More

China Hackers Hit Western Oil Companies: Report

China Oil

JOE McDONALD   02/10/11 11:52 PM ET   AP

BEIJING — Hackers operating from China stole sensitive information from Western oil companies, a U.S. security firm reported Thursday, adding to complaints about pervasive Internet crime traced to the country.

The report by McAfee Inc. did not identify the companies but said the "coordinated, covert and targeted" attacks began in November 2009 and targeted computers of oil and gas companies in the United States, Taiwan, Greece and Kazakhstan. It said the attackers stole information on operations, bidding for oil fields and financing.

"We have identified the tools, techniques, and network activities used in these continuing attacks – which we have dubbed Night Dragon – as originating primarily in China," said the report.

The report gave no indication the attacks were anything other than standard corporate espionage that plagues businesses around the world, which the U.S. and China have both accused each other of being deeply involved in.

The fact that oil companies were targeted may speak more to the value of their inside information than any attempt to cause damage to pipelines. McAfee called the attack methods "unsophisticated," but said the culprits were patient: they may have been inside the networks for years.

"It looked to me like the traditional hack-to-steal-valuable-stuff," said Josh Shaul, vice president of product management at Application Security Inc., a New York-based database security software maker that wasn't involved in McAfee's research. Application Security counts energy companies, including oil firms, among its clients. "It all seemed to me like someone trying to get ahead in the oil industry rather than doing something more nefarious."

The intruders were prolific in their purloining, snatching files including configurations for the oil companies' control systems, but Dmitri Alperovitch, vice president of threat research for McAfee, said they didn't appear to be trying to figure out how to blow up a pipeline or destroy equipment.

"I got a very strong sense that was not their goal," he said. "They expressed a much stronger interest in financial information."

McAfee said it identified an individual in the eastern Chinese city of Heze in Shandong province who provided servers that hosted an application that controlled computers at the victim companies. The report did not identify the man but U.S. news reports citing McAfee gave his name as Song Zhiyue.

Contacted by phone, Song said he was a salesman for a company, Science and Technology Internet, that rents server space. He said some of his customers were hackers but he declined to comment on the attacks cited by McAfee. Song said he has not been contacted by Chinese authorities.

"I recently heard about Chinese hackers using U.S. servers provided by companies like ours to attack oil companies in the U.S. Our company alone has a great number of hackers" as customers, Song said. "I have several hundred of them among all my customers as far as I know."

Critical infrastructure is increasingly a hacking target as its technology is brought into the Internet age.

An attack might be as simple as getting a low-level employee to open a malicious e-mail link. Or, it might involve exploiting well known vulnerabilities in Internet-connected servers, which is how McAfee said the oil companies were attacked. Finding those weaknesses can be simple; programs exist that will scan the Internet and automatically issue an alert when vulnerable servers have been found.

Still, money, not terrorism, appears to frequently be the motive, as it is with most computer crime.

A separate report last year from McAfee and the Center for Strategic and International Studies in Washington found that more than half of the 600 operators of power plants and other critical infrastructure surveyed said their networks were infiltrated by sophisticated adversaries. Extortion was identified as a common motivation. Oil companies were among the most frequently targeted.

Security consultants say China is a leading center for Internet crime including industrial spying aimed at major companies. Consultants say the high skill level of earlier attacks suggests China's military, a leader in cyberwarfare research, or other government agencies might be stealing technology and trade secrets to help state companies.

Last year, Google Inc. closed its China-based search engine after complaining of cyberattacks from China against its e-mail service.

The Chinese government has denied it is involved.

Officials in the United States, Germany and Britain say hackers linked to China's military have broken into government and defense systems. Attacks on commercial systems receive less attention because companies rarely come forward, possibly for fear it might erode trust in their businesses.

Spokesmen from several American, British and Greek oil companies said they were either unaware of the hacking or that they could not comment on security matters.

McAfee, based in Santa Clara, California, said the hackers worked through servers in the United States and the Netherlands and used techniques including taking advantage of vulnerabilities in the Microsoft Windows operating system.

McAfee said extraction of information occurred from 9 a.m. to 5 p.m. Beijing time on weekdays. It said that suggested the attackers were "company men" on a regular job, rather than freelance or amateur hackers.

The attackers used hacking tools of Chinese origin that are prevalent on Chinese underground hacking forums, McAfee said.

Google announced last January that cyberattacks from China hit it and at least 20 other companies. Google says it has "conclusive evidence" the attacks came from China but declined to say whether the government was involved.

Google cited those attacks and attempts to snoop on dissidents in announcing it wanted to stop censoring search results in China, which the communist government requires. The company closed its China-based search engine last March.

In 2009, a Canadian research group said a China-based ring stole information from thousands of hard drives worldwide. The Information Warfare Monitor said attackers broke into government and private organizations in 103 countries, including the computers of the Dalai Lama and his exiled Tibetan government.

There are no estimates of losses attributable to hacking traced to China, but McAfee has said previously that intellectual property worth an estimated $1 trillion was stolen worldwide through the Internet in 2008.

McAfee's report was released ahead of the annual RSA Conference next week in San Francisco. Security firms issue a flurry of reports around such conferences to promote their products and call attention to new hacking trends.

___

AP researcher Zhao Liang in Beijing and AP Business Writer Chris Kahn in New York contributed to this report.

___

Online:

McAfee Inc.'s report: http://bit.ly/hvV38n

FOLLOW HUFFPOST WORLD

BEIJING — Hackers operating from China stole sensitive information from Western oil companies, a U.S. security firm reported Thursday, adding to complaints about pervasive Internet crime traced ...
BEIJING — Hackers operating from China stole sensitive information from Western oil companies, a U.S. security firm reported Thursday, adding to complaints about pervasive Internet crime traced ...
Filed by Cara Parks  | 
 
 
  • Comments
  • 195
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2 3 4 5  Next ›  Last »  (5 total)
photo
ken607
nothing clean about coal nothing natural about gas
08:16 AM on 02/14/2011
whats the diff between a military attack and cyber attack. arent they still attacks? both can do considerable amounts of damage. lets just cut spending, instead of RAISING REVENUE! see aronald reagan word salad. another way of saying raise taxes.
11:49 PM on 02/12/2011
Let's see the people of China pull an Egypt and dump their unelected, undemocratic government.
12:20 AM on 02/14/2011
Why should China do that?

Just since when any government must be "Democratic" to be legitimate? Is it stated in the Western Bible and must be observed by all humanity?
photo
adamben
yes i said yes i will yes
12:26 PM on 02/14/2011
that poster didn't mention "legitimate". however, democracy for all is a good thing even if you don't believe or know what it is.
photo
HUFFPOST SUPER USER
Edward Standley
opinionated jerk
10:53 AM on 02/14/2011
Guessing they won't do that because the Chinese military is not the Egyptian military. So far, great kudos belong to the Egyptian generals. Hope they remain on the "up-and-up".
This comment has been removed due to violations of our [Guidelines]
photo
rikster
buy the ticket-take the ride
07:33 PM on 02/11/2011
the PLA hacker corps strikes again...!
08:33 PM on 02/11/2011
As if we don't strike at them. The difference we whine loud through our media and they just kept quiet and suck it in like a man.
photo
adamben
yes i said yes i will yes
12:27 PM on 02/14/2011
we don't need to steal their info.
03:17 PM on 02/11/2011
Don't be fooled. These are chincom govt controlled hackers. It's a Chinese govt op.
08:34 PM on 02/11/2011
And when our hackers go after them, our hackers are not from US government sponored black ops?
photo
adamben
yes i said yes i will yes
12:27 PM on 02/14/2011
which hackers and hacks are you talking about?
01:04 PM on 02/18/2011
Whose side are you on? You equate the US govt to a Chinese communist dictatorship?
10:14 AM on 02/11/2011
Is it me or is China being more aggressive? I think this is why we need to keep a strong defense and the oil and gas companies need to hire a new computer security guy
photo
HUFFPOST SUPER USER
AG creative
Ba Gawk!
12:45 PM on 02/11/2011
Chinese, Indian, African & Russian hackers are owning right now.
photo
HUFFPOST SUPER USER
Bahne
01:05 PM on 02/11/2011
Funny thing is you don't hear about the more sophisticated hackers because they aren't getting caught like alot of these guys you mentioned.
photo
ibsteve2u
Someone who cares - to his unending regret
03:07 AM on 02/11/2011
Given the nature of Big Oil, I imagine one of the financial advantages being sought is the tools of blackmail.

Although I suppose I could just assume that Big Oil's finances - to include what and who they have bought - are completely on the up-and-up and therefore a hacker wouldn't find anything useful for leverage down the road...
02:38 AM on 02/11/2011
they call them chinese hackers, but in fact they work for the chinese govenmrnt. china has no respect for laws.
08:36 PM on 02/11/2011
And our hackers are not working on behave of our government?

Realistically, if our government does not send out massive number of hackers against the rest of the world and uncover ALL information that can be used, I think our government has done a dis-service to our national interests.
01:14 AM on 02/11/2011
Sorry for the long post...

I think this has something to do with the STUXNET virus, which I think originated from China. I also believe that China had to do with this long line of shutdowns and moments of utter embarrassment for the USA...

SEPTEMBER
9/30: 6 Million Computers and 1000 Enterprises Hit by Virus in China (Opposing Factions -- Insider War)
http://www.foxbusiness.com/markets/2010/09/30/stuxnet-virus-spreads-china-xinhua/
9/30: Start-up of Iran’s Bushehr Nuclear Plant Delayed By Virus
http://www.bbc.co.uk/news/world-middle-east-11445126
(11/26): Stuxnet Virus Almost Impossibly Sophisticated (Extraterrestrial-Designed)
http://www.foxnews.com/scitech/2010/11/26/secret-agent-crippled-irans-nuclear-ambitions/
01:16 AM on 02/11/2011
OCTOBER
10/21: Exxon Mobil Oil Refinery Near Chicago Has Equipment Failure
http://www.bloomberg.com/news/2010-10-22/exxon-mobil-has-equipment-failure-flaring-at-joliet-refinery.html
10/22: Oil Refinery in Rodeo, CA Has Equipment Failure
http://www.mercurynews.com/news/ci_16409951
10/22: Brand New UK Nuclear Submarine "HMS Astute" Loses Power, Runs Aground Off Scotland
http://www.reuters.com/article/idUSTRE69L2FJ20101022
10/23: 1/9th of US Missile Arsenal Taken Offline for One Hour
http://www.cbsnews.com/8301-503544_162-20020817-503544.html
10/23: US Lost Command of 1/9th of Nuclear Arsenal -- Unprecedented, Enormous Failure
http://gizmodo.com/5674028/one+ninth-of-us-nuclear-intercontinental-missiles-down-last-saturday
10/28: French Warship to Join US Fleet -- Escalating Persian Gulf Tensions
http://www.presstv.ir/detail/148623.html
10/31: French Nuclear Aircraft Carrier Breaks Down Enroute to Persian Gulf
http://www.presstv.ir/detail/149065.html
01:22 AM on 02/11/2011
11/8: Equipment Failure Causes 15 Time Warner Channels (If Not All of Them) to Freeze for 90 Minutes
http://blog.cleveland.com/metro/2010/11/equipment_failure_freezes_15_t.html
11/8: Time Warner Blackout Included NBC’s George W. Bush Interview and “The Event”
http://chronicle.northcoastnow.com/2010/11/09/time-warner-blames-equipment-failure-for-frozen-screens-last-night/
11/9: Massive Missile Launch Occurs Off LA Coast, Still Unexplained
http://news.yahoo.com/s/nm/20101109/ts_nm/us_usa_missile_mystery
11/9/2007: Chinese Sub Appears in US Navy Exercise -- Huge Shock and Embarrassment (Same Day as 2010 Missile)
http://www.dailymail.co.uk/news/article-492804/The-uninvited-guest-Chinese-sub-pops-middle-U-S-Navy-exercise-leaving-military-chiefs-red-faced.html
11/10: Mystery Contrail May Have Been An Airplane (Not)
http://www.foxnews.com/scitech/2010/11/10/blogger-solved-california-missile-mystery/
11/10: Rocketry Expert Confirms It Was a Solid Propellant Missile
http://www.cbsnews.com/stories/2010/11/10/earlyshow/main7040379.shtml
11/10: Weird Line of “Fire” Hangs in NY Skyline
http://newyork.cbslocal.com/2010/11/10/did-you-see-the-fire-in-the-nyc-sky/
01:22 AM on 02/11/2011
11/15: BP Texas Oil Refinery Fails, Releases Hydrogen Sulfide
http://www.bloomberg.com/news/2010-11-16/bp-texas-refinery-had-equipment-failure-galveston-news-says.html
11/28: Kansas Oil Refinery Has Equipment Failure, Releases Hydrogen Sulfide and Sulfur Dioxide
http://www.bloomberg.com/news/2010-11-28/cvr-s-coffeyville-kansas-refinery-reports-equipment-failure.html

DECEMBER
12/4: Louisiana Oil Refinery Has Fiery Equipment Failure
http://www.bloomberg.com/news/2010-12-04/motiva-has-equipment-failure-flares-at-refinery-in-louisiana.html
01:18 AM on 02/11/2011
NOVEMBER
11/3: Electrical Fault Causes Largest American Nuclear Power Plant to Shut Down
http://nuclearstreet.com/nuclear_power_industry_news/b/nuclear_power_news/archive/2010/11/29/south-texas-project-unit-2-returns-to-service-112901.aspx
11/4: Quantas Airlines Grounds All Airbus A380s After Engine Fire Over Indonesia
http://www.huffingtonpost.com/2010/11/04/qantas-airbus-problem-ai_n_778719.html
11/5: Engine Problems Hit Second Quantas Aircraft -- This Time a Boeing 747-400
http://www.reuters.com/article/idUSTRE6A435P20101105
11/7: 911 Emergency System Equipment Failure in Atlanta
http://www.ajc.com/news/cherokee/equipment-failure-caused-cherokee-731853.html?cxtype=rss_news_60046
11/8: Quantas Uncovers More Engine Problems
http://www.abc.net.au/news/stories/2010/11/08/3059568.htm
11/8: “Complete Coincidence” as Two Different Nuclear Plants Shut Down Within One Hour – New York and Vermont
http://www.nydailynews.com/news/national/2010/11/08/2010-11-08_complete_coincidence_two_nuclear_plants_owned_by_new_orleansbased_entergy_corp_a.html#ixzz14hcA0Qyw
11/8: Carnival Splendor Cruise Ship's Propulsion and Communication Systems Destroyed, Ship Stranded for Days
http://www.dailymail.co.uk/news/article-1328692/Carnival-Splendor-passengers-speak-cruise-liner-nightmare.html
12:09 AM on 02/11/2011
Continued proof that China's rise is not due to Chinese innovation, but rather Western charity, given and taken.
01:28 AM on 02/11/2011
Actually it's more like a master owning a slave and the slave having secrets of his own.
03:06 AM on 02/11/2011
If you are able to boil down the relationship between the US and China to that of master and slave you have quite a misinformed about said relationship.

China holds 20% of US Treasury Securities sold to foreign nations; Japan holds a slightly lesser percentage.

The pillar of the Chinese economy is exports purchased en mass by American and European consumers.

The notion that China somehow 'owns' the US is extremely off base. The relationship is one of mutual reliance, not one that is one side, and definitely not one where China is in the driver seat.

Without the US and European consumer the Chinese economy would plummet and millions upon millions of migrant Chinese, working in the Pearl River Delta, would take to the streets. This would have an adverse effect on the US economy, but not one which would put it into any more peril than it already has been lead into.

On the flip side a cash rich China is extremely important for stabilizing the dip in import/export industries of the West. as well as pushing R&D in all fields of work.

But it is hardly a master and slave relationship in favor of China.
photo
ibsteve2u
Someone who cares - to his unending regret
03:39 AM on 02/11/2011
You're right, but our "right" is too dependent upon their philosophy of greed - greed too easily satisfied with the illusion of "money" - to see the real and massive shift in power that they have enabled; that they have, indeed, fostered.

lolll...perhaps our right thinks that China pursues alternative energy - a "green revolution" - for the good of their people?

You have to be pretty dumb not to be able to see that China, instead, seeks to eliminate the worst of their two weaknesses: Reliance upon external energy (food being the other...but a distant and secondary weakness when your supply of workers and soldiers can absorb severe punishment but the codependent mechanisms of industry and war are bounded by available energy).

China has watched how our Republicans' ability to keep America sickly dependent upon oil has harmed the American economy with continuous price shocks and massive outflows of "money" in foreign oil payments and distorted both our strategic goals and capabilities. They have watched...and learned.

But our right? They're just...dumb. They think the world begins and ends around "money"...that figment of the human imagination invented solely to facilitate trade and denominate true wealth.
photo
Left of Right
Want to default your country? Default your job!
12:03 AM on 02/11/2011
Why would China want to steal from us? They already own us. Isn't that like sneaking a dollar from your wallet and sneaking it into your own pocket?
01:29 AM on 02/11/2011
Actually it's more like a master owning a slave and the slave having secrets of his own. Then finding ways to squeeze that secret out the slave.
11:23 PM on 02/10/2011
What else is new! Every country, company or university that forms a partnership with China will have some or all of their intellectual property stolen from them eventually. There are no new ideas coming out of China that wasn't stolen. China is akin to the neighbor who steals your car then tries to sell it to you after they re-paint it. All that cheap stuff we're getting is just our stuff, repackaged. The only good about this hacking is that they're 'stealing' from the industry that's polluting our country, causing billions going to endless wars for oil, preventing the US from moving to alternative energy, and tax cuts that run into the billions. Karma hurts!
11:17 PM on 02/10/2011
When western hackers hack Chinese sensative information, the Chinese just kept quiet and tried to save face.

When Chinese hackers go after online information of western companies or governments, the western media screamed as loud as they can on behave of their governments.

It is interesting to see the display of very different culture and mentality.
01:35 AM on 02/11/2011
If it was that we hacked into Chinese companies and try to steal their intellectual property I can see where you were getting at. But if it's us going into there government servers to see what they are planning, that's different.

We are ahead of the Chinese in technology, maybe not employed in the same way, but we are still ahead. That's why the Chinese are hacking into our corporation systems, while the communism has left there technological progress lacking compare to ours.

Also I don't think you should mention Chinese media vs America. One is ALOT more free to spread information then the other.
12:53 PM on 02/12/2011
Do you really believe America Media is free?

What happen for the last 30 years when Mubarrack is the Egyptian president and accumulate massive amount of money? Where is our media on that?

It is free only on issues that suite the US national interests.

Grow up.
09:46 PM on 02/10/2011
Be my guest!
07:10 PM on 02/10/2011
The USA has no meaningful China policy. China is going to carve up the USA like a turkey on thanksgiving as they rise to World's 1 super power.