Vast Electronic Spying Operation Discovered
homesalad writes "Researchers in Toronto have discovered a huge international electronic spying operation that they are calling 'GhostNet.' So far it has infiltrated government and corporate offices in 103 countries, including the office of the Dalai Lama (who originally went to the researchers for help analyzing a suspected infiltration). The operation appears to be based in China, and the information gained has been used to interfere with the actions of the Dalai Lama and to thwart individuals seeking to help Tibetan exiles. The researchers found no evidence of infiltration of US government computers, although machines at the Indian embassy were compromised. Here is the researchers' summary; a full report, 'Tracking "GhostNet": Investigating a Cyber Espionage Network' will be issued this weekend." A separate academic group in the UK that helped with the research is issuing its own report, expected to be available on March 29. Here is the abstract. They seem to be putting more stress on the "social malware" nature of the attack and ways to mitigate such techniques.
gay nigger association of america
eat my asshole you dirty chinks
The U.S. and other governments have been doing things like this for years...
the abstract mentions that the attack was done using malwares. Firstly, I expected Chinese hackers (read govt.) smarter than this. Secondly, almost every government that allows internet reach its people have some some kind of surveillance and spy network in place. And its getting pretty obvious from the new laws that we are seeing popping up in various countries these days.
Eclipse PDE and Me
Unless I missed it, I don't see Windows mentioned...but I'm going to go out on a limb here and figure the targeted OS is Windows.
Transporter_ii
Doctors destroy health, lawyers destroy justice, universities destroy knowledge, religion destroys spirituality
*in Japanese* The fact that you didn't make me Sulu shows remarkable racial sensitivity.
*holding eyes at a slant* I'm Sulu!
*in Japanese* Laugh now, the next century belongs to us.
It seems pretty obvious that we're going to end up in an economic war with China. Some little official is going to do something stupid and then we're going to have to bitch-slap them.
If you freeze Chinese assets in US banks, deny them access to telecom links, port and air landing rights, etc., China would be bankrupted in about a year. And whoever replaced the Communist party would have better manners.
Im wondering how many posts here are submitted on behalf of the Chinese Government?
They can join and influence our conversations but we can never join theirs..
Sanctions against China are way overdue. Our gov't and big businesses are just feeding that monster.
Caveat Utilitor
I would guess that the Russian crooks are doing it today with very targeted attacks. We just have not discovered it, or if discovered the financial institutions attacked have covered it up.
products. Why try and trick someone into installing malware when Microsoft sells the latest version of Windows with built in backdoors for our governments to spy on us.
More likely the operation is run out of the office of the world's most dangerous person.
I hope this helps the Chinese authorities.
Yours In Communism,
Kilgore Trout
zdnet
neowin
Is infrastructure in place to punish those responsible for such invasions?
What could the affected countries do against China to discourage them from doing this again? I don't think its act-of-war level but I think its at least sue-for-billions-and-billions-and-billions worthy.
Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
Very, very niave.
"GhostNet" What a wacky idea.
ALL HAIL THE HYPNOTOAD!
It must have been something you assimilated. . . .
"They said they had found no evidence that United States government offices had been infiltrated."
That kind of tells you something, doesn't it. It's made to look like it's from China but it's really from the US. :)
The Dalai Lama has (or needs) an office? WTF?
Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
That isn't how treasury bonds work. There is no "call in debt" they are Bonds that are not instantly redeemable. Ten Year Bonds gets paid off in Ten years etc.
All they can do is attempt to sell all their bonds on the open market and destroy their value. In that case they cut off their onw nose to spite themselves.
It is definitely not only China that employs some monitoring techniques on its citizens' Skype accounts. Last year during Myanmar's Saffron Revolution, my Burmese roommate organized information sessions and candle light vigils on our small, liberal arts school's campus, taking care to remain anonymous or using my name as a proxy for his actions. The only Burmese contact he had at the time was Skyping with his ex-girlfriend, a student at a nearby liberal arts school who organized protests of greater scope on her campus. After about 3 days he mysteriously received a call from his mother who sounded scared (remember, most non-satellite phone lines were all but taken down during the protests) assuring him that she was OK but he needed to stop everything he was planning on campus. My roommate had no choice but to stop his involvement in the protests.
In case they try to compromise the Intersect.
I don't believe in time. It's a grand conspiracy designed to sell watches.
You made sure your tinfoil hat is shiny-side out, right? That's the only way to make it effective.
on spying on the rest of the world? Does "ECHELON" ring a bell?
You're not the least bit worried about the monster closer to home, thrashing around in your own back yard? I'd say "sanctions" against our own monster(s) is way overdue....
Perhaps, next time, you might not want to impose sanctions on the government that holds by far the largest share of the US debt:
http://en.wikipedia.org/wiki/File:Foreign_Holders_of_United_States_Treasury_Securities-percent_share.gif
You impose sanctions, they call in that debt. And who else do you really think is going to loan you the money to pay that back?
The US/China relationship is not as much of a black-and-white situation as nationalistic extremists both in the USA and China would like it to be. If the Chinese 'call in' all of that debt at once in some way, shape or form, there is no way the USA could pay up. Effectively the US would have to default, i.e. welch on the debt. That would wipe out an awful lot of hard earned Chinese wealth. Some of the noises coming out of Beijing lately only confirm that the Chinese are getting nervous even at the mere suggestion of the possibility of a US default. Another thing to consider is that the Chinese are very dependent on exports to the USA and it's NATO allies who are likely to eventually follow the USA's lead, however grudgingly, in any major conflict of any kind with China. If the Chinese were to 'call in' this debt it would be self defeating exercise, as likely to harm the Chinese them selves as much as it would harm the USA. The economies of these countries are very intertwined.
Only to idiots, are orders laws.
-- Henning von Tresckow
Does anyone have a backup for http://www.infowar-monitor.net/modules.php?op=modload&name=News&file=article&sid=2176&mode=thread&order=0&thold=0 in TFA?
Why is it that companies allow the bad guys to p0wn their computers? Sure windows is a pile of horse-crap but it's possible to implement good firewalls and application proxies and to run the proper applications on proper OS's.
Perhaps if we get rid of all the 'professional manager' types and fake idiots types in IT things will improve.
I wonder how much Microsoft's Malicious Software reporting tool would be to help in targeting specific systems?
See: http://www.infoworld.com/article/08/04/29/Microsoft-botnet-hunting-tool-helps-bust-hackers_1.html
Someone care to expand on the above??? I've googled some but came up with nothing so far.
Doctors destroy health, lawyers destroy justice, universities destroy knowledge, religion destroys spirituality
Google Titan Rain, unlike some previous posters statement to search Assassins Mace or something similar that only shows mostly tinfoil hat type sites, TR is/was a real known threat, that may or may not have effected US gov systems and Commercial entities.... that is all I will say as that information is already known publicly....
:...has infiltrated at least 1,295 computers in 103 countries"
That doesn't seem really vast...to be honest I've seen small botnets that are bigger.
i especially like the reference to the cuban mariel boatlift at the end there. emphasis: CUBAN. china's going to send 60 million refugees to the usa? really? on what? airplanes? rafts? pffffffffft
all the indignation about "buy american" and chinese labor conditions is exactly that: empty indignation. when it comes down to actually buying the crap you need, you go to walmart, and buy the cheapest stuff. end of story
oh sure, there's people with enough disposable income and reams of time to actually go out of their way to buy harder to find, more expensive stuff. i salute all 10 of you. as for the other 300 million of you who will give lipservice to a "cause" while you go on buying you crap at walmart, i see only one thing: reality
and you talk about tariffs. even more retarded efforts on your part. lets make lots of stuff more expensive for vague geopolitical goals of doubtful impact. yeah, you have a lot of support from the average joe who now has to spend much more of his scant income in order to do that. protectionism just makes us poorer, and the chinese poorer. and speaking of tits and weaning, the chinese atuocracy was weaned on the tit of poverty and suffering. so by making eveyrone poorer, you've just tightened the autocrats grasp in china, and also moved US closer to autocracy. you're a fucking genius
china makes the cheapest stuff. therefore we will buy it. therefore, we need ANOTHER WAY TO CHANGE CHINA. understand? you're feeble graps of pulling the strings on international trade is not the way
the big problem here is not that i don't share the noble goals of those who wish to defeat chinese autocracy, chinese autocracy is evil and needs to be defeated. my problem is with the cottonheaded idotic ways people think you go about doing this. buying more expensive stuff IS NOT THE WAY
so, how do you defeat the autocrats? you continue buying their cheap stuff, they get rich, then they clamor for change in their own country. how does chinese autocracy end? with a rich china. furthermore, with a rich china, guess what? the price differential for making stuff in the usa versus china simply disappears, putting american manufacturing back into competitiveness, especially since you don't have to put it on a supertanker to get it here
the whole philosopphical schizm between you and i is that you think you change someone else by denying them something. meanwhile, i change them by giving them something. my way is superior, your way gets nowhere
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
i just love the way people poopoo american foreign policy and big business
as they gas up their SUVs
and go shop at walmart
the problem is not big business
the problem is not the american government
nothing but empty cruft compared to the real problem: the behavior of the american consumer
you convince them to spend $10 a gallon on gas, you convince them to buiy their crap at 2x the price. go for it
stop blaming esoteric entities when the real problem is sitting right there, in front your computer, reading this post
YOU AND YOUR OWN BEHAVIOR
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
look! a chinese american! part of the "gossamer net" of unwitting spies!
and you got modded up?
well then we have now identified one potent weapon against the "gossamer net": the american flypaper of xenophobic retards
or maybe i'm being unfair, maybe you were modded up for your eloquent, flowery language
strangely reminescent of a qing dynasty poem!
hmmmm
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
eh eh, this is so small. this is so small. tiny. really can't blame the chinese for anything, we should actually give them a helping hand instead. americans have their spyware in some 90% of worlds desktop computers, NSAKEYs awaiting.
run thru Tor
In Canada, if a message is secret and urgent, Tor is used to get it close to the destination. Then it is printed in code and sent on its final leg strapped to a Husky.
In other words (ahem): Canadians send secret Rush messages By Tor and The Snow Dog .
Isn't the hub parked at Bill Gates' house?
The only Burmese contact he had at the time was Skyping with his ex-girlfriend, a student at a nearby liberal arts school who organized protests of greater scope on her campus
Did it occur to you that maybe, just maybe, your roommate was sold out by his "burmese contact"? Skype sniffers can't tell the Burmese government that the other person was the ex-girlfriend of a...I don't know what the fuck is going on in that set of connections, but dude, it's far more likely the guy in Burma is on the take...or someone in his apartment is.
Or maybe you all wildly misinterpreted his mother's "don't make waves" urgings.
Please help metamoderate.
It turns out there really is a vast global conspiracy.
Protip: Don't be a sucker like your neighbors. Sure they look great but it is unnecessary to wear fancy headgear to avoid the reds mindcontrol beams. Tinfoil works just fine!
Large print giveth, and the small print taketh away
Whatever.
The eternal struggle of good vs. evil begins within one's self.
there are a few things we don't yet know.
It might be us who ran that spy net. It could also be the chinese, the russians or even the pakistanis.
They're using their grammar skills there.
How can you be sure your computer is 100% secure, and not infiltrated? Even in a fresh-installed, never-connected OS (any OS), how to be sure all executables on the CD don't have some hidden code in them, even when first released, that was somehow slipped in? What OS do they use in embassies, military, etc? What security measures, products, procedures?
Build your own energy sources from scratch. http://otherpower.com/
so solly! please to be folgiving, i not know insclutable asian palt of mindless botnet!
"The bulk of Chinese intel is heavily distributed. The world's largest families don't need to rely on 007 agents; they can aggregate huge quantities of data by getting observant volunteers from the chinese diaspora to send bits of info back home through regular channels, like aunt Ping or even uncle James. It's so distributed it doesn't look like spying, and it isn't really, in the traditional sense."
please, educate little knee jerk foolish me. describe how this works exactly
this is what it sounds like right now: so we have chinese americans. and they are doing what exactly? they hear bits and pieces. a guy walks by them on the street and they overhear a bit of conversation? then the next chinese person, he sees parts of a file on a disk drive. and these peopple "unwittingly" do this through... family gatherings? what are they, robots? oh right, they ARE: "I think it's brilliant, even if wholly dependent on the chinese sense of family ties. A malware attack is a similar approach: it doesn't look like the work of spies, at first, and it's broadly distributed."
so chinese americans, you know, they go the laundromat or the chinese restaurant, as they all do, right? and there they consort and whisper all their gems of intel, and through "aunt ping", pass the info back to the mothership, i mean, er, the chinese communist party, since all asian people are obedient ant-like slaves to the old country, right? do i understand your genius grasp on the secret truth of the world i deny out of my liberal bleeding heart yet?
please! tell me where i am wrong in that description, i await my enlightenment
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Then set up another more secure network, but keep using the compromised version to disseminate false notices, making the Chinese Gov't respond to false information...
Once I was a four stone apology. Now I am two separate gorillas.
China not only has their money fixed against the dollar, but they also have trade barriers against imports. Now, they are fighting to continue to pollute at will, while the west is cracked down. It seems to me that if the west is smart, they will skip the cap/trade and instead do a VAT on ALL GOODS (local made for local sell and imported for local sell ) BASED ON POLLUTION esp CO2.
I prefer the "u" in honour as it seems to be missing these days.
Governments need to WAKE THE HELL UP and start enforcing policies against certain kinds of uses of government computer systems. And yes, it would be nice if the systems were loaded with "dedicated functions" without the ability to do anything more than that which is needed to do their jobs. But that's not how Windows works is it?
Some serious actions against China should be taken, but then again, those same actions should be taken against the U.S. as you can bet the U.S. is guilty of the same if not worse behavior with all the crap the NSA and CIA have been doing.
This is all easily remedied. 1. No government system with anything even vaguely sensitive let alone classified is allowed anything but heavily secured access routed through random proxies (so you can't see .gov whatever for source IP), no-admin/no-root systems, and heavily micro-managed/monitored systems.
2. All VOIP or communications systems come with high-level encryption on only open-source systems, with no government backdoors.
Dude, where's my packet?
> High-sounding but irrelevant verbiage having no bearing on the facts. I mean, how grandiose you are in dismissing one simple fact: working our manufacturing economy was how Americans managed to have a standard of living envied by most of the world. How do you think wealth is created? By magic? Hardly: it's by building and selling things to other countries, it's called trade.
So, let me get this straight. We have a huge trade deficit. This means that we're exporting American dollars and importing lots of foreign products. You're telling me we're screwed because those dollars aren't really worth anything, not being real wealth.
But we're getting rid of those and getting real, physical goods for that money.
Please explain to me one more time how we're getting the short end of the stick in that arrangement? If things go belly-up, we still have all those goods that we bought. What makes you say that an industrial superpower is the only kind?
> Suppose we took your idea to its logical conclusion, and ended up with an entirely automated production system with no need for people at all. We'd all be unemployed at that point. No thanks.
Would anyone NEED to be employed at that point, if robots could take care of everything?
from tfa: the spokesman, Wenqi Gao, said. "The Chinese government is opposed to and strictly forbids any cybercrime."
yup -- just like the Pakistan government is opposed to and strictly forbids terrorism...
do you get a paycheck for everytime you mention that lamoid website?
please to be folgiving, i not know insclutable asian palt of mindless botnet!
your post is racist nonsense, regardless of your intent
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
In what kind of age do you live ? It's 2009, where AI is still in it's babysteps...
By then we don't have robots to deal with, but grey goo ;)
--- I am known for the ones who want to find me on the net. Is that a privacy risk or a privilege? One might wonder..
I would guess you are. We only didn't find out so far. And if so, you would have bribed the discoverer.
See where your "logic" leads? Totally worthless.
As near as I can tell from the Markoff article, the infiltration was made possible by run-of-the-mill phishing attacks. (Markoff says it's called "whaling" when it's directed at specific high-level targets. I've never heard of that, and don't really see any substantive difference.)
If so, then technically speaking there's probably nothing really new here. What seems interesting to me is:
- Obviously, the vast scale, the sensitivity of the targets, and the potential political impact.
- The operation has not been publicly revealed by government agencies (FBI sez "no comment"), but rather by Nart Villeneuve et al. at the University of Toronto.
- Phishing is evidently effective enough to make widespread infiltration like this possible. Sure, there are more sophisticated things that attackers could do, and of course most users should know better than to blindly click links in their email. But here we are, phished to death all over the world. Why should an attacker go to any more trouble?
I wonder how much security improvement would be gained if Thunderbird & Outlook disabled the automatic opening of a browser when you click on a link in email, and made us go back to the old days of copying & pasting links. Would users be more careful if they could more easily see what they're doing?
Always keep a sapphire in your mind
In exchange for your $10, you've made a whole series of people $2 richer, and you now own a book presumably worth $10 to you. That $10 just became $20 of national wealth, by the "magic" of economics.
Thinking like this is what has gotten this country is such a mess. Your math is screwed.
For one thing your book is worth $10 not because you think it is worth $10 but the people buying think it is worth $10.
OK you sell it for 10 but do you make 10? No. You have overhead. Your book on your P&L statement is only worth the $2 profit you made. To the printer you book is only worth the $2 profit he makes and so forth. There is no magic here. 6+2+2=10
Just because someone sent you $10 for your book doesn't mean you can spend the whole $10 as profit. You have fucking bills to pay. You are right in the sense that this is banking and business today yes this is why things are sooo fucked up. Banks got your $10 in the coffers and loaned out $20 on it to other people that put down $10 profit on their P&L statement when it fact they only made $2. So now comes the time you must pay back the 10 but you only have 2 to pay to the bank because the 8 was only a fantasy you had to pay it out for overhead. So you default on the $10 loan. Lets say you paid the $2 the bank is still out $8. Now what about the other phantom $10 made by magic? Well the bank loaned it to another person that doctored his P&L statement and he defaults so now the bank is down $16 when in the beginning it only had $10 to start with.
You get $10.. you shell out $8 to print.. 10-8=2
Sorry there is no magic. There is no goose that lays golden eggs.
I found the general analysis of the attack to be accurate however there were a few issues:
- They tried to coin a new phrase of "social phishing". The phrase "spear phishing" is already in use in the security world for these kinds of attacks.
- Their recommendations on how to mitigate these attacks fall FAR short of what it actually takes to defend. These attacks are very difficult to defend against using commercial products with commercial signatures. They are all custom crafted to avoid detection. You have to develop custom detection schemes today to catch most of it.
If I'm not mistaken his President 'boss' hit his two-term limit and the both of them left office on January 20th. Of course Mr Cheney is still on TV touting who knows what BS. Perhaps he can be the next Sham-Wow pitch man.
what information is gleaned?
i overhear a bit of a conversation? i see a file? what the hell can be gleaned from random exposure to bits of detritus?
either you are a spy with a target and a purpose, or you are what, exactly?
i'd like to be more diplomatic, but i have to be honest: you are of low intelligence and highly xenophobic. i have not yet been described a coherent threat to american national security from random chinese people doing random things. nor do i see how there could be
i mean, you couldn't even describe to me an entertaining b-grade hollywood movie from this fantasy life of yours. how does it work, you read them a robert frost poem?
http://en.wikipedia.org/wiki/Telefon
jesus christ, people believe the most severely retarded things
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Would the Chinese agents be covered by diplomatic immunity for breaking US Laws? I think not, and last time I checked, it was illegal to gain unwarranted access to a communications device (email in this case) under US Federal Law without a US issued court order. As the server is based in California, it does indeed fall under US law. The good thing about it being a Federal offence is that it gets looked after by the Feds who can actually do something about international suspects.
So how do you go about putting members of a foreign government department in to INTERPOL?
Dan. -- So what if it's spelt wrong, nobody's perfect
although i can see how in a demented mind that can only view it through the lens of racism, that if i argue against religious extremism, whether christian, jewish, or muslim, that this makes me somehow anti-arab
you're a simple idiot. you can only see the world in simple stupid ways. you can only process my words according to your retarded proclivities
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
Obviously a story planted by the CIA to further demonize the Chinese government. Why, you ask ... here are a few obvious reasons that come screaming out of the page.
1. Of all the thousands of offices and business's affected by the "worm" it was the good ole CIA's number one buddy the Dali lama and his office employees that alert the security firm to a possible incursion happening ... Total nonsense.
2. With such a sophisticated worm being created the Chinese didn't have the where with all to hide the fact that it was all originating from Chinese servers ... Total nonsense.
3. No American servers were affected. The Chinese apparently are foiled when it comes to infiltrating any American servers ... Total nonsense.