Subscribe free to our newsletters via your
. Military Space News .




CYBER WARS
FireEye report: Chinese hackers target foreign ministries
by Staff Writers
Beijing (UPI) Dec 13, 2013


disclaimer: image is for illustration purposes only

Cybersecurity company FireEye claims Chinese hackers broke into the computer systems of five European foreign ministries over the summer.

The hackers sent emails with malware attachments purporting to detail a possible U.S. intervention in Syria, the BBC reported.

Nine computers were compromised, the company told the BBC.

The company hasn't revealed which ministries were targeted but said the malware was meant for individuals involved in last summer's Group of 20 talks in St. Petersburg attended by senior government leaders.

A main topic of discussion among the leaders was the Syrian crisis.

FireEye's 23-page report, available on its website, calls the cyber espionage campaign "Ke3chang" where hackers sent out emails that advertised information updates about the Syrian crisis.

"We believe that the Ke3chang attackers are operating out of China and have been active since at least 2010," the report said.

"However, we believe specific Syria-themed attacks against foreign affairs ministries -- codenamed by Ke3chang as 'moviestar' -- began only in August 2013. The timing of the attacks precedes a G20 meeting held in Russia that focused on the crisis in Syria."

FireEye researchers said they were able to monitor one of the Hackers' computer servers for one week.

"When they [the hackers] shift infrastructure, the servers are open. I just happened to check the servers when they weren't secured," senior FireEye researcher Narottama Villeneuve told the BBC.

The report says FireEye "gained visibility into one of 23 known command-and-control servers operated by the Ke3chang actor for about a week. During this time, we discovered 21 compromised machines connecting to the CnC server."

Researchers observed what "appeared to be three administrative tests by the attackers and two connections from other malware researchers."

Among the targets, FireEye said it identified nine compromises at government ministries in five European countries. Eight of these compromises were at ministries of foreign affairs.

"When FireEye had visibility on the CnC server, we saw the attackers engage in post-compromise information-gathering and lateral movement on the target network whereupon FireEye immediately contacted the relevant authorities and began the notification process.

"At that stage, it appeared to be about network reconnaissance," Villeneuve told the BBC. "The hackers were based in China, but it is difficult to determine from a technology point of view how or if it is connected to a nation state," Villeneuve said.

During the week the malware was observed in action, no documents were stolen.

The report by FireEye, based in Milpitas, Calif., comes amid growing Western concern over fears of increasing attacks by Chinese hackers -- some allegedly with government approval or direction.

The Australian government said in May it won't dump its nearly completed spy agency headquarters in Canberra and start building over again, despite allegations Chinese Internet hackers stole the building's blueprints.

Australian Broadcasting Corp.'s investigative program "Four Corners" reported Chinese hackers managed to get into files of top secret detailed blueprints.

The plans reportedly showed details of complex electrical and electronic cabling, security and communications systems as well as floor plans for the headquarters of the Australian Security Intelligence Organization, the Australian reported.

U.S. Defense Secretary Chuck Hagel, on his first trip after taking up the post, publicly rebuked China in June for its alleged cyberespionage operations.

The Voice of America reported Hagel called for China to work with the United States to establish a cyberspace code of conduct.

"The United States has expressed our concerns about the growing threat of cyberintrusions, some of which appear to be tied to the Chinese government and military," Hagel said in a speech to officials of several Asia-Pacific nations gathered for an annual security summit at Singapore's Shangri-La Hotel.

Setting up a joint cyber working group would be "a positive step in fostering U.S.-China dialogue on cyber," he said.

"We are determined to work more vigorously with China and other partners to establish international norms of responsible behavior in cyberspace."

The Chinese government continues to deny any connection to alleged cyberattacks.

.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle








CYBER WARS
Raytheon BBN Technologies and GrammaTech collaborate to help U.S. government prevent malware in IT devices
Boston MA (SPX) Dec 17, 2013
Raytheon BBN Technologies and GrammaTech, Inc. are collaborating on a $4.8 million contract award under the Defense Advanced Research Projects Agency's VET program. Raytheon BBN Technologies is a wholly owned subsidiary of Raytheon. The VET (Vetting Commodity IT Software and Firmware) program seeks to help U.S. government agencies address the threat of malicious code and hidden "backdoor" ... read more


CYBER WARS
Iran nuclear accord means NATO missile defence unnecessary: Russia

IBCS Completes US Army Integrated Air and Missile Defense Demonstration

Patriot performance excels in PAC-3 test firing

Israel moves closer to missile defense shield

CYBER WARS
US to cut funding on Turkish Chinese-missile purchase

Merrill Lynch rejects Turkey role over China missile plans: report

Turkey says no new bids to rival China missile offer

Kongsberg seals Penguin missile deal with New Zealand

CYBER WARS
Northrop starts production of Global Hawk UAS for NATO

Pentagon chief talks drones with Pakistan PM

Northrop Grumman Begins On-Time Production of First NATO Global Hawk

U.S. responding to Gulf states push for UAV systems

CYBER WARS
US Navy Accepts MUOS-2 Satellite, Ground Stations After On-Orbit Testing

Boeing Tests Validate Performance of FAB-T Satellite Communications Program

Intelsat General To Provide Satellite Services To US Marines

Manpack Radios in Arctic Connect with MUOS Satellites Orbiting Equator

CYBER WARS
U.S. Army holds online development event

Financial groups pour billions into cluster bomb trade: NGO

Less than 90 days: how US will destroy Syria chemical weapons

Switzerland, Austria seek U.S. Foreign Military Sales deals

CYBER WARS
EADS vows to limit redundancies in jobs cull

EADS details restructuring effect on jobs

EADS to cut 5,800 jobs in Europe in restructuring

Russia indicts former defence minister

CYBER WARS
Beyond Obama-Castro handshake, Cuban reconciliation takes shape

Japan looks for ASEAN backing on China at summit

Japan to boost military amid row with China

White House dismisses critics over Obama-Castro handshake

CYBER WARS
Scientists scale terahertz peaks in nanotubes

Berkeley Lab Researchers Discover Nanoscale Shape-Memory Oxide

Laser light at useful wavelengths from semiconductor nanowires

Stanford engineers show how to optimize carbon nanotube arrays for use in hot spots




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement