News / Asia

China's Cyber Espionage Case a Guide to Hacking

Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
The alleged hacking of U.S. corporate computers by elements of China’s military wasn’t in and of itself all that unique.
 
As cyber attacks go, it was moderately sophisticated in technique.
 
But that raises a more troubling question.
 
How could major international corporations — such as U.S. Steel, Alcoa and others with millions of dollars of intellectual property — get robbed by a small, low-cost group of hackers working from China?
 
The answer: It’s surprising it doesn’t happen more often.
 
Over its 48 pages and 31 counts of criminal misconduct, the U.S. Justice Department’s indictment details how five Chinese army officers, with Internet identities such as “Ugly Gorilla”, “Kandygoo” and “WinXYHappy,” went about infiltrating computer networks of six large U.S. corporations.
 
Sections of the indictment are so detailed that they read like a primer, a virtual "how-to manual" for anyone interested in how hackers do what they do.
 
Social engineering
 
While some of the terms such as “spearphishing,” “beacon” or “hop-points” may need a little technical explaining, it’s clear from the indictment that the defendants generally employed something security analysts call social engineering.
 
In essence, social engineering is a tactic where hackers pretend to be somebody else to try and trick the target into trusting them.
 
The aim is getting them to reveal information directly (such as a password) or infect their computers by clicking on malicious links and attachments. Social engineering, in the end, is just a fancy label for little more than a con job.
 
There are many different tricks a hacker might employ to earn their target’s trust.

But once they have it, it’s relatively easy to fool unsuspecting targets into releasing sensitive information.
 
A common example: if someone you believe is a trusted co-worker sends you an email urgently asking for a password they’ve forgotten, you’re probably much more likely to send it to them without thinking twice than someone you don’t know, analysts say.
 
“Given that these types of attacks can be attempted with very little consequence if they don't succeed,” said Mike Auty, senior security researcher at the firm MWR Infosecurity,

“It allows the attacker to launch a number of attacks, over a long period of time, and the chances are high that there will be a mistake, and someone will grant them access,” he said.
 
Which, as the indictment details, is  what the Chinese are alleged to have done.
 
One particular social engineering trick allegedly used by the defendants was “spearphishing” — sending links or attachments via email that, if clicked, would infect the target’s computer system without them knowing.
 
Once infected, the malware would create what’s called a “back door” or secret entrance into the system that could likely go undetected for prolonged periods.
 
In the recent indictment papers, U.S. prosecutors say that, defendant “SUN” — short for Sun Kailiang — “sent spearphishing e-mails purporting to be from two U.S. Steel e-mail accounts to approximately eight U.S. Steel employees, including U.S. Steel’s Chief Executive Officer.
 
“The e-mails had the subject line “US Steel Industry Outlook” and contained a link to malware that, once clicked, would surreptitiously install malware on the recipients’ computers, allowing the co-conspirators backdoor access to the company’s computers,” the indictment said.

“Further...an unidentified co-conspirator sent approximately 49 spearphishing e-mails to U.S. Steel employees with the same subject, “US Steel Industry Outlook,” according to the indictment.
 
But it didn’t stop with basic spearphishing.
 
Researcher Auty said successful social engineering hacks often require more than just bad emails.
 
And the indictment lays out another, more sophisticated attack strategy that required much greater planning, research and patience.
 
Persistence over technology
 
Throughout the document, the Justice Department describes how the defendants would first try to gain lists of current and former employees at each of the six targeted companies and then went about researching who they were.
 
The defendants then went about purchasing a variety of web site domain names, such as ‘arrowservice.net’ or ‘hugesoft.org’ (readers are advised NOT to visit these sites) and populating them both with content that appeared legitimate, but also contained hidden Trojan-horse malware.
 
These websites both served to create an appearance of trust and also to serve as “hop-points” between the infected computers and the main attack servers in China to coordinate and control all the malware-infected computers in the U.S.
 
In the indictment, attorneys detail how these hop-points could surreptitiously allow the hackers to grab documents and “exfiltrate” — a computer term that basically means stealing — the data back to China.
 
As the indictment put it: “Between intrusions, the co-conspirators used the domain accounts to reassign the malicious domain names to non-routable or innocuous IP addresses, (e.g., IP addresses for popular webmail services, like Gmail or Yahoo), which would obscure any beacons their malware sent during that period.”
 
“Bad guys want my stuff”
 
Technologically speaking, it wasn’t anywhere near the sophistication of something like the Stuxnet virus.

But for sheer persistence and imagination, it was quite a clever operation.
 
“People need to realize: the bad guys are persistent, they’re organized,” said Stephen Cobb, a senior security researcher at the cyber security firm ESET North America. “Maybe this would help: it’s not an individual who’s trying to break into your web server every five seconds.”
 
“Let’s face it: every company today has information on their computers that they need to protect,” Cobb said. “If you’ve got a website, there’s an attempt to break into it every five, six seconds. It’s automated programs.

"So people from all around the world who want to get into somebody else’s computer are running automated script looking for holes," he said. "There’s a constant probing of systems.”
 
Still, it’s hard for most people to understand cyber security, analysts say.
 
“If you work for a bank, you should be fairly aware that people might want to rob you, that’s where the money is,” Cobb said. “But if you’re a doctor, or an engineer designing a product, you’re not necessarily thinking ‘there are bad guys who want my stuff.’‘”
 
But security expert Auty said that’s not a cause to lose hope.
 
“People will always be a weak element, but given that organizations have learnt to harden their perimeter, the next area of improvement required within the industry is ensuring internal visibility and appropriate segregation,” he said.
 
For both Auty and Cobb, the segregation of data into specific areas with different levels of security is key.
 
“You can’t protect what you don’t know about,” Cobb told VOA. “One of the very first things on my list for remediation or security programs for small business or big business is know what you’ve got.”

Doug Bernard

dbjohnson+voanews.com

Doug Bernard covers cyber-issues for VOA, focusing on Internet privacy, security and censorship circumvention. Previously he edited VOA’s “Digital Frontiers” blog, produced the “Daily Download” webcast and hosted “Talk to America”, for which he won the International Presenter of the Year award from the Association for International Broadcasting. He began his career at Michigan Public Radio, and has contributed to "The New York Times," the "Christian Science Monitor," SPIN and NPR, among others. You can follow him @dfrontiers.

You May Like

Tired of Waiting, South Africans Demand Change ‘Now’

With chronic poverty and lack of basic services largely fueling recent xenophobic attacks, many in Rainbow Nation say it’s time for government to act More

Challenges Ahead for China's Development Plans in Pakistan

Planned $46 billion in energy and infrastructure investments in Pakistan are aimed at transforming the country into a regional hub for trade and investment More

Audio 'Forbidden City' Revisits Little Known Era of Asian-American Entertainment

Little-known chapter of entertainment history captured in 80s documentary is revisited in new digitally remastered format and book More

This forum has been closed.
Comment Sorting
Comments
     
by: TheSaucyMugwump from: saucymugwump.blogspot.com
May 25, 2014 6:23 PM
Corporations are being hacked by both Chinese and Russians, with the former doing it for corporate espionage and the latter doing it for personal loot. Corporations today are only concerned with reducing costs and maximizing the salaries of CEOs and other corporate officers. Target and eBay outsourced a large part of their IT function and got burned.

There is a preventative measure for phishing: before clicking on links in emails, hover the mouse over the link (but don't click on it) and read the URL in the bottom-left corner of the screen. If the URL is not what you expect, report the email as spam. It is amazing how few articles mention this simple trick.

by: Anonymot from: Boston
May 25, 2014 11:13 AM
Wow! Sic 'em. They're doing what NSA & CIA are doing and we are supposed to have a global monopoly on hacking for governmental usage, both commercial for American corporate use as well "intelligence".

It makes no sense to allow these dangerous , skilled competitors wander freely around our electronic fairs. Perhaps we should bar ALL Chinese from entering and expel those who are here who may know too much - and Japanese, too (& Indians, Pakistanis, etc.) We don't really need any other smart people in the world. We suffice.

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Study: Insecticide Damaging Wild Bee Populationsi
X
April 24, 2015 10:13 PM
A popular but controversial type of insecticide is damaging important wild bee populations, according to a new study. VOA’s Steve Baragona has more.
Video

Video Study: Insecticide Damaging Wild Bee Populations

A popular but controversial type of insecticide is damaging important wild bee populations, according to a new study. VOA’s Steve Baragona has more.
Video

Video Data Servers Could Heat Private Homes

As every computer owner knows, when their machines run a complex program they get pretty hot. In fact, cooling the processors can be expensive, especially when you're dealing with huge banks of computer servers. But what if that energy could heat private homes? VOA’s George Putic reports that a Dutch energy firm aims to do just that.
Video

Video Cinema That Crosses Borders Showcased at Tribeca Film Festival

Among the nearly 100 feature length films being shown at this year’s Tribeca Film Festival in New York City are more than 20 documentaries and features with international appeal, from a film about a Congolese businessman in China, to documentaries shot in Pakistan and diaspora communities in the U.S., to a poetic look at disaffected South African youth. VOA’s Carolyn Weaver has more.
Video

Video UN Confronts Threat of Young Radicals

The radicalization and recruitment of young people into Islamist extremist groups has become a growing challenge for governments worldwide. On Thursday, the U.N. Security Council heard from experts on the issue, which has become a potent threat to international peace and security. VOA’s Margaret Besheer reports.
Video

Video Growing Numbers of Turks Discover Armenian Ancestry

In a climate of improved tolerance, growing numbers of people in Turkey are discovering their grandmothers were Armenian. Hundreds of thousands of Armenians escaped the mass deportations and slaughter of the early 1900's by forced conversion to Islam. Or, Armenian children were taken in by Turkish families and assimilated. Now their stories are increasingly being heard. Dorian Jones reports from Istanbul that the revelations are viewed as an important step.
Video

Video Migrants Trek Through Western Balkans to Reach EU

Migrants from Africa and other places are finding different routes into the European Union in search of a better life. The Associated Press followed one clandestine group to document their trek through the western Balkans to Hungary. Zlatica Hoke reports that the migrants started using that route about four years ago. Since then, it has become the second-most popular path into Western Europe, after the option of sailing from North Africa to Italy.
Video

Video TIME Magazine Honors Activists, Pioneers Seen as Influential

TIME Magazine has released its list of celebrities, leaders and activists, whom it deems the world’s “most influential” in 2015. VOA's Ramon Taylor reports from New York.
Video

Video US Businesses See Cuba as New Frontier

The Obama administration's opening toward Cuba is giving U.S. companies hope they'll be able to do business in Cuba despite the continuation of the U.S. economic embargo against the communist nation. Some American companies have been able to export some products to Cuba, but the recent lifting of Cuba's terrorism designation could relax other restrictions. As VOA's Daniela Schrier reports, corporate heavy hitters are lining up to head across the Florida Straits - though experts urge caution.
Video

Video Kenya Launches Police Recruitment Drive After Terror Attacks

Kenya launched a major police recruitment drive this week as part of a large-scale effort to boost security following a recent spate of terror attacks. VOA’s Gabe Joselow reports that allegations of corruption in the process are raising old concerns about the integrity of Kenya’s security forces.
Video

Video Japan, China in Race for Asia High-Speed Rail Projects

A lucrative competition is underway in Asia for billions of dollars in high-speed rail projects. Cambodia, India, Indonesia, Malaysia Thailand and Vietnam are among the countries planning to move onto the fast track. They are negotiating with Japan and the upstart Chinese who are locked in a duel to revolutionize transportation across Asia. VOA Correspondent Steve Herman in Bangkok has details.
Video

Video Scientists: Mosquitoes Attracted By Our Genes

Some people always seem to get bitten by mosquitoes more than others. Now, scientists have proved that is really the case - and they say it’s all because of genes. It’s hoped the research might lead to new preventative treatments for diseases like malaria, as Henry Ridgwell reports from London.
Video

Video Bible Museum Coming to Washington DC

Washington is the center of American political power and also home to some of the nation’s most visited museums. A new one that will showcase the Bible has skeptics questioning the motives of its conservative Christian funders. VOA religion correspondent Jerome Socolovsky reports.
Video

Video Armenia and Politics of Word 'Genocide'

A century ago this April, hundreds of thousands of Armenians of the Turkish Ottoman empire were deported and massacred, and their culture erased from their traditional lands. While broadly accepted by the U.N. and at least 20 countries as “genocide”, the United States and Turkey have resisted using that word to describe the atrocities that stretched from 1915 to 1923. But Armenians have never forgotten.
Video

Video Afghan First Lady Pledges No Roll Back on Women's Rights

Afghan First Lady Rula Ghani, named one of Time's 100 Most Influential, says women should take part in talks with Taliban. VOA's Rokhsar Azamee has more from Kabul.
Video

Video New Brain Mapping Techniques Could Ease Chronic Pain

From Boulder, Colorado, Shelley Schlender reports that new methods for mapping pain in the brain are providing validation for chronic pain and might someday guide better treatment.

VOA Blogs