Chinese Hackers Launch Zero-Day Malware At Spiritual Activists, Military Groups
twoheadedboy writes "A Chinese hacker group is the chief suspect of spear phishing attacks against the Falun Dafa spiritual group and military organizations in the Philippines. Data handed to TechWeek by AlienVault Labs showed how zero-day malware, designed to pilfer Outlook email account logins, was just one strand of the attacks, which are ongoing. Other malware sought to steal passwords for other accounts, dodging many commercial AV products, whilst remote access tools indicate this is a serious surveillance operation. Chinese authorities have neither confirmed nor denied the claims. But it marks another case of Internet-led surveillance with China's name attached to it, following numerous reports of mass Chinese hacking, which has already allegedly hit massive firms like Facebook and Google."
Unless your business has a legitimate need to accept traffic from China or Russia, wouldn't it be possible, perhaps prudent even, to block any traffic to and from those countries?
Don't tailgate - the end is near!
This seems consistent with the Mandiant report, at least the Spear Phishing attacks and maybe the tools?
Snowden wasn't employed in a position where he had access to the Chinese espionage program. He was employed where he had access to the US programs. Maybe one day there will be a Chinese version of Snowden that will shine light on all the mischeif that the Chinese get up to...
Moved to http://soylentnews.org/. You are invited to join us too!
Probably because he hasn't worked for them (but plenty of people are more than happy to tell you it's widespread and unstoppable apart from giving the NSA another trillion dollars). Also i think i would prefer the Chinese having all my data than the US, because china is a lot less likely to use it against me (not hand it over to the mpaa to sue me or something). Of course if i was a billion dollar defence contractor working on top secret weapon designs for the US, or a Chinese citizen, i might have a different view point.
Rocket Surgeon.
In US: Use metadata to find suspects, request a secret warrant from a secret court (with a history of granting 100% of warrant requests) to find additional information.
following numerous reports of mass Chinese hacking, which has already allegedly hit massive firms like Facebook and Google.
Following a report that US surveillance consists of massive firms like Facebook and Google.
Posting anonymously, because I often fly internationally, am already easily profiled, and do not want to increase my risk of showing up on a secret TSA hassle list.
>and you guys are even worse; you hack and monitor even your staunch allies.
And you don't? Sorry, that's not really a question. We know you do.
You spout a lot about hypocrisy, but it appears you misunderstand the word, or perhaps the context. It would be hypocritical to say "Chinese Hackers Launch Zero-Day.. AND THAT'S A BAD THING WE'D NEVER DO", and then go ahead and do exactly the same. It's not in the slightest way hypocritical to say "Chinese Hackers Launch Zero Day" if they did. It's just reporting news. Just as the Chinese government media report anything bad they can possibly find to say about the west. Simply reporting news is NOT, in any way, hypocritical. It would only be hypocritical if it was to be reported, and then claimed that we don't do the same.
The irony here is, that by saying "you guys are even worse; you hack and monitor even your staunch allies" when you do exactly the same, you're the only person being hypocritical. You're saying the US is "worse" because it "monitors its allies", yet China does exactly the same. Cue, hypocrisy.
"The true measure of a person is how they act when they know they won't get caught." - DSRilk
No, China won't hand your information over to MPAA. They'll just imprison you indefinitely for speaking against the government.
From what I hear North Korea feels the "love" from China. So do most of the countries around China.
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
How exactly are they going to do that? Even if they managed to invade my country, finding me in that war zone wont be all that easy. But what the hell, lets find out what happens. CHINA GOVERNMENT EATS BABIES. How long do you think it's going to take to arrest me?
Rocket Surgeon.
As soon as you go through customs if you ever decide to go to China, Taiwan or Hong Kong for a holiday?
The targets alone prove that this was the work of the Chinese because there's no money to be made in attacking either of these groups. The criminals are in it for the money and they wouldn't waste zero days on military groups in the Philippines or some offshoot of the Falun group of religious people. Furthermore, everybody knows that the Chinese government employs hackers, it's now documented public information, so there's no obvious political value in staging a false flag operation to make it look like it was the Chinese because that cat's already out of the bag. The only government on the entire planet that would perceive any value in attacking either of these groups is the Chinese government.
Yeah because there are all those reports from western peoples families, that their loved ones were abducting by the Chinese government while they were on a holiday in china. On the other hand there have been many stories of people being stopped entry to America because of something they wrote on the internet (no abductions that i know about at the airport, but i wouldn't like to be snowden or assange walking around over there) and if America finds you in a country they don't like (and are alot bigger than) they can throw you in guantanamo bay.
Rocket Surgeon.
Re: How are the Chinese doing this?
The same way the US tracks protesters/anti war groups or faith based charities are examined, Russia tracks the press/CIA/MI6 funded NGOs or dissidents.
You find the 'easy' local groups, raid them and see what their admins are doing. Build up picture of their networks and then legend your sock puppets/long term infiltrators for the international supporters.
Sock puppets get people taking, long term infiltrators build trust with the admins and become helpful leaders in the online communities.
Later when the network is mapped out, leadership and top posters named more direct option are open to the gov.
Philippines and Vietnam both has historical issues with China and the quality of their computer networks would be expanding for trade, military upgrades and tourism.
Trade and tourism would usually be some front end based on Microsoft as hinted with the mention of "Microsoft Word vulnerabilities were exploited, the payload decrypted and then executed"
MS (made in the USA) is the way in for the NSA, China and any other group it seems.
Domestic spying is now "Benign Information Gathering"
I'm not American - hell, I'm actually banned from the country (a technical issue with visas). I'm not interested in anyone "winning". I'm simply pointing out, since you seem to have missed it again, that reporting news isn't "hypocrisy". It's only hypocritical if the media, while reporting the news, actually made statements to the effect that it would never happen in the West. That isn't happening. You're seeing hypocrisy where there is none. Call it partisan. Call it overblown. But you can't call it hypocritical.
"The true measure of a person is how they act when they know they won't get caught." - DSRilk
At a previous gig I was tasked with setting up a network with VPN endpoints in Shanghai, Noida, SF, and NYC. Within months I was consulting with my buddies that started their own security company because my doorknob was rattling off the hook mainly in the Shanghai region. The data being protected was a AAA game engine under heavy development, which I can say never got leaked unlike the one from our sister studio in the UK. The mass of massive hacking coming my way did seem to be chinese govt related (in this case rightfully so) because I can only describe it as a gigantor sized botnet with permanent PMS that seemed to disappear when you began investigating it. It was explained to me they have developed their own protocols which do not translate well to a western approximation of things. Constant attempts to poison DNS on our domain controller from seemingly 3g mobile network addresses in the region and a heavy use of whale-sized infiltration techniques were constant headaches. I could not just change the platform or OS too many 3rd party tools. I got no help from admins on their end when I asked why all this **** was on their network segment and why their BYOD policy was allowing it. My only saving grace was a machine put together from spare parts dedicated to taking the brunt of Shanghai attack attempts which had absolutely nothing on it but was set up to look like the machine that was the goal of all the attacks on the network. After a month or so it would mysteriously get knocked off the network whenever it was put up even after an OS reinstall when VPN was up. Luckily, it gave us enough time to get spinlocking RSA dongles in the mail which were all the rage back then. Found out later all this work was to protect some shady employment practices that became very public after I had left the company. The point of this very long tale which will most likely get buried is get both sides of the story. Justice is blind, even on the net, wherever these people are you have to ask yourself when it comes to a person's life or wellbeing these things may actually be necessary and it is not always to stem the tide of dissent. You can read the news but this is an actual in the trenches account- hope it helps and hope more people will share these experiences.
Hey China, there's this place called Westboro Baptist Church, I heard that they said nasty things about your government. (crosses fingers and waits).
It makes perfect sense that Chinese groups are attacking the military of the Philippines since China is paving the way for aggression. China is trying to claim sovereignty over islands claimed by many of its neighbors. The age old quest by China to establish its hegemony continues.
Philippines Protests Renewed Chinese Pressure in South China Sea
China And The Biggest Territory Grab Since World War II
The Philippines and Japan want U.S. help in dealing with China’s aggression
Philippines upgrades military to end China "bullying" in S. China Sea
Japan Will Sell Ships To Philippines To Fight China’s “Bullying”
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
A Russian Snowden would not help that much, as any illumination he did would be with alpha particles which aren't very penetrating.
A Chinese snowden would be lucky to make it out of the country, and would likely be dead in an 'accident' a week after the first leak.
Why foreign organisations are using: 1) a closed-source OS developed by a foreign power 2) software with all these security flaws 3) a software defective by design
Unless they're moving against Christians, most of the western world doesn't care.
China has a thriving trade in sex slaves, protected by official corruption - bigger fish to fry.
How can malware be zero-day? If it's exploiting some security weakness, then it's a virus and not malware. If it's malware, then it's probably gotten itself installed (even if through nefarious means) via some social engineering technique. I suspect this is a stretched use of "zero-day" in order to make the headline & article more exciting.
I'm not even sure they have computers. AFAIK, God may Hate Computers.
Dark Reflection
I'll bet they have computers. Westboro isn't actually a church.
They are more like patent trolls, but they troll city governments that try to quash the protests and then sue them.
It's a family business, not a church, just like a patent troll is a business but not a company that makes or sells items (unless ou consider a protection racket an item).
btw, I think the only government Westboro has complained about is the US one.
Say what you will about Chinese government & private sector computer crime, at least they're not reading my email and logging all my net traffic.
How do you know that? Maybe they've hacked into the USA's NSA and stolen all our data already;-)
The 'evidence' isn't (although I agree FG is a cult, your evidence is just garbage).
IF I accepted it as evidence, then Billy Graham would not be a real preacher because he had his own TV shows and asked for donations.
That would mean the Pope isn't actually in charge of a 'real' church because they have their own Catholic bank.
Opinion, even when I agree with it, isn't the same as evidence or fact.
Having been to their website once (morbid curiosity), I'd say they had computers in the mid-nineties, set up the website, and then got rid of them all. I recall a lot of GIFs and blinking text.
Ha ha, I'm making fun of their lack of web design skills. Also they're terrible fucking hypocrites who will burn in hell. That's funny too.
And that is how asymmetric advantage accrues to the genuinely oppressive regimes. Cripple intelligence agencies in free societies, do nothing about the actual oppressive regimes. What could possibly go wrong?
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
Whether they are a cult doesn't make it ok for the Chinese government to persecute them.