Security researcher IDs China link in Google hack
The code behind the attack, called Aurora, was written in 2006
IDG News Service - The malicious software used to steal information from Google Inc. and other companies contains code that links it to China, a security researcher said Tuesday
After examining the backdoor Hydraq Trojan used in the hack, SecureWorks Inc. researcher Joe Stewart found that it used an unusual algorithm to check for data corruption when it transmits information. The source code for this algorithm "only seems to be found on Chinese Web sites, which suggests that the person who wrote it reads Chinese," Stewart said.
That may be an important hint. Because while Google has implied that the people who hacked its computers had the support of the People's Republic of China, company executives have admitted that they have no proof.
Google has threatened to pull out of China, in part because of the cyberattack.
According to Stewart's firm, aside from the fact that some of the servers used in the attack were hosted in China, there had previously been no evidence of a China link. Because the attackers could have purchased or hacked into hosting services in China, simply linking the command-and-control servers to China is inconclusive.
The code behind the attack, called Aurora, was written in 2006. But apparently it was rarely used, which helped it evade detection by antivirus programs for several years. The Hydraq Trojan -- just one element of all of the Aurora software the security firms have found -- dates back to April 2009, Stewart said. Google learned of the attack in December and quickly notified other affected companies.
Like other Trojans, Hydraq gives the attackers ways of running commands on the computers they hack. With it, hackers can do things such as list directories and read and search files, Stewart said.
Stewart, who earns his living analyzing malicious code, says he has never seen this particular data-checking algorithm used anywhere else except with Hydraq.
Whoever is behind Aurora is known to have hit 34 companies, but researchers suspect that there may be many more victims.
Web giants attacked
- White House orders security review in wake of WikiLeaks disclosure
- Leaked U.S. document links China to Google attack
- Update: Researchers track cyber-espionage ring to China
- Google, China now playing cat and mouse?
- McAfee: 'Amateur' malware not used in Google attacks
- Military warns of 'increasingly active' cyber-threat from China
- China: Google 'totally wrong' to stop censoring
- Update: Google stops censoring in China
- Google's China ad partners wait in 'incomparable pain'
- Google may soon leave China, reports say
- 18 Hot IT Certifications for 2014
- CIOs Opting for IT Contractors Over Hiring Full-Time Staff
- 12 Best Free iOS 7 Holiday Shopping Apps
- For CMOs Big Data Can Lead to Big Profits
- Slideshow: 5 ways to lock down your mobile device
- Slideshow: 10 mistakes companies make after a data breach
- How to rob a bank: A social engineering walk through
- Which smartphone is the most secure?
If you think getting it right from day one is always what matters, you probably haven't been following technology too closely.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Mitigating DDoS Attacks with F5 Technology
- This document examines various DDoS attack methods and the application of specific ADC technologies to block attacks in the DDoS threat spectrum while...
- The DDoS Threat Spectrum
- Bolstered by favorable economics, today's global botnets are using distributed denial-of-service (DDoS) attacks to target firewalls, web services, and applications, often simultaneously.
- Defending Against Denial of Service Attacks
- By utilizing end-user interviews, this whitepaper explores a deeper understanding of DDoS defense plans and reveals the knowledge gaps around the Denial of...
- Strategic Solutions for Government IT
- This paper outlines why F5 is the optimum partner to help achieve the levels of security, performance and availability that are vital to...
- Osterman White Paper: The Need for Enterprise-Grade File Transfer
- Key trends in file transfer All Government IT White Papers
- Modernizing SAP environments with minimum risk - a path to Big Data Hear from top IDC analyst, Richard Villars, about the path you can start taking now to enable your organization to get the benefits...
- The Power of the Citrix Mobility Solution, XenMobile Does everything become a smartphone? Or does the smartphone begin to do everything? How can we afford to support BYOD? Rather, how can...
- BYOD Happens: How to Secure Mobility How to navigate the journey of securing mobility, including the BYOD corruption of IT, the top ten mobility strategies, and the mobility management...
- Fighting Fraud Videos: IBM Intelligent Investigation Manager Short videos about IBM Intelligent Investigation Manager (IIM) for Fraud. IIM optimizes the investigation of fraud for customers across many industries in both...
- IBM Intelligent Investigation Manager: Online Product Demo Intelligent Investigation Manager optimizes fraud investigation and analysis and it dynamically coordinates and reports on cases, provides analysis and visualization, and enables more...
- All Government IT Webcasts
Does your organization offer extensive benefits, cool perks, competitive salaries, opportunities for training and advancement? Then get it recognized!
Nominate your company or another deserving organization for Computerworld's 2014 Best Places to Work in IT list now through Dec. 20, 2013.