intruders stole a laptop computer that contained algorithms used to command and control the International Space Station (ISS), detailed by Discovery News.

"Some of these intrusions have affected thousands of NASA computers, caused significant disruption to mission operations, and resulted in the theft of export-controlled and otherwise sensitive data, with an estimated cost to NASA of more than $7 million," Martin wrote.

NASA said it is aware of the problem and taking steps to improve its computer security programs.

"The NASA IT Security program is transforming and maturing," the agency's chief information officer Linda Cureton said in her written testimony to the same panel.

"NASA is increasing visibility and responsiveness through enhanced information security monitoring of NASA's systems across the agency," she said.


View the original article here

Wednesday, November 23, 2011

Chinese hackers took control of NASA satellite for 11 minutes - Geek.com

Chinese hackers took control of NASA satellite for 11 minutes | Geek.com .wp-polls .pollbar {margin: 1px;font-size: 6px;line-height: 8px;height: 8px;background-image: url('http://www.geek.com/wp-content/plugins/wp-polls/images/default/pollbg.gif');border: 1px solid #c8c8c8;}  HomeGeek.com Home AppleApple Reviews GadgetsGadget Reviews MobileMobile Phone Reviews GamesVideo Game Reviews ChipsComputer Processors Technology ForumsForumsTechnology Forums Technology ShopShopTechnology Shop Tech Support Chips Apple Mobile Games Gadgets Software The Lounge Geek.com Stuff Cameras Cell Phones Computers Electronics Laptops Memory Monitors PDAs Software Storage Devices Video Games All Products Search: All Articles Products Glossary Forums Username: Password: Cancel Forgot Username / Password? Back to Geek-Cetera Print Chinese hackers took control of NASA satellite for 11 minutes Nov. 19, 2011 (11:05 am) By: Matthew Humphries


Landsat-7 and Terra EOS satellites

Hacking is becoming a growing problem on Earth. It may seem strange to mention Earth, as there’s not much to hack outside of our planet’s atmosphere unless you count satellites. Even then, how feasible would it be to gain access to the systems running such devices?

Well, China not only has people working on such things, it has been discovered they actually managed to take control of two NASA satellites for more than 11 minutes.

The successful attacks occurred in 2007 and 2008. The more serious of the two happened in ’08 when NASA had control of the Terra EOS earth observation system satellite disrupted for 2 minutes in June, and then a further 9 minutes in October. During that time, whoever took control had full access to the satellites’ systems, but chose to do nothing with it.

The second hack affected the Landsat-7 satellite on two occasions, one in October of ’07, the other in July of ’08. Unlike the Terra OS incident, this hack did not see control taken away, but access was gained.


Washington D.C. captured by Landsat-7 in 2005

We only know about these hacks because of a report becoming available this month. It is entitled the 2011 Report to Congress of the U.S.-China Economic and Security Review Commission and made available online at the USCC website (link below). The specific details can be found on page 216 of the document, which is actually page 224 of the PDF.

It is suggested such malicious cyber activity in relation to satellites can be carried out to either destroy the system rendering it useless, or to exploit it to see what the “enemy” sees and gain intelligence on “ground-based infrastructure.”

Interestingly, the report points to the use of ground stations outside of the U.S. to control satellites as weak points. The reason being they use the Internet for data access and communication, not a closed link. We don’t know if that is still the case, but we’d hope not, or at least hope that the communication link is using better encryption and security checks.

Read the report online at the USCC website (PDF), via ITWorld

Tags: 2007, 2008, 2011 Report to Congress of the U.S.-China Economic and Security Review Commission, China, control, hack, hacking, internet, Landsat-7, NASA, satellite, Terra EOS DiggDigg redditReddit FacebookFacebook StumbleUponStumble TwitterTwitter Email To Email Address:
To Name:
Your Name:
Your Email Address

Popular Geek Pick Articles Chinese hackers took control of NASA satellite for 11 minutes Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus Analyst predicts Amazon smartphone in 2012 Kindle Fire hacked to access Android Market Google and Facebook, it’s time to take the kid gloves off about SOPA Geek Pick Archives November 2011October 2011September 2011August 2011July 2011June 2011May 2011April 2011March 2011February 2011January 2011December 2010November 2010October 2010September 2010August 2010July 2010June 2010 Search: All Articles Products Glossary Forums Previous
World’s first Galaxy Nexus owner finds developer ROM on his phone
Is George Clooney being considered for the role of Steve Jobs?
Kindle Fire hacked to access Android Market
Google’s Nyan cat obsession spills onto Google+
Analyst predicts Amazon smartphone in 2012
Google Music exits beta, Music Store coming to Android Market
Google and Facebook, it’s time to take the kid gloves off about SOPA
Chinese hackers took control of NASA satellite for 11 minutes
FXI Cotton Candy is an ARM PC in a USB stick
Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus Next Recent Geek Pick Activity Popular Article CommentsForum Talk artyiom

there are many ideas a man can think but if he thinks it twice he thought about another idea which makes his idea non...

Posted In: Geek.com Stuff Read More » ExpertOnCoolers

The break in the case came when investigators focused on a grainy surveillance video that showed the boy, wearing his...

Posted In: Geek.com Stuff Read More » davidross

One of the most attracting features of Mac OSX Lion is auto save for documents. And Autosave would not save the modi...

Posted In: Apple Read More » View All Forum Talk » Prachi Desai

I am a big fab of Windows. Windows 8 Developer Edition is now available for download, I have installed it on PC. I must ...

Posted In: Download a preview build of Windows 8 tonight Prachi Desai

I am a big fab of Windows. Windows 8 Developer Edition is now available for download, I have installed it on PC. I must ...

Posted In: Download a preview build of Windows 8 tonight Georgecarlinjr

Apparently that also takes away the neat new task manager and explorer, which is a shame.Of course you can have the bes...

Posted In: How to get a Windows 7 start menu in Windows 8 Chinese hackers took control of NASA satellite for 11 minutes

Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus

Analyst predicts Amazon smartphone in 2012

Kindle Fire hacked to access Android Market

Google and Facebook, it’s time to take the kid gloves off about SOPA

.contentBox { clear: both; } @import url(http://www.geek.com/wp-content/themes/geek5a/styles/price-grabber.css); Geek Shop Categories Cameras Cell Phones Computers Electronics Laptops Memory Monitors PDAs Software Storage Devices Video Games All Products Geek.com Buyer's Guides Desktop Computer Buyer's GuideDigital Camera Buyer's GuideHDTV Buyer's GuideLaptop Buyer's GuideNetbook Buyer's GuideSmartphone Buyer's Guide Geek Feeds Geek Feeds Apple Gadgets Mobile Games Chips More Geek Goes Social Geek on Facebook Geek on Youtube Geek on Twitter Geek.com Archives This Month Last Month All Archives Reviews Newsletters Features Glossary © 1996-2011 Ziff Davis, Inc. AdChoices (function(){var e=document,b,a=(e.location.protocol=="https:"?"https":"http"),c=(a=="https"?"https://info.betteradvertising.com/c/betrad/pub/":"http://cdn.betrad.com/pub/");e.getElementById("_bapw-icon").src=c+"icon1.png";e.getElementById("_bapw-link").onclick=function(){var f=this;function d(i,l){var j=e.getElementsByTagName("head")[0]||e.documentElement,h=false,g=e.createElement("script");function k(){g.onload=g.onreadystatechange=null;j.removeChild(g);l()}g.src=i;g.onreadystatechange=function(){if(!h&&(this.readyState=="loaded"||this.readyState=="complete")){h=true;k()}};g.onload=k;j.insertBefore(g,j.firstChild)}this.onclick="return false";d(a+"://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js",function(){d(c+"pub1.js",function(){BAPW.i(f,{pid:8,ocid:660},false)})});return false};b=e.createElement("img");b.src=a+"://l.betrad.com/pub/p.gif?pid=8&ocid=660&ii=1&r="+Math.random();b.height="1";b.width="1";e.body.appendChild(b)}()); About Contact Us Advertise Posting Guidelines Privacy Statement Terms of Use Glossary document.write(unescape("%3Cscript src='" + (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js' %3E%3C/script%3E")); COMSCORE.beacon({ c1:2, c2:6035546, c3:"", c4:"", c5:"", c6:"", c15:"" });

View the original article here