News / Asia

China's Cyber Espionage Case a Guide to Hacking

Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
The alleged hacking of U.S. corporate computers by elements of China’s military wasn’t in and of itself all that unique.
 
As cyber attacks go, it was moderately sophisticated in technique.
 
But that raises a more troubling question.
 
How could major international corporations — such as U.S. Steel, Alcoa and others with millions of dollars of intellectual property — get robbed by a small, low-cost group of hackers working from China?
 
The answer: It’s surprising it doesn’t happen more often.
 
Over its 48 pages and 31 counts of criminal misconduct, the U.S. Justice Department’s indictment details how five Chinese army officers, with Internet identities such as “Ugly Gorilla”, “Kandygoo” and “WinXYHappy,” went about infiltrating computer networks of six large U.S. corporations.
 
Sections of the indictment are so detailed that they read like a primer, a virtual "how-to manual" for anyone interested in how hackers do what they do.
 
Social engineering
 
While some of the terms such as “spearphishing,” “beacon” or “hop-points” may need a little technical explaining, it’s clear from the indictment that the defendants generally employed something security analysts call social engineering.
 
In essence, social engineering is a tactic where hackers pretend to be somebody else to try and trick the target into trusting them.
 
The aim is getting them to reveal information directly (such as a password) or infect their computers by clicking on malicious links and attachments. Social engineering, in the end, is just a fancy label for little more than a con job.
 
There are many different tricks a hacker might employ to earn their target’s trust.

But once they have it, it’s relatively easy to fool unsuspecting targets into releasing sensitive information.
 
A common example: if someone you believe is a trusted co-worker sends you an email urgently asking for a password they’ve forgotten, you’re probably much more likely to send it to them without thinking twice than someone you don’t know, analysts say.
 
“Given that these types of attacks can be attempted with very little consequence if they don't succeed,” said Mike Auty, senior security researcher at the firm MWR Infosecurity,

“It allows the attacker to launch a number of attacks, over a long period of time, and the chances are high that there will be a mistake, and someone will grant them access,” he said.
 
Which, as the indictment details, is  what the Chinese are alleged to have done.
 
One particular social engineering trick allegedly used by the defendants was “spearphishing” — sending links or attachments via email that, if clicked, would infect the target’s computer system without them knowing.
 
Once infected, the malware would create what’s called a “back door” or secret entrance into the system that could likely go undetected for prolonged periods.
 
In the recent indictment papers, U.S. prosecutors say that, defendant “SUN” — short for Sun Kailiang — “sent spearphishing e-mails purporting to be from two U.S. Steel e-mail accounts to approximately eight U.S. Steel employees, including U.S. Steel’s Chief Executive Officer.
 
“The e-mails had the subject line “US Steel Industry Outlook” and contained a link to malware that, once clicked, would surreptitiously install malware on the recipients’ computers, allowing the co-conspirators backdoor access to the company’s computers,” the indictment said.

“Further...an unidentified co-conspirator sent approximately 49 spearphishing e-mails to U.S. Steel employees with the same subject, “US Steel Industry Outlook,” according to the indictment.
 
But it didn’t stop with basic spearphishing.
 
Researcher Auty said successful social engineering hacks often require more than just bad emails.
 
And the indictment lays out another, more sophisticated attack strategy that required much greater planning, research and patience.
 
Persistence over technology
 
Throughout the document, the Justice Department describes how the defendants would first try to gain lists of current and former employees at each of the six targeted companies and then went about researching who they were.
 
The defendants then went about purchasing a variety of web site domain names, such as ‘arrowservice.net’ or ‘hugesoft.org’ (readers are advised NOT to visit these sites) and populating them both with content that appeared legitimate, but also contained hidden Trojan-horse malware.
 
These websites both served to create an appearance of trust and also to serve as “hop-points” between the infected computers and the main attack servers in China to coordinate and control all the malware-infected computers in the U.S.
 
In the indictment, attorneys detail how these hop-points could surreptitiously allow the hackers to grab documents and “exfiltrate” — a computer term that basically means stealing — the data back to China.
 
As the indictment put it: “Between intrusions, the co-conspirators used the domain accounts to reassign the malicious domain names to non-routable or innocuous IP addresses, (e.g., IP addresses for popular webmail services, like Gmail or Yahoo), which would obscure any beacons their malware sent during that period.”
 
“Bad guys want my stuff”
 
Technologically speaking, it wasn’t anywhere near the sophistication of something like the Stuxnet virus.

But for sheer persistence and imagination, it was quite a clever operation.
 
“People need to realize: the bad guys are persistent, they’re organized,” said Stephen Cobb, a senior security researcher at the cyber security firm ESET North America. “Maybe this would help: it’s not an individual who’s trying to break into your web server every five seconds.”
 
“Let’s face it: every company today has information on their computers that they need to protect,” Cobb said. “If you’ve got a website, there’s an attempt to break into it every five, six seconds. It’s automated programs.

"So people from all around the world who want to get into somebody else’s computer are running automated script looking for holes," he said. "There’s a constant probing of systems.”
 
Still, it’s hard for most people to understand cyber security, analysts say.
 
“If you work for a bank, you should be fairly aware that people might want to rob you, that’s where the money is,” Cobb said. “But if you’re a doctor, or an engineer designing a product, you’re not necessarily thinking ‘there are bad guys who want my stuff.’‘”
 
But security expert Auty said that’s not a cause to lose hope.
 
“People will always be a weak element, but given that organizations have learnt to harden their perimeter, the next area of improvement required within the industry is ensuring internal visibility and appropriate segregation,” he said.
 
For both Auty and Cobb, the segregation of data into specific areas with different levels of security is key.
 
“You can’t protect what you don’t know about,” Cobb told VOA. “One of the very first things on my list for remediation or security programs for small business or big business is know what you’ve got.”

Doug Bernard

dbjohnson+voanews.com

Doug Bernard covers cyber-issues for VOA, focusing on Internet privacy, security and censorship circumvention. Previously he edited VOA’s “Digital Frontiers” blog, produced the “Daily Download” webcast and hosted “Talk to America”, for which he won the International Presenter of the Year award from the Association for International Broadcasting. He began his career at Michigan Public Radio, and has contributed to "The New York Times," the "Christian Science Monitor," SPIN and NPR, among others. You can follow him @dfrontiers.

You May Like

Lion Cecil's Killing Sparks 'Canned Hunting' Debate in S. Africa

Conservationists believe incident, which triggered worldwide outrage, will reshape debate about practice in which hunters are allowed to target animals bred for hunting More

Taliban's New Leader Says Jihad Will Continue

Top US Afghan diplomat also meets with Pakistani, Afghan officials following news of Mullah Omar's death More

Environmentalists Issue Warning on Mekong Biodiversity

Scientists say decades of economic development, hydropower-dam construction, lax law enforcement and trafficking have taken their toll More

This forum has been closed.
Comment Sorting
Comments
     
by: TheSaucyMugwump from: saucymugwump.blogspot.com
May 25, 2014 6:23 PM
Corporations are being hacked by both Chinese and Russians, with the former doing it for corporate espionage and the latter doing it for personal loot. Corporations today are only concerned with reducing costs and maximizing the salaries of CEOs and other corporate officers. Target and eBay outsourced a large part of their IT function and got burned.

There is a preventative measure for phishing: before clicking on links in emails, hover the mouse over the link (but don't click on it) and read the URL in the bottom-left corner of the screen. If the URL is not what you expect, report the email as spam. It is amazing how few articles mention this simple trick.

by: Anonymot from: Boston
May 25, 2014 11:13 AM
Wow! Sic 'em. They're doing what NSA & CIA are doing and we are supposed to have a global monopoly on hacking for governmental usage, both commercial for American corporate use as well "intelligence".

It makes no sense to allow these dangerous , skilled competitors wander freely around our electronic fairs. Perhaps we should bar ALL Chinese from entering and expel those who are here who may know too much - and Japanese, too (& Indians, Pakistanis, etc.) We don't really need any other smart people in the world. We suffice.

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Astronauts Train Underwater for Deep Space Missionsi
|| 0:00:00
...    
🔇
X
George Putic
July 30, 2015 8:59 PM
Manned deep space missions are still a long way off, but space agencies are already testing procedures, equipment and human stamina for operations in extreme environment conditions. Small groups of astronauts take turns in spending days in an underwater lab, off Florida’s southern coast, simulating future missions to some remote world. VOA’s George Putic reports.
Video

Video Astronauts Train Underwater for Deep Space Missions

Manned deep space missions are still a long way off, but space agencies are already testing procedures, equipment and human stamina for operations in extreme environment conditions. Small groups of astronauts take turns in spending days in an underwater lab, off Florida’s southern coast, simulating future missions to some remote world. VOA’s George Putic reports.
Video

Video Civil Rights Leaders Struggled to Achieve Voting Rights Act

Fifty years ago, lawmakers approved, and U.S. President Lyndon Johnson signed, the Voting Rights Act of 1965. The measure outlawed racial discrimination in voting, giving millions of blacks in many parts of the southern United States federal enforcement of the right to vote. Correspondent Chris Simkins introduces us to some civil rights leaders who were on the front lines in the struggle for voting rights.
Video

Video Booming London Property a ‘Haven for Dirty Money’

Billions of dollars of so-called ‘dirty money’ from the proceeds of crime - especially from Russia - are being laundered through the London property market, according to anti-corruption activists. As Henry Ridgwell reports from the British capital, the government has pledged to crack down on the practice.
Video

Video Hometown of Boy Scouts of America Founder Reacts to Gay Leader Decision

Ottawa, Illinois, is the hometown of W.D. Boyce, who founded the Boy Scouts of America in 1910. In Ottawa, where Scouting remains an important part of the legacy of the community, the end of the organization's ban on openly gay adult leaders was seen as inevitable. VOA's Kane Farabaugh reports.
Video

Video 'Metal Muscles' Flex a New Bionic Hand

Artificial limbs, including the most complex of them – the human hand – are getting more life-like and useful due to constant advances in tiny hydraulic, pneumatic and electric motors called actuators. But now, as VOA’s George Putic reports, scientists in Germany say the future of the prosthetic hand may lie not in motors but in wires that can ‘remember’ their shape.
Video

Video Russia Accused of Abusing Interpol to Pursue Opponents

A British pro-democracy group has accused Russia of abusing the global law enforcement agency Interpol by requesting the arrest and extradition of political opponents. A new report by the group notes such requests can mean the accused are unable to travel and are often unable to open bank accounts. VOA's Henry Ridgwell reports.
Video

Video 'Positive Atmosphere' Points Toward TPP Trade Deal in Hawaii

Talks on a major new trade agreement among 12 Pacific Rim nations are said to be nearing completion in Hawaii. Some trade experts say the "positive atmosphere" at the discussions could mean a deal is within reach, but there is still hard bargaining to be done over many issues and products, including U.S. drugs and Japanese rice. VOA's Jim Randle reports.
Video

Video Genome Initiative Urgently Moves to Freeze DNA Before Species Go Extinct

Earth is in the midst of its sixth mass extinction. The last such event was caused by an asteroid 66 million years ago. It killed off the dinosaurs and practically everything else. So scientists are in a race against time to classify the estimated 11 million species alive today. So far only 2 million are described by science, and researchers are worried many will disappear before they even have a name. VOA’s Rosanne Skirble reports.
Video

Video Scientists: One-Dose Malaria Cure is Possible

Scientists have long been trying to develop an effective protection and cure for malaria - one of the deadliest diseases that affects people in tropical areas, especially children. As the World Health Organization announces plans to begin clinical trials of a promising new vaccine, scientists in South Africa report that they too are at an important threshold. George Putic reports, they are testing a compound that could be a single-dose cure for malaria.
Video

Video 'New York' Magazine Features 35 Cosby Accusers

The latest issue of 'New York' magazine features 35 women who say they were drugged and raped by film and television celebrity Bill Cosby. The women are aged from 44 to 80 and come from different walks of life and races. The magazine interviewed each of them separately, but Zlatica Hoke reports their stories are similar.
Video

Video US Calls Fight Against Human Trafficking a Must Win

The United States is promising not to give up its fight against what Secretary of State John Kerry calls the “scourge” of modern slavery. Officials released the country’s annual human trafficking report Monday – a report that’s being met with some criticism. VOA’s National Security correspondent Jeff Seldin has more from the State Department.
Video

Video Washington DC Underground Streetcar Station to Become Arts Venue

Abandoned more than 50 years ago, the underground streetcar station in Washington D.C.’s historic DuPont Circle district is about to be reborn. The plan calls for turning the spacious underground platforms - once meant to be a transportation hub, - into a unique space for art exhibitions, presentations, concerts and even a film set. Roman Mamonov has more from beneath the streets of the U.S. capital. Joy Wagner narrates his report.
Video

Video Europe’s Twin Crises Collide in Greece as Migrant Numbers Soar

Greece has replaced Italy as the main gateway for migrants into Europe, with more than 100,000 arrivals in the first six months of 2015. Many want to move further into Europe and escape Greece’s economic crisis, but they face widespread dangers on the journey overland through the Balkans. VOA's Henry Ridgwell reports.
Video

Video Stink Intensifies as Lebanon’s Trash Crisis Continues

After the closure of a major rubbish dump a week ago, the streets of Beirut are filling up with trash. Having failed to draw up a plan B, politicians are struggling to deal with the problem. John Owens has more for VOA from Beirut.
Video

Video Paris Rolls Out Blueprint to Fight Climate Change

A U.N. climate conference in December aims to produce an ambitious agreement to fight heat-trapping greenhouse gases. But many local governments are not waiting, and have drafted their own climate action plans. That’s the case with Paris — which is getting special attention, since it’s hosting the climate summit. Lisa Bryant takes a look for VOA at the transformation of the French capital into an eco-city.

VOA Blogs