Showing posts with label Chinese Hackers. Show all posts
Showing posts with label Chinese Hackers. Show all posts

Saturday, 10 October 2015

China Arrests Hackers At The Request Of United States



Chinese authorities have arrested at the request of the US government several hackers allegedly broke into US companies. In addition, business secrets were stolen for the purpose by which Chinese enterprises play, so the reports Washington Post.

The arrests were made ​​two weeks before the visit of Chinese President Xi to be the USA, as is now known. Earlier, Susan Rice, National Security Advisor of the United States, announced that cyber espionage by China really had to stop. During his visit, Xi showed that China is not engaged in cyber espionage, and he wants to join forces with the US. In recent weeks, US intelligence and investigation agencies made ​​a list of hackers who were sought.

The list was then given to the Chinese authorities that led to the arrests of a handful of individuals. US officials are now wondering whether the Chinese authorities will prosecute the hackers. Earlier this week, the Financial Times said that the US authorities had three Chinese companies identified that have benefited in the past from cyber espionage. Something that denied two of the three companies.

Wednesday, 5 August 2015

Chinese VPN Service Uses Windows Servers Hacked



A commercial service that Chinese customers VPN connections offering appears to use dozens of hacked Windows servers of organizations and companies abroad, so claims the American security company RSA published today in a report ( pdf ).

The VPN service, which is called by RSA only by the codename "Terracotta", consists of more than 1,500 nodes worldwide.With a Virtual Private Network (VPN) make users through a secure tunnel connection to another server, for example to access the internet from there. This way, the ISP can not view the contents of the traffic, and it is possible to, for example, censored still visit web sites. The Chinese VPN service is thus offered as a way to bypass the firewall and Chinese as a way for users to protect their anonymity.

VPN services generally use their own servers where clients connect to it. In the case of going to the Terra Cotta according to RSA, inter alia, to hacked Windows-based servers from a variety of organizations. RSA researchers argue that the number of new servers from the VPN service will be expanded continuously. In addition, the attackers deliberately opt for Windows servers, because the platform includes VPN services can be configured quickly. A total of 31 Windows servers hacked discovered which were part of the VPN service. All were found to be hacked servers linked to the Internet, and did not use any hardware firewall.

Attack

To take over the servers are brute-force attacks against the administrator account. In case a working combination of username and password is found, the switch forwards a few hours later, the Windows firewall and install the Telnet service.After this, the attackers log in via Remote Desktop and then removing Windows Defender. The next step is the installation of a remote administration tool and create a new Windows account.

Finally the hacked server is configured for VPN service. According to RSA make both end users and cyber spies of the VPN service usage, which is offered in China under different names. In addition, users would not know that they are making use of hacked servers. The reason that the service servers of foreign organizations hacks would mostly related to cost savings.

Sunday, 14 June 2015

Hack US Government Possibly Worse Than Thought


The US government agency that attackers late last year for a second time managed to break in and possibly the data of millions of officials spoils were very likely also sensitive private data stolen by which officials could be extorted.

The Office of Personnel Management runs a system called e-QIP, where federal officials can apply for security clearances. It should be introduced all sorts of very personal information ( pdf ), including financial data. Research now shows that these sensitive data may be stolen. It would be forms that officials must fill highly personal information, such as mental health problems, drug and alcohol use, arrests by police and bankruptcies. Also have names of acquaintances and contacts are being completed, and the social security number.

In a statement allows the White House that researchers have found that with a "very high degree of certainty" the systems for the background checks of current, former and future officers used are compromised and data is stolen, reports the Associated Press . As with the first report of the burglary researchers have no hard evidence that the data are actually captured.

Saturday, 6 June 2015

US Officials Stole Millions Of Data Possible


Attackers are late last year managed to break into a US government agency and have thereby allow the data from about 4 million civil servants stolen, let the Office of Personnel Management (OPM) themselves know . The hack at the OPM took place last December.

Earlier in 2014 knew attackers even though at the same public body to strike . The last burglary was discovered in April this year, after the OPM for the first break-in last March had boosted security and had rolled out various network tools. The Office of Personnel Management runs a system called e-QIP, where federal officials can apply for security clearances. It should be introduced all kinds of highly personal information, including financial data.

In addition, officials who have security clearances to update their personal information via the website. Information from the OPM would, for example spear phishing attacks can be used. Who is behind the attack is still unknown, although the FBI suspects it comes to Chinese hackers, so let sources across the Washington Post know. Whether the attackers actually been able to steal data is unknown. The OPM speaks for itself that the "possible" happened. However, all 4 million civil servants will be warned next week.

Sunday, 3 May 2015

Successful Chinese Hacking Team Is Looking For Math Nerds


A Chinese hacking team that in recent years during various competitions hacker vulnerabilities in popular software such as Adobe Flash Player, Windows 8.1, Apple Safari and Mac OS X Mavericks discovered is particularly looking for mathematical geniuses who are also "real geeks" are.

The Keen Team consists of over twenty highly talented hackers, although the leader himself does not mention that. "We call ourselves geeks, not hackers, because we do not want people to think we are invaders who want to destroy things," said the 37-year-old CEO Wang Qi in front of Vice Magazine . It is the first time that Chinese hackers do an interview in English.

Income

The Pwn2Own hacker contests deserved members of Keen Team tens of thousands of dollars. Yet the prize is not their main source of income. The hackers are hired by parties like Microsoft and Google to find vulnerabilities in software. How many employees earn Wang would not say, but he describes the prize of the Pwn2Own hacker contests as a nice pocket money.The CEO pointed Keen Team in 2011, before that he worked for Microsoft.

According to Wang, the standards Keen Team employs more than Microsoft's. "They should be as high as any computer or phone is touched by our research." In finding new hackers main focus is on math. Some of the members are winners of international math competitions. The best students from Chinese schools are also selected.

"You have real nerds need for this kind of work:. Who have no friends and no life but first we need to know your character and morality, you can not use your talents for criminal matters If you have a criminal past, we will not.. take. " Keen Team members are between 20 and 40 years old and all man. "Maybe it's because women do not like playing with hardware. And maybe they can not stand the loneliness," Wang noted.

Method

What exactly are hackers proceed will not tell the CEO, but the core consists of writing programs that automatically search for vulnerabilities, also known as fuzzing. "It's not that we endlessly looking at code and find vulnerabilities in our eyes," Lu Juhui adds. He managed to earn during the recent Pwn2Own contest with his exploits tens of thousands of dollars. Despite the automated portion of the hackers make their hours. Lu works in their own words twelve hours a day.

Monday, 13 April 2015

Southeast Asia: State Cyber Spies Operate Ten Years Undetected


For a decade, spying a group of hackers governments and companies in Southeast Asia and India. According to one report, China is said to have instructed the snooping.

In 2005, the group of hackers APT would have 30 started successfully spy on government and economic institutions in Southeast Asia and India. These have targeted political, economic and military information the attacker. In the course of journalists came into the focus of hackers. That's according to a report of IT security firm FireEye , which shines through the operation of APT 30. Responsible for Cyber ​​espionage is China, the researchers suggest.

The security researchers from FireEye have analyzed over 200 spy tools and software for planning the attacks, monitoring of targets and execution of the attacks. The tools were tailored according FireEye with clearly defined objectives. A derivative of espionage tools have successfully hidden on infected computers before anti-virus programs.

Attacked first computer behind an Air Gap

In the wake of the attacks it was the hacker group also managed to penetrate into independent, non-affiliated security reasons with the Internet company networks, as a descendant of espionage tools has spread through removable media. The infiltration of computers behind an Air Gap succeeded APT 30 FireEye According back in 2006 - the first such attacks were documented in 2008.

In order to sneak on target computers, put the hacker group on phishing e-mails with supposedly important documents in the appendix. Opened an employee a file, an espionage tool that searched the computer for relevant information and related documents sent secretly to the attackers installed.

The assumption on the part of FireEye that China is behind the espionage activities, based on the evaluation of the goals. Among other journalists were monitored, reported on the Chinese dissident movement. In addition, the graphical user interface of attack planning software was written in Chinese and also the spy tools reported Chinese terms on.

Monday, 19 January 2015

Chinese Cyber Spies Were Joint Strike Fighter (JSF) Secrets Booty


China would have used cyber espionage to steal all kinds of secret information on the Joint Strike Fighter (JSF). This is evident from documents leaked by whistleblower Edward Snowden. According to an NSA presentation where the German newspaper Der Spiegel and the Sydney Morning Herald reports about Chinese cyber spies would "teraybytes" to sensitive military information JSF have captured.


Among the stolen design details are information on the radar systems of the JSF and detailed designs of the motor and methods for cooling the exhaust gases. In 2013, an advisory board of the US government had proposed a confidential report that JSF secrets were stolen by the Chinese. Last year, an expert claimed that the details of the JSF in a Chinese fighter jet appeared.

Besides information on the JSF would also sensitive details about the B-2 stealth bomber and F-22 Raptor fighter jet were stolen, as well as a nuclear submarine and missile designs. The amount of data stolen is estimated at 50 terabytes. However, the documents also show that the NSA and intelligence services of the "Five Eyes" by Chinese intelligence services have broken and access to computers have obtained senior Chinese military officials.