Chinese Hackers Launch Zero-Day Malware At Spiritual Activists, Military Groups
twoheadedboy writes "A Chinese hacker group is the chief suspect of spear phishing attacks against the Falun Dafa spiritual group and military organizations in the Philippines. Data handed to TechWeek by AlienVault Labs showed how zero-day malware, designed to pilfer Outlook email account logins, was just one strand of the attacks, which are ongoing. Other malware sought to steal passwords for other accounts, dodging many commercial AV products, whilst remote access tools indicate this is a serious surveillance operation. Chinese authorities have neither confirmed nor denied the claims. But it marks another case of Internet-led surveillance with China's name attached to it, following numerous reports of mass Chinese hacking, which has already allegedly hit massive firms like Facebook and Google."
More like Daffy Duck.
How are the Chinese doing this? Snowden hasn't said a word about Chinese espionage programs that I recall.
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
Unless your business has a legitimate need to accept traffic from China or Russia, wouldn't it be possible, perhaps prudent even, to block any traffic to and from those countries?
Don't tailgate - the end is near!
This seems consistent with the Mandiant report, at least the Spear Phishing attacks and maybe the tools?
Or is it back to the regularly scheduled China bashing? It seems the typical Western hypocrisy didn't take long to return, and you guys are even worse; you hack and monitor even your staunch allies.
In US: Use metadata to find suspects, request a secret warrant from a secret court (with a history of granting 100% of warrant requests) to find additional information.
following numerous reports of mass Chinese hacking, which has already allegedly hit massive firms like Facebook and Google.
Following a report that US surveillance consists of massive firms like Facebook and Google.
Posting anonymously, because I often fly internationally, am already easily profiled, and do not want to increase my risk of showing up on a secret TSA hassle list.
Say what you will about Chinese government & private sector computer crime, at least they're not reading my email and logging all my net traffic.
insistEd that the fruitless
The targets alone prove that this was the work of the Chinese because there's no money to be made in attacking either of these groups. The criminals are in it for the money and they wouldn't waste zero days on military groups in the Philippines or some offshoot of the Falun group of religious people. Furthermore, everybody knows that the Chinese government employs hackers, it's now documented public information, so there's no obvious political value in staging a false flag operation to make it look like it was the Chinese because that cat's already out of the bag. The only government on the entire planet that would perceive any value in attacking either of these groups is the Chinese government.
At a previous gig I was tasked with setting up a network with VPN endpoints in Shanghai, Noida, SF, and NYC. Within months I was consulting with my buddies that started their own security company because my doorknob was rattling off the hook mainly in the Shanghai region. The data being protected was a AAA game engine under heavy development, which I can say never got leaked unlike the one from our sister studio in the UK. The mass of massive hacking coming my way did seem to be chinese govt related (in this case rightfully so) because I can only describe it as a gigantor sized botnet with permanent PMS that seemed to disappear when you began investigating it. It was explained to me they have developed their own protocols which do not translate well to a western approximation of things. Constant attempts to poison DNS on our domain controller from seemingly 3g mobile network addresses in the region and a heavy use of whale-sized infiltration techniques were constant headaches. I could not just change the platform or OS too many 3rd party tools. I got no help from admins on their end when I asked why all this **** was on their network segment and why their BYOD policy was allowing it. My only saving grace was a machine put together from spare parts dedicated to taking the brunt of Shanghai attack attempts which had absolutely nothing on it but was set up to look like the machine that was the goal of all the attacks on the network. After a month or so it would mysteriously get knocked off the network whenever it was put up even after an OS reinstall when VPN was up. Luckily, it gave us enough time to get spinlocking RSA dongles in the mail which were all the rage back then. Found out later all this work was to protect some shady employment practices that became very public after I had left the company. The point of this very long tale which will most likely get buried is get both sides of the story. Justice is blind, even on the net, wherever these people are you have to ask yourself when it comes to a person's life or wellbeing these things may actually be necessary and it is not always to stem the tide of dissent. You can read the news but this is an actual in the trenches account- hope it helps and hope more people will share these experiences.
Instead of the normal crap you see on here deal with the dang problem if China is a problem then disconnect them from the internet you yanks say you own the dang thing do something instead of just wetting your panties ..
It makes perfect sense that Chinese groups are attacking the military of the Philippines since China is paving the way for aggression. China is trying to claim sovereignty over islands claimed by many of its neighbors. The age old quest by China to establish its hegemony continues.
Philippines Protests Renewed Chinese Pressure in South China Sea
China And The Biggest Territory Grab Since World War II
The Philippines and Japan want U.S. help in dealing with China’s aggression
Philippines upgrades military to end China "bullying" in S. China Sea
Japan Will Sell Ships To Philippines To Fight China’s “Bullying”
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
Why foreign organisations are using: 1) a closed-source OS developed by a foreign power 2) software with all these security flaws 3) a software defective by design
Unless they're moving against Christians, most of the western world doesn't care.
China has a thriving trade in sex slaves, protected by official corruption - bigger fish to fry.
How can malware be zero-day? If it's exploiting some security weakness, then it's a virus and not malware. If it's malware, then it's probably gotten itself installed (even if through nefarious means) via some social engineering technique. I suspect this is a stretched use of "zero-day" in order to make the headline & article more exciting.
the CHICOMS! filthy yellow hordes!
nukes will fry every chinese computer and all these wankers will be out of a job
deniability means that most of them will be shot by their own government one of these days
It's a stretch to claim that Falun Gong is a "spiritual practice." They're a cult on the same order as Reverend Moon's "Unification Church" or Lyndon Larouche's Larouche Youth Movement.
They have a TV station: http://en.wikipedia.org/wiki/New_Tang_Dynasty_Television a newspaper http://en.wikipedia.org/wiki/The_Epoch_Times a radio station: http://en.wikipedia.org/wiki/Sound_of_Hope and a performing dance troupe: http://en.wikipedia.org/wiki/Shen_Yun_Performing_Arts
Their leader, Li Hongzhi, claims to "not accorded special treatment, nor does he accept money or donations from students of Falun Dafa" http://www.stanford.edu/group/falun/eng/faq.htm but if you go to the Shen Yun website http://www.shenyunperformingarts.org/, you'll see on the front page prominently features an essay by Li Hongzhi in which he goes onto define "What is Classical Chinese Dance?" Like any cult leader, to his followers he is an expert in all things, man made or otherwise.
But don't take my word for it; do your own research. Take a look at Li Hongzhi's official biography, where he claims to have by age eight, acquired "the superb great law with supernatural powers." Or look into his statements about whether to seek normal medical treatment or to rely on his teachings. Or just go ask some practitioners how their "spiritual practice" funds itself and is able to support so many media outlets and lobbying efforts.