Forty-nine of the 72 compromised organizations were in the United States: the attack was dubbed "Operation Shady RAT" (no, not THAT rat).
UN, US targets of major cyber spying campaign: report WASHINGTON — Over 70 organizations including the United Nations and major US defense groups have been targets of a global cyber spying effort, according to security firm McAfee, with analysts pointing to China as the culprit, the Washington Post said Wednesday.
Targets for the intrusions -- identified from logs tracked to a single server -- included computer networks of the United Nations secretariat, a US Energy Department lab, and some dozen US defense firms, said the McAfee report to be released Wednesday, according to the Post.
The snooping appeared to have been ongoing for several years.
The report identified 72 compromised organizations in all, 49 of which were located in the United States, said the Post.
Intruders, according to the McAfee report, sought sensitive data on US military systems and satellite communications, among other prizes.
Cybersecurity experts told the Post that China was the most likely culprit, as much of the intruders' targets listed by McAfee put emphasis on organizations linked to Taiwan and the International Olympic Committee (IOC) in months leading up to the 2008 Beijing games.
However McAfee, a leader in the cyber security industry, tracking network intrusions around the world, did not openly blame Beijing.
See also:
Report identifies widespread cyber-spying
(Reuters) - Hackers breached the computer networks of 72 organizations around the world over a five-year period, in the biggest hacking campaign discovered to date, security firm McAfee said on Wednesday.
Q. Who are the victims?
A. They include:
- Governments of Canada, India, South Korea, Taiwan, United States and Vietnam.
- International bodies such as the United Nations, the Association of Southeast Asian Nations (ASEAN), the International Olympic Committee, the World Anti-Doping Agency.
- 12 U.S. defense contractors, 1 U.K. defense contractor.
- Companies in construction, steel, energy, solar power, technology, satellite communications, accounting and media.
- Other groups ranging from a U.S. insurance association to the Nevada county government and think tanks.
McAfee declined to identify many of the victims by name.
Q. When and how did the attacks take place?
A. McAfee found evidence of security breaches dating back to mid-2006, but said the hacking might have begun well before that. Some of the attacks lasted just a month, others stretched to as many as 28 months.
The hackers sent so-called spear-phishing emails, which are tainted with malicious software, to specific people at the targeted organizations. When the unsuspecting individual clicks on an infected link, it allows intruders to jump on to the machine and use it to infiltrate the computer network.
Q. What information was stolen?
A. McAfee investigators have done their best to guess what was likely stolen, based on interviews with a number of victims. McAfee Vice President of Threat Research Dmitri Alperovitch said the attacker sought data that would give it military, diplomatic and economic advantage.
"If you look at an industry and think about what is most valuable in terms of intellectual property, that is what they were going after," Alperovitch said. As examples, he cited email archives, negotiation documents and schematics for electronics.
Q. Who did it?
A. McAfee's Alperovitch said he believes that a nation state was behind the attacks, but he declined to identify it. He said the attacker is the same country that was behind other security breaches that McAfee has previously investigated.
Jim Lewis, an expert in cyber attacks with the Center for Strategic and International Studies, was briefed by McAfee. Lewis said the presence of Taiwan and the International Olympic Committee in the victims list suggest China is most likely the perpetrator of the attack.
Q. How valuable is the data that was stolen?
A. "This is the biggest transfer of wealth in terms of intellectual property in history," Alperovitch said. "The scale at which this is occurring is really, really frightening."
"Companies and government agencies are getting raped and pillaged every day. They are losing economic advantage and national secrets to unscrupulous competitors," he said.
Q. How did McAfee learn of these attacks?
A. While investigating some attacks against defense contractors, McAfee researchers found a "command and control" server in 2009 used to manage the campaign. In March of this year, they returned to that computer and found logs that revealed all of the attacks.
McAfee is typically unable to discuss its investigations because of non-disclosure agreements. The company was able to discuss Operation Shady RAT because it was not bound by any confidentiality agreements in this case.
Q. What does the "RAT" in Operation Shady RAT stand for?
A. RAT stands for "remote access tool," a type of software that hackers and security professionals often use to access computer networks from afar.
http://www.reuters.com/article/2011/...7720IS20110803