Showing posts with label Chinese Hackers. Show all posts
Showing posts with label Chinese Hackers. Show all posts

Tuesday, 19 February 2013

Hackers Attack US traced to Chinese military unit in Shanghai

Hackers Attack U.S traced to Chinese military unit in Shanghai.
Black-hat hacker cyber attacks on U.S resultant of stole massive amount of sensitive information from U.S military contractors  energy companies and some major industry in the U.S. The really strange came in track back of hackers. Trace stop at doorstep of Chinese Military announced by U.S security firm alleged on Tuesday  China totally rejected that report and consider it Groundless.


This is not 1st time that U.S accused China on Hacking. The report by Virginia-based Mandiant Corp. contains some of the most extensive and detailed accusations to date linking its military to a wave of cyberspying against U.S. and other foreign companies and government agencies.

News of the report spread Tuesday on the Chinese Internet, with many commentators calling it an excuse for the U.S. to impose greater restrictions to contain China's growing technological prowess.

Ref: Link

Tuesday, 31 July 2012

Power failure Across India, Hit by Malware Attack

India’s Northern power grid crashed on Monday morning wreaking havoc at airports, railway and metro stations, hospitals and across traffic congested roads, its worst power outage in a decade.

Indian power infrastructure under attack: India losing out millions in just hours same snag developed within just 24 hours of recovery reports say the system is infected by sophisticated malware.
Malware is spreading; today more than 67 crore people are without power. Cyber analysts suspect "PAK"- CHINA nexus behind this attack.


 Hundreds of millions of people have been left without electricity in northern and eastern India after a massive power breakdown.

There are some analyst saying that it is cyber Attack by a Malware but no Indian Authorities confirmed it yet. Authorities are restoring the service suggest the whole thing is out of their skills, meanwhile mainstream media has been barred from reporting as this could bring disgrace to security services of India.

Since the first power trip up on Monday, there have been discussions within the security establishment about the possibility of entities trying to carry out a sophisticated cyber-attack to cripple the grids.

Officials who carried out an audit of critical information infrastructure admit it is "theoretically possible" to cripple India's power grids through a cyber-attack.


Despite such a possibility, the shutdown did not seem to have led to a crisis management procedure that aimed at ruling out or confirming a cyber-attack.

"Given the fact that our grids are vulnerable to a cyber-attack, those responsible for managing grids should have a proactive policy to rule out cyber-attack as part of their crisis management procedures," a senior official said. "But none of it was visible," he added.

Sources aware of contacts among power ministry, power grid authorities and those in both CERT-IN ( Computer Emergency Response Team-India) and NTRO (National Technical Research Organisation) say there was no proactive effort by those responsible for power grids.

However, both CERT-IN and NTRO are believed to have established their own procedures to ensure the shutdowns were not a cyber-attack, having been brought on by massive over-the-limit withdrawals by states to supply electricity for pumps tapping groundwater in the absence of rainfall during this monsoon.

Officials said the government is now discussing possible ways to speed up the setting up of National Critical Information Infrastructure Protection Centre (NCIPC), which would act as the command and control centre for monitoring the critical information infrastructure of the country. NCIPC was recently approved by the National Security Council headed by the Prime Minster.

Sources said the government is also planning to hold a national consultation of all stakeholders involved in critical information infrastructure.

The government is already setting up dedicated CERT-INs for various critical sectors such as power and civil aviation.

Officials point out to breaches reported from power grids in the US, cyber intrusion into the Iranian nuclear network and other such incidents around the world to warn that India needs to have a more robust crisis management procedure that includes proactive ruling out of cyber-attacks.

European Cyber Security at the Mercy of Chinese Hackers


Europe is “Under the watchful eye of Chinese pirates”, writes Libération,which picks up on a Bloomberg feature report on computer security breaches. The American press agency reveals that a group of Chinese cyberspies – which has been tracked by an American collective (that includes academics, companies that have been targeted by Chinese espionage and computer security experts) – succeeded in infiltrating a large number of institutions and companies last year.


The group  linked to the Chinese military, which has been named “Byzantine Candor” by American secret services, notably managed to infiltrate European institutions, reports the French daily –

    At a critical moment in the euro crisis in July, a group of Chinese spies remotely infiltrated the computers of the European Council, not once but five times. Launching their attacks from China, the hackers stole data including email correspondence with Herman Van Rompuy [...] Along with the European Council, the networks of at least 20 European businesses have fallen victim to Byzantine Candor [...] According to Bloomberg, most of the breached corporate networks were characterised by the fact that they contained information on innovation that could be economically advantageous to Chinese firms.

Libération adds that a decade ago –

    … the usual targets for these kinds of attacks were American arms manufacturers [...] However, no one is safe today.

As a result, the drive to combat cyber-espionage is now a critical priority for Europe: notably in Spain, which, according to El País –

    … is one of the countries that has been worst affected by hacking attacks, with tens of thousands of incidents every year.

The Madrid daily explains that a new national cybersecurity centre of excellence, financed by the European Commission and headquartered at the Autonomous University of Madrid, will be inaugurated in September. In the wake of the establishment of similar centres in Montpellier (France) and Dublin (Ireland), it will be the third of its kind in the EU.

However, the daily regrets that one of the companies tasked with the creation of the centre, CFLabs, is directed by Matías Bevilacqua –

    … an IT expert who was arrested and charged in connection with purchase and sale of confidential data [...] and in particular sensitive information sourced from virtually all of the institutions of the Spanish state.

In conclusion El País wonders about the wisdom of appointing “a hacker to play a key role in such a sensitive project”.

Sunday, 29 July 2012

Anonymous Rattles A Chinese Web Giant

Anonymous may be best known for knocking websites offline or stealing data, but one faction of the movement is subverting figures of power in a more circumspect way — by trawling through documents and computer code.

The sub group Anonymous Analytics released a damning report yesterday about Qihoo, the Chinese web giant that claims to be the No. 1 provider of Internet and mobile security products and services in China, as measured by its user base.


Qihoo distributes antivirus software called 360 Safeguard and has a browser called 360 Secure Browser, but in recent years has restructured it business to focus on selling online advertising space, in particular from a single directory page, hao.360.cn. The company claims to get approximately 90% of its advertising revenue “directly or indirectly” from this page and its sub pages; advertising accounted for 73% of the company’s total revenue in 2011 of $22.9 million.

That figure marked an increase of 136% from the year before, meaning hao.360.cn is a serious money-maker for Qihoo. Qihoo recently said that it charged, on average, 1 million yuan  ($156,000) per month, per link on the “Famous Sites” section of its directory page — a breed of e-commerce widely known to have dwindled in Western cyberspace.

Anonymous Analytics says there’s something fishy about Qihoo’s directory page. Qihoo recently claimed on its fourth quarter conference call that the page was getting 20% more web traffic than dominant-player Baidu’s similar page and its sub pages, hao123.com. Qihoo confirmed this with me, citing a table of figures from iResearch.

But the Anonymous group claims that Qihoo is “grotesquely exaggerating” its traffic advantage, and their evidence comes in the form of a recent change in the source code of hao.360.cn. Having been monitoring the site since last year, the group noticed that a comScore tag had been added to Qihoo’s HTML source code. (ComScore is the best-known, third-party verifier of a web site’s traffic.)

This seemed fine, until the tag was removed on or around June 20, 2012. Why? Anonymous Analytics thinks that Qihoo didn’t like the figures it was seeing. The group then managed to get what it claims are the actual comScore figures through unnamed third parties — “people we trust,” according to the group’s representative — who had bought them from comScore. The figures show that in the months of February, March and April 2012, Qihoo’s all-important directory page had 56%, 51% and 52% less traffic than Baidu’s.

Anonymous Analytics provided me with what appears to be a legitimate document from comScore showing web traffic figures for Baidu and Qihoo’s main directory pages in April 2012. It states that Baidu’s directory page had 84.689 million unique visitors from China, while Qihoo’s had 40.877 million.

The activist group believes that before Qihoo balked at the figures, it had added the comScore tag to appease analysts, investors and critics, “who have called for management to provide independent verification of Qihoo’s traffic claims.”

The group further believes that management installed the tag with a view figuring out how to manipulate comScore’s traffic analytics. “We are so certain of this that we invite engineers at comScore to analyze data coming out of hao.360.cn since the beginning of the year,” Anonymous Analytics says.

Tuesday, 3 July 2012

Chinese hackers sink the Indian Navy systems


Chinese hackers have managed to take out the computer system on the Indian Navy's Eastern Command.
The hackers planted malware on the system, which is based around the city of Visakhaptnam, which sent sensitive data to IP addresses in China.
The Indian Express reported how India's first nuclear missile submarine, INS Arihant, was running trials at the facility and might have got the bug.
The virus had reportedly created a hidden folder, collected specific files and documents based on certain "key words" it had been programmed to identify.

It remained hidden on the pen drives until they were put in computers connected to the internet, after which the bug quietly sent files to the specific IP addresses.
It is not clear how much was taken in the hacking raid, or if the malware operated like Stuxnet and needed to be installed within the system by a spook first.
So far, India has arrested six officers for procedural lapses which led to the breach. It is not clear if any of them will later face spying charges.
India's navy stores sensitive data in standalone computers which are not connected to the web. However, they are also not supposed to have ports or access points for flash drives or external storage devices.

Reference: Link1