Vast Electronic Spy System Loots Computers In 103 Countries

digg Share this on Facebook Huffpost - Vast Electronic Spy System Loots Computers In 103 Countries stumble reddit del.ico.us RSS

CHARMAINE NORONHA | March 29, 2009 06:52 AM EST | AP

Compare other versions »
I Like ItI Don’t Like It
In this Tuesday March 10, 2009, file photo, Tibetan spiritual leader, the Dalai Lama, speaks to the media on the 50th anniversary of the Tibetan uprising against Chinese rule that sent him into exile, in Dharmsala, India. The South African government said Tuesday, March 24, 2009, that the Dalai Lama is not welcome until after the 2010 football World Cup, for fear tensions over Tibet would overshadow all other issues. Organizers said earlier that a peace conference scheduled in Johannesburg on Friday has been indefinitely postponed because the government had barred attendance by the Tibetan leader, who has clashed with China. Tibet's government-in-exile said South Africa was acting under pressure from China, but South Africa's government denied it. South Africa is China's largest African trading partner. (AP Photo/Ashwini Bhatia/file)

TORONTO — A cyber spy network based mainly in China hacked into classified documents from government and private organizations in 103 countries, including the computers of the Dalai Lama and Tibetan exiles, Canadian researchers said Saturday.

The work of the Information Warfare Monitor initially focused on allegations of Chinese cyber espionage against the Tibetan community in exile, and eventually led to a much wider network of compromised machines, the Internet-based research group said.

"We uncovered real-time evidence of malware that had penetrated Tibetan computer systems, extracting sensitive documents from the private office of the Dalai Lama," investigator Greg Walton said.

The research group said that while it's analysis points to China as the main source of the network, it has not conclusively been able to detect the identity or motivation of the hackers.

Calls to China's Foreign Ministry and Industry and Information Ministry rang unanswered Sunday. The Chinese Embassy in Toronto did not immediately return calls for comment Saturday.

Students For a Free Tibet activist Bhutila Karpoche said her organization's computers have been hacked into numerous times over the past four or five years, and particularly in the past year. She said she often gets e-mails that contain viruses that crash the group's computers.

The IWM is composed of researchers from Ottawa-based think tank SecDev Group and the University of Toronto's Munk Centre for International Studies. The group's initial findings led to a 10-month investigation summarized in the report to be released online Sunday.

The researchers detected a cyber espionage network involving over 1,295 compromised computers from the ministries of foreign affairs of Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados and Bhutan. They also discovered hacked systems in the embassies of India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal, Germany and Pakistan.

Once the hackers infiltrated the systems, they gained control using malware _ software they install on the compromised computers _ and sent and received data from them, the researchers said.

Two researchers at Cambridge University in Britain who worked on the part of the investigation related to the Tibetans are also releasing their own report Sunday.

In an online abstract for "The Snooping Dragon: Social Malware Surveillance of the Tibetan Movement," Shishir Nagaraja and Ross Anderson write that while malware attacks are not new, these attacks should be noted for their ability to collect "actionable intelligence for use by the police and security services of a repressive state, with potentially fatal consequences for those exposed."

They say prevention against such attacks will be difficult since traditional defense against social malware in government agencies involves expensive and intrusive measures that range from mandatory access controls to tedious operational security procedures.

The Dalai Lama fled over the Himalaya mountains into exile 50 years ago when China quashed an uprising in Tibet, placing it under its direct rule for the first time. The spiritual leader and the Tibetan government in exile are based in Dharmsala, India.

TORONTO — A cyber spy network based mainly in China hacked into classified documents from government and private organizations in 103 countries, including the computers of the Dalai Lama and Tib...
TORONTO — A cyber spy network based mainly in China hacked into classified documents from government and private organizations in 103 countries, including the computers of the Dalai Lama and Tib...
 
Comments
104
Pending Comments
0
iPhone App Promo

Want to reply to a comment? Hint: Click "Reply" at the bottom of the comment; after being approved your comment will appear directly underneath the comment you replied to

View Comments:
Page: 1 2 3 Next › Last » (3 pages total)
- All in All I'm a Fan of All in All 63 fans permalink

Personally­... I think what Hackers do is a good thing, and instead of putting them in prison right off (if at all) their skills should be noted & tapped for the "greater good"!

    Favorite    Flag as abusive Posted 08:55 AM on 04/01/2009
photo

Not sure why this is a US vs China thing. This is about the Chinese oppression of Tibetans far and wide.

This link explains and offers rebuttals to Chinese farcical propaganda attacks

http://www.studentsforafreetibet.org/article.php?id=422

Read the history of Tibet there as well as find ways to help the Tibetan people.

    Favorite    Flag as abusive Posted 10:36 AM on 03/29/2009
- Ergon I'm a Fan of Ergon 87 fans permalink
photo

Ah yes the racists students who attacked ethnic Chinese civilians with hatchets in Lhasa.

    Favorite    Flag as abusive Posted 10:01 PM on 03/30/2009
- LMPE I'm a Fan of LMPE 68 fans permalink

If China hacked into George W. Bush's computer and found things that he writes, they'd never be able to understand it (or would he just have someone ghostwrite it?).

    Favorite    Flag as abusive Posted 09:38 AM on 03/29/2009
photo

You are putting the carriage before the horse.

I seriously doubt Bush can write.

    Favorite    Flag as abusive Posted 10:08 AM on 03/29/2009
photo

or operate a computer..­.

    Favorite    Flag as abusive Posted 10:21 AM on 03/29/2009
- moflard I'm a Fan of moflard 12 fans permalink

To all those affronted Americans, let's not forget ECHELON.

    Favorite    Flag as abusive Posted 06:11 AM on 03/29/2009
- bubbuh I'm a Fan of bubbuh 135 fans permalink
photo

On the other hand, who wants to bet that against the idea that all these Chinese infowarriors belong to a variety of tongs and are waging war on each other as well?

    Favorite    Flag as abusive Posted 03:23 AM on 03/29/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

Oh great. They will hurl their botnets against each other and the entire Internet will suffer.

    Favorite    Flag as abusive Posted 03:28 AM on 03/29/2009
photo

make some popcorn and watch the fun.

    Favorite    Flag as abusive Posted 03:57 AM on 03/29/2009
- OneTop I'm a Fan of OneTop 92 fans permalink
photo

A vote for Linux ..........­... !

    Favorite    Flag as abusive Posted 02:28 AM on 03/29/2009
- Yaaawn I'm a Fan of Yaaawn 5 fans permalink
photo

Really. Save yourselves the heartache and move to Mac or Linux. Windows will cause you nothing but grief.

    Favorite    Flag as abusive Posted 01:45 PM on 03/29/2009
- Yves Papa I'm a Fan of Yves Papa 14 fans permalink

Live with this:
ALL your phone conversations, internet access, purchases, etc... are recorded in some secret, super-storage facilities, in places such as Homeland Security or at ATT.
There is NO privacy left. Everything you say or do is recorded.
Live with it. Know it.
You can't keep anyone from recording you. But you have the power to forbid the use of these recordings.

    Favorite    Flag as abusive Posted 02:04 AM on 03/29/2009
- bubbuh I'm a Fan of bubbuh 135 fans permalink
photo

Since 50% of it is porn of one sort or another and 45% of it is trivial, the information collectors must be going glazy crazy by now.

    Favorite    Flag as abusive Posted 03:20 AM on 03/29/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

They actually have very good filters. They filter out all that junk and they don't even bother with it. Only the "good stuff" comes through the filters.

    Favorite    Flag as abusive Posted 03:25 AM on 03/29/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

It's not super secret. Your ISP is doing it. ISPs _hate_ the Internet. They really long for the old days of AOL where they had total control of your content. They want to push you onto their content, so they do all sorts of strange things to your Internet connection to make everyone else's content slower, and their content faster. They have to inspect the data that you send out onto the Internet in order to do this. It is tantamount to opening people's mail and it should be totally illegal.

    Favorite    Flag as abusive Posted 03:36 AM on 03/29/2009

The ultimate sci-fi novel...AL­L sources of information are transformed from print to the "Web" and then someone turns all our resource access into the blue screens of death.

At its most benign, who will we Tweet? At its most evil, 100s of millions of blue screens of death.

    Favorite    Flag as abusive Posted 01:21 AM on 03/29/2009
- TJCole I'm a Fan of TJCole 163 fans permalink
photo

LOL..!

We elect idiots Tom Clancy said that..!

No not the Chinese government, it's some fisherman in a grass hut..!

    Favorite    Flag as abusive Posted 12:33 AM on 03/29/2009
- RRK70 I'm a Fan of RRK70 16 fans permalink

Maybe since we borrow the money from China to fund our government, they were just checking in on their investment?

    Favorite    Flag as abusive Posted 11:47 PM on 03/28/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

Before long they are going to start thinking of us as their property. They do indeed have enough of our money to own us.

    Favorite    Flag as abusive Posted 11:50 PM on 03/28/2009
- RRK70 I'm a Fan of RRK70 16 fans permalink

To be frank that's probably the way others have viewed the US, what comes around goes around!

    Favorite    Flag as abusive Posted 11:54 PM on 03/28/2009
- bubbuh I'm a Fan of bubbuh 135 fans permalink
photo

I opened my midi-tower; and there was this tiny Asian guy sitting there taking notes.

    Favorite    Flag as abusive Posted 10:59 PM on 03/28/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

Richard Stallman and Linus Torvalds live in my computer.

    Favorite    Flag as abusive Posted 11:38 PM on 03/28/2009
- TJCole I'm a Fan of TJCole 163 fans permalink
photo

LOL..!

    Favorite    Flag as abusive Posted 01:34 AM on 03/29/2009
- Tinsdale I'm a Fan of Tinsdale 18 fans permalink

The Chinese army has within its ranks a a dedicated group of "infowarri­ors." The goal is thought to be the utilization of technology to damage an opponents infostructure such as missile systems, defense capabilities, power grids, financial networks and communication functions, This type of warfare was used on a less ambitious scale in the initial hours of the Iraq war to limit responses by the Iraqi air and ground forces.

In the past, there was a very significant cyber assault on the U.S. Department of Defense systems, Tthe attackers utilized a large number of assets The attack was also of significant duration. The country involved was deemed to be China . It was thought to be a probing attack to gather information on our systems and our responses. The attack was code named "Titan Rain." There is non-classified information available on the internet using Google or any other search engine.

    Favorite    Flag as abusive Posted 08:57 PM on 03/28/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

All you have to do is ditch Windows and you are immune to 99% of this crap. Windows zealots brag about how they have 90% market share. I don't know about you, but I don't like to brag when I am a target.

    Favorite    Flag as abusive Posted 11:37 PM on 03/28/2009
photo

Yeah Right! To configure my video or sound cards, I need to F with hundreds of config files and I may have to screw around with the arcane header files using C to rebuild the binaries.

Because the windows is used in majority of the desktop around the word, it is targeted heavily by hackers. Some of its flaws are exposed. For the reasons I mentioned above, *nix is not the dominant OS and hackers don't bother with it. The hidden security vulnerabilities in *nix aren't exposed as a result. Good luck with your *nix OS!

    Favorite    Flag as abusive Posted 10:04 AM on 03/29/2009
- bubbuh I'm a Fan of bubbuh 135 fans permalink
photo

"We have met the enemey and they is us." I use some proprietary software that runs only under windows so I have a dual boot system with Ubuntu as my primary OS. I rarely use windows on the web anymore. When i do, i use either Opera or Firefox as the browser. Ubuntu, which is a really well behaved Linux variant, has extended the life of my hardware and saved me a few hunfdred dollars on software. It really is virually impervious to the kind of crap which brings down windows and vista.

I would hope our government systems specialists have finally figured out what they need to do to properly protect their chares.

    Favorite    Flag as abusive Posted 03:17 AM on 03/29/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

I hope you have SELinux enabled! Don't ever run Flash without it!

    Favorite    Flag as abusive Posted 03:29 AM on 03/29/2009

You think the Israelis and the Russians do too? and how about the U.S. Army, NSA, CIA and more?

    Favorite    Flag as abusive Posted 08:10 AM on 03/29/2009
photo

If you follow the "principle of least privilege", you can greatly minimize things like spying. We completely blocked Chinese and some eastern European counties IP numbers for both inbound or outbound traffic. End users do not have local administrator or root permissions.

    Favorite    Flag as abusive Posted 08:28 PM on 03/28/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

That's why they use infected computers in this country, to get around those firewalls.

People in general have no clue about how powerful these botnets are.

    Favorite    Flag as abusive Posted 11:35 PM on 03/28/2009
- Tinsdale I'm a Fan of Tinsdale 18 fans permalink

You raise an excellent point about botnets and their power including their support teams: everything from "Herders" to money launderers. I think if people looked up information on the "RBN"- the "Russian Business Network" which "went dark' at the end of last year, or even the now dismanteled "Shadow Crew" they would get an idea of what you are talking about.

    Favorite    Flag as abusive Posted 01:25 AM on 03/29/2009
photo

That's why I said "minimize". You can never completely eliminate the threat. You can only be proactive and protect your network.

If you think about it, how in the world the end users got the virus/spyw­are/malwar­e/botnet to begin with? You, the network administrator, allowed them to go to sites they shouldn't be going to and downloaded scumware that compromised your network.

If you block all access to all sites and all protocols, you will not have this problem but in reality this is impossible. That's why you follow the "principle of least privilege". You only allow the users to sites that he/she absolutely needs to do their "job". Even then an end user can bring in his/her own compromised USB drive and spread the malware. Here you need a strong IT policy.

So you never can completely eliminate the threats, but you can use tools like IDS, Layer 7 inspection firewalls, principle of least privilege and IT policies to minimize the impact.

    Favorite    Flag as abusive Posted 09:46 AM on 03/29/2009
- frantaylor I'm a Fan of frantaylor 22 fans permalink

Good lord every country spies on every other country and they have for years. Is this anything new? It is much better that they spy on each other and figure out what each other is doing. The alternative is that countries get all paranoid and start invading or dropping bombs on each other.

As far as commercial theft over the Internet goes, well, folks, the Internet has been around for 20+ years now and if you can't figure out how to keep people from breaking into your place and stealing your stuff, it's your own incompetence more than anything else.

And if you haven't figured out by now that having Microsoft on your computer is just an invitation to this sort of thing, well that is your own incompetence, also.

    Favorite    Flag as abusive Posted 08:05 PM on 03/28/2009
- muchtosay I'm a Fan of muchtosay 4 fans permalink
photo

If You want to get these people set them up bait the line. all fisherman use all types of bait for what they fishing for ,wait up people ,This is America we are smarter then this we know how to sop thngs before it happens not after then it to late

    Favorite    Flag as abusive Posted 07:45 PM on 03/28/2009
Page: 1 2 3 Next › Last » (3 pages total)
Comments are closed for this entry

 You must be logged in to comment. Log in  or connect with 

Connect