Google China spat shines spotlight on cyberspying
Related articles
Cyber attacks disclosed by Google and Adobe that may lead Google to quit China highlight a sophisticated type of bespoke cyberspying that could be more widespread than previously thought.
Google, the world's top search engine, said on Tuesday it might shut down its Chinese site, Google.cn, after an attack on its infrastructure it believed was primarily aimed at accessing the Google mail accounts of Chinese human rights activists.
Unlike ordinary viruses that are released into cyberspace and quickly spread from computer to computer, the type of attack launched against Google and at least 20 other companies were likely handcrafted uniquely for each targeted organization.
Such attacks, most often delivered using Adobe PDF documents sent by e-mail, secretly deposit a software file on a user's hard drive allowing the computer to be remotely accessed. Typically, top personnel with access to high-level information are targeted with such software, known as malware.
Since each organization is hit with a malware that looks different from malware delivered to others, companies cannot detect samples spreading around the globe and protect themselves as they normally would, security experts say.
"Attacks like this are very hard to block and very hard to filter," says Mikko Hypponen, chief research officer at security software maker F-Secure, who has been monitoring such attacks against Chinese human-rights activists since 2005.
The fact that this kind of malware can easily sit in computers undetected, potentially forever, also means the true number of such hacking attempts is hard to estimate.
"I don't think they're very unusual at all. I think they're very usual - that's the problem," says John Walker, a professor in cyber-crime at the Nottingham Trent University and chief technology officer of security software adviser Secure-Bastion.
Google said it had found that at least 20 other companies had been targeted in attacks originating from China, and that it was in the process of notifying them.
Adobe, which makes the popular Acrobat, Flash and Photoshop software including the PDF format often used by hackers, said on Wednesday its computer-network systems had been attacked, but no sensitive information was stolen.
Hypponen said the logical explanation was that hackers wanted to gain access to Adobe's development systems to better exploit PDF vulnerabilities.
Cyber security firm iDefense said that according to its sources, the attack on Google bore similarities to a July 2009 attack in which about 100 information technology-focused companies were targeted with e-mail campaigns using PDF files.
"It is possible that the two attacks are one and the same, and that the organizations targeted in the Silicon Valley attacks have been compromised since July," it said.
In September, a coordinated cyberattack on the Chinese assistants of foreign news agencies contained malware that also exploited an Adobe Acrobat vulnerability.
Other companies targeted in the latest attacks did not immediately come forward.
Microsoft, which has recently launched a Chinese version of its much-hyped new search engine Bing, said in a statement: "We have no indication that any of our mail properties have been compromised."
Life & Style blogs
Million pound investment to bring Liverpool homes back into use
Dozens of empty homes in two of Liverpool’s most deprived areas will be brought back into use thanks...
London renters are getting poorer and moving further out
Plus, do energy saving measures boost house prices?
Travel Shop
- 1 Serena Williams apologises after comment that rape victim 'shouldn't have put herself in that position'
- 2 Disability campaigners celebrate 'victory' after government rethink over plans to make it more difficult to claim disability benefits
- 3 Bankers could face jail after report urges the Government to introduce new criminal offence for reckless management
- 4 Breaking the Silence: In the reality of occupation, there are no Palestinian civilians – only potential terrorists
- 5 We never knew Nigella Lawson - and we still don’t
How will you make today delicious?
Tell us how you plan to make today delicious and you could win a £50 M&S gift card.
Win a Nook® Simple Touch eReader
Find out how Nook® is supporting the Evening Standard's Get Reading campaign - and your chance to win one.
Free reading festival for families
Follow The Standard's campaign to get London's children reading - and experience this unique event at Trafalgar Square on 13 July.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
iJobs Gadgets & Tech
Java Developer
£200 - £250 per day: Progressive Recruitment: Java Developer - Urgent Requirem...
SAP Consultant MM/WM
£40000 - £47000 per annum + BENEFITS : Progressive Recruitment: Sap Consultant...
SAP PP
£45000 - £60000 per annum: Progressive Recruitment: SAP PP functional consulta...
Change Manager,Hampshire,Telecomms,SC Clear,£200PD
Negotiable: Orgtel: Change Manager, Hampshire, Telecomms, SC Cleared, £200 per...
First night: The Cripple of Inishmaan
Scandi-geeks descend on Nordicana for fan-convention
Female aristocrats battle to inherit the title








Comments