|
The hacker group that attacked Google Inc in 2009 has launched hundreds of other cyber assaults since then, focusing on U.S. defense companies and human rights groups, according to new research from security software maker Symantec Corp.
Google said in January 2010 that it and more than 20 other companies were the victims of a sophisticated cyber attack - later dubbed Operation Aurora - from China-based hackers that resulted in the theft of intellectual property.
Although the hackers were never publicly identified, the incident heightened tensions between Washington and Beijing over growing evidence that a significant number of cyber attacks against U.S. institutions originated from China.
![]() Symantec reveals more information about Operation Aurora (Image credit: The Daily Caller)
"It was big news at the time, but what people don't realize is that this is happening constantly," said Eric Chien, a manager in Symantec's research group. "They haven't gone away, and we wouldn't expect them to go away."
Symantec said on Friday the hackers behind Operation Aurora have focused on stealing intellectual property, such as design documents from defense contractors and their suppliers, including shipping, aeronautics, arms, energy, manufacturing, engineering and electronics companies.
The hackers used components of a common infrastructure that Symantec termed the "Elderwood Platform," named after a word repeatedly found in the software code used in different attacks.
Over the past year, the Elderwood hackers have focused almost exclusively on stealing data from companies that supply parts to big defense contractors, rather than targeting the firms themselves, Chien said.
The second most common group of targets was non-government organizations involved in Tibetan human rights issues. Financial firms and software companies were also targeted, Symantec said.
The security firm, which sells anti-virus software to corporations and consumers under the Symantec and Norton brands, declined to identify specific victims and noted that it did not have evidence to prove the attacks originated from China.
Cyber security experts widely believe the Google attacks originated from China.
Dmitri Alperovitch, chief technology officer of security startup CrowdStrike, said his firm has linked the culprits to more recent attacks, including ones last year on EMC Corp's RSA Security division and Lockheed Martin Corp.
The hackers infected personal computers by exploiting what were major security flaws in commonly used software from Adobe Systems Inc and Microsoft Corp. Such flaws, known as zero-day vulnerabilities, are rare because they are difficult to find. The flaws have since been fixed.
Last year, security experts uncovered eight zero-day flaws being exploited by various hacking groups, according to Symantec.
Symantec said it believed the Elderwood hackers alone have used eight zero-day vulnerabilities from 2010 to 2012 - the largest number it has seen from a single organization. That suggests the group had the money to hire large teams of skilled software engineers or purchase them.
Some experts estimate that a zero-day vulnerability that enables attackers to hack into highly secured systems can cost hundreds of thousands of dollars, even more than $1 million.
The fact that the Elderwood hackers has used so many zero-day vulnerabilities suggests it is either a very large criminal group, or backed by a nation-state, or a nation-state itself, Chien said.
Reuters |
Tags: Google Inc , Google , Cyber attacks , hacks , Hacking , hackers , Operation Aurora , Chinese based hackers , Symantec , Elderwood Platform , anti-virus software , Adobe systems
SPOTLIGHT
Samsung Galaxy S4 Active specs leaked in...
19 May, 2013, 05:16 PM
Top news this week: Nexus 4 launched,...
19 May, 2013, 04:24 PM
Tumblr’s porn content may cause Yahoo...
19 May, 2013, 03:53 PM
Is Samsung 'mentally enslaving' Indian smartphone buyers...
17 May, 2013, 07:51 PM IST
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
17 May, 2013, 01:09 PM IST
tech2 live: The latest from Google I/O 2013
16 May, 2013, 01:56 PM IST
MouthShut.com petitions SC to protect freedom of expression and quash
09 May, 2013, 07:01 PM IST
No arrests over objectionable posts on social sites without senior...
16 May, 2013, 03:17 PM IST
Top news this week: Nexus 4 launched, Google I/O highlights, Windows 8.1 announced and more!
19 May, 2013, 04:24 PM
Kerala engineer claims creation of new 'anti-piracy hardware'
19 May, 2013, 01:20 PM
India to launch indigenous IRNSS navigation satellite system on June 12
19 May, 2013, 01:19 PM
Your Aadhaar card hasn’t reached you yet? Download e-Aadhaar
To avoid all the hassle and with a view to make it convenient for...
We have 5 tech gift ideas that will help you find a gift that will...
5 Websites to create custom t-shirts
If you are bored of wearing the run-of-the-mill t-shirts, then you can...
Samsung Galaxy S4 Active specs leaked in benchmark scores
Sriram Iyer
Sun May 19, 18:35:34
UP govt gives away free HP laptops to 10,000 students
Ashish Awasthi
Sun May 19, 18:30:22
Samsung Galaxy S II Plus: A specifications review
Abdullah Abro
Sun May 19, 14:22:44
Samsung Galaxy S4 Active specs leaked in...
HTC One production capacity improving,...
World's first 8-inch Windows 8 tablet
Microsoft reportedly launching 7.9-inch...
Next-gen Xbox more than a console for...
Adult video streaming service SugarDVD...


















reddit

Mixx
Facebook
Twitter
Digg
delicious
MySpace















