Tampilkan postingan dengan label china. Tampilkan semua postingan
Tampilkan postingan dengan label china. Tampilkan semua postingan

Kamis, 23 Februari 2012

Smartphone security gap exposes location, texts, email, expert says


latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

Dmitri Alperovitch, the former McAfee cyber security researcher who is best known for identifying a widespread China-based cyber espionage operation he dubbed "Shady Rat," has used a previously unknown hole in smartphone browsers to deliver an existing piece of China-based malware that can commandeer the device, record its calls, pinpoint its location and access user texts and emails. He conducted the experiment on a phone running Google's Android operating system, although he says Apple's iPhones are equally vulnerable.
"It's a much more powerful attack vector than just getting into someone's computer," said Alperovich, who just formed a new security company, called Crowdstrike, with former McAfee chief technology officer George Kutz.
Alperovich, who has consulted with the U.S. intelligence community, is scheduled to demonstrate his findings Feb. 29 at the RSA conference in San Francisco, an annual cyber security gathering. The Shady Rat attack he disclosed last year targeted 72 government and corporate entities for as long as five years, siphoning off unknown volumes of confidential material to a server in China.

Kamis, 16 Februari 2012

Chinese Telecoms May Be Spying on Large Numbers of Foreign Customers

theatlantic.com
A U.S. Congressional probe is investigating whether China's state-linked firms, which built much of the communications infrastructure in several Asian countries, is using its access for snooping.

Two Chinese telecommunications giants are under scrutiny by a US congressional committee. The outcome of the probe could have revealing implications for Central Asian states, which have used these companies to modernize their telecom sectors.
US legislators have expressed concern that Huawei and ZTE act as front companies for the Chinese government, and represent a grave "cyber-security threat." The chairman of the House Permanent Select Committee on Intelligence, Michigan Republican Mike Rogers, asserted during a congressional hearing last October that China is engaged in the "brazen and wide-scale theft of intellectual property from foreign commercial competitors."
"Attributing this espionage isn't easy, but talk to any private sector cyber analyst, and they will tell you there is little doubt that this is a massive campaign being conducted by the Chinese government," he added.

More...

Selasa, 14 Februari 2012

Traveling Light in a Time of Digital Thievery

Note: Having recently traveled to China, I can attest to Mr. Lieberthal's concerns....Do yourself (and your company) a favor, Just accept the fact that you "will" be collected against...and take Mr. Lieberthal's advice...very seriously.  JDL

nytimes.com

SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.
He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”
What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.


More...

Senin, 26 Desember 2011

U.S. Headed For Cyberwar Showdown With China In 2012

forbes
The new year is likely to bring a distinct shift in U.S. national security priorities, as the Obama Administration and Congress sharpen their response to China’s continuous assault on U.S. information networks.  Although intelligence-community analysts believe the most sophisticated intrusions are being executed by a relatively small number of agents linked to the general staff of China’s Peoples Liberation Army, the damage they are inflicting on U.S. security and economic competitiveness is judged to be extensive.

Thus far, China’s cyber campaign consists mainly of espionage aimed at stealing military secrets and intellectual property.  However, Gen. Keith Alexander, head of the Pentagon’s joint Cyber Command established to counter such campaigns, said in November that, “We see a disturbing track from exploitation to disruption to destruction.”  Alexander wasn’t talking just about the Chinese, but there’s little doubt among intelligence analysts that Beijing is the biggest and most persistent perpetrator of cyber crimes.
The question is what to do about it.  To date, U.S. cyber efforts have been focused mainly on defensive measures, seeking to repel network intruders in a fashion that Alexander likens to the famously failed Maginot Line.  The National Security Agency and other U.S. security organizations are known to have developed their own network-attack capabilities, but former White House cyber-security advisor Richard Clarke has warned that it would be dangerous for the U.S. to step up its own campaign against Chinese networks while U.S. safeguards against retaliation are so weak.

Rabu, 21 Desember 2011

Chinese Computer Hackers Hit U.S. Chamber of Commerce

foxnews


A group of hackers in China breached the computer defenses of America's top business-lobbying group and gained access to everything stored on its systems, including information about its three million members, according to several people familiar with the matter.
The break-in at the U.S. Chamber of Commerce is one of the boldest known infiltrations in what has become a regular confrontation between U.S. companies and Chinese hackers. The complex operation, which involved at least 300 internet addresses, was discovered and quietly shut down in May 2010.
It isn't clear how much of the compromised data was viewed by the hackers. Chamber officials say internal investigators found evidence that hackers had focused on four Chamber employees who worked on Asia policy, and that six weeks of their email had been stolen.

It is possible the hackers had access to the network for more than a year before the breach was uncovered, according to two people familiar with the Chamber's internal investigation.
One of these people said the group behind the break-in is one that U.S. officials suspect of having ties to the Chinese government. The Chamber learned of the break-in when the FBI told the group that servers in China were stealing its information, this person said. The FBI declined to comment on the matter.
A spokesman for the Chinese Embassy in Washington, Geng Shuang, said cyberattacks are prohibited by Chinese law and China itself is a victim of attacks. He said the allegation that the attack against the Chamber originated in China "lacks proof and evidence and is irresponsible," adding that the hacking issue shouldn't be "politicized."


More...

Chinese hackers hit Boston Scientific

massdevice.com
Boston Scientific is one of 760 firms hit by China-based cyber attacks.
Med-tech titan Boston Scientific (NYSE:BSX) was one of 760 companies hit by Chinese cyber attacks that also targeted U.S. government agencies, research universities and Internet providers.
It's not clear whether the Natick, Mass.-based medical device maker lost any sensitive information in the attack.
"We're talking about stealing entire industries," Scott Borg, director of the U.S. Cyber Consequences Unit, told the news service. "This may be the biggest transfer of wealth in a short period of time that the world has ever seen."
The attacks were aimed at the medical device, biotechnology, clean energy, advanced semiconductor, high-end manufacturing and information technology industries, according toBloomberg
Along with BSX, Abbott Laboratories (NYSE:ABT) and pharmaceutical giant Pfizer's (NYSE:PFE) Wyeth subsidiary were victims. The Chinese government is denying responsibility for the attacks.
The cyber-warfare is just the latest item in a string of bad luck for Boston Scientific, which got hit with a half-billion-dollar tax bill from the U.S. Internal Revenue Service last week.
The latest tab, for $581 million plus interest and penalties, comes out of an IRS audit of Boston Scientific's 2006 acquisition of pacemaker firm Guidant Corp.

Sabtu, 17 Desember 2011

China ‘Incredibly Aggressive’ in Cyber Theft

cnbc.com
China is stealing online information from the United States and feeding the data to homegrown companies for commercial benefit, Michael Hayden, Former Director of the Central Intelligence Agency said at the Black Hat Technical Security Conference in Abu Dhabi on Wednesday.

He pointed out that as an intelligence officer, he was "impressed" with the sophistication of Chinese cyber espionage, although spying in cyber space is an activity that all states, including the United States, take part in.
According to Hayden, "We steal secrets, you bet. But we steal secrets that are essential for American security and safety. We don't steal secrets for American commerce, for American profit. There are many other countries in the world that do not so self limit."
Despite the difficulty in tracing the origins of cyber attacks, Hayden believes China is the culprit behind various incidents of data theft.
"The body of evidence makes me quite comfortable and confident in saying that there's an incredibly large amount of this cyber activity coming from China," he told CNBC on the sidelines of the conference.
The retired general, who also served as the Director of the National Security Agency, added that, "I have come to the conclusion that the Chinese, the Chinese state and others in China are incredibly aggressive in the cyber domain, when it comes to the theft of property: state on state or against commercial targets."

Kamis, 03 November 2011

U.S. Calls Out China and Russia for Cyber Espionage Costing Billions

foxnews


Hey, China and Russia, get off of our clouds.
That's the warning from a new U.S. national intelligence director's report to Congress released Thursday that states China and Russia are the biggest perpetrators of economic espionage through the Internet. 
The report, Foreign Spies Stealing U.S. Economic Secrets in Cyberspace, also warns that the efforts to calculate the cost of lost research and development is nearly impossible to calculate but could be costing up to $398 billion. As mobile devices proliferate, it's only going to get easier for spies to steal.


Analysts note that this is the first time the U.S. government report has so openly blamed countries that support cyber attacks and espionage at the national and state level.
"The computer networks of a broad array of U.S. government agencies, private companies,
universities, and other institutions -- all holding large volumes of sensitive economic information -- were targeted by cyber espionage; much of this activity appears to have originated in China," reads the report.
Drawing on data from 13 agencies, including the CIA and FBI, over the past two years, the report concludes that attacks against U.S. government networks and military contracts are on the rise. But one of the most worrying trends is the growing number of attacks on businesses that are smaller than the Fortune 500 companies.
Additionally, the report states that China's intelligence services -- as well as private companies and other entities -- are exploiting Chinese citizens or others with family ties in China who have "insider access to corporate networks to steal trade secrets using removable media devices or e-mail."



More...

Note: Worried about Cyber Espionage? Contact us, we can help. ~JDL

Senin, 31 Oktober 2011

Cyber spy campaign targets chemical industry: Symantec

(AFP)
SAN FRANCISCO — US Internet security firm Symantec on Monday exposed a cyber spying campaign targeting trade secrets at top chemical firms and linked the industrial espionage to a man in China.
At least 48 companies, including some that make advanced materials for military vehicles, were targeted in a campaign Symantec dubbed "Nitro" given the type of information at risk.
"Attacks on the chemical industry are merely their latest attack wave," Symantec security response team members Eric Chien and Gavin O'Gorman said in a report released on Monday.
The attacks targeted NGOs supporting human rights from late April to early May before switching to the motor industry, according to the report.
Major chemical firms, mainly in the United States, Britain, and Bangladesh, came under fire by cyber spies from late July to mid September, Symantec said.
Nitro was aimed at stealing intellectual property for competitive advantage, according to Chien and O'Gorman.
Attackers researched firms, sending selected workers booby-trapped emails that, once opened, secretly infected computers with malicious "Poison Ivy" software designed to steal information.
While various ruses were used to trick workers into opening email attachments to unleash spy software in machines, a typical pretext was to fake a meeting invitation from an established business partner.
Another tactic used by cyber spies was to send employees email purporting to be a security software update that needed to be installed in computers, according to Symantec.
Poison Ivy code was written by a Chinese speaker and Nitro attacks were traced to a server located in the United States but owned by a "20-something male" in the Hebei region of China, the report said.

Minggu, 23 Oktober 2011

FBI: Tech firms face spy risk

democratandchronicle.com


Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.


A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.

And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation. "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."

Chili's Sydor Optics played host as the FBI spent a handful of hours talking about counterintelligence and economic espionage issues, with handouts and a video presentation all revolving around the message that companies are under siege by foreign economic competitors, often with explicit help from foreign governments.

Optics in particular "is a targeted industry," said FBI special agent Chad Kaestle. Other frequently targeted technologies include sensors, aeronautics and marine systems.

Minggu, 02 Oktober 2011

Business travelers should be on alert for cyber-spying

dailyherald.com

Packing for business in China? Bring your passport and business cards, but maybe not that laptop loaded with contacts and corporate memos.

China’s massive market beckons to American businesses — the nation is the United States’ second-largest trading partner — but many are increasingly concerned about working amid electronic surveillance that is sophisticated and pervasive.


Security experts also warn about Russia, Israel and even France, which in the 1990s reportedly bugged first-class airplane cabins to capture business travelers’ conversations. Many other countries, including the United States, spy on one another for national security purposes.

But China’s brazen use of cyber-espionage stands out because the focus is often corporate, part of a broader government strategy to help develop the country’s economy, according to experts who advise American businesses and government agencies.

“I’ve been told that if you use an iPhone or BlackBerry, everything on it — contacts, calendar, emails — can be downloaded in a second. All it takes is someone sitting near you on a subway waiting for you to turn it on, and they’ve got it,” said Kenneth Lieberthal, a former senior White House official for Asia who is at the Brookings Institution.


More...


Rabu, 21 September 2011

Cyber spying is the new face of espionage

cbc.ca

'When we do trace [cyber espionage] back to China, the Chinese put the blame on a rogue group of hackers — they're very careful to make sure it never gets traced back to intelligence or defence sources.'
—Christian Leuprecht, Royal Military College of Canada

When many people think of espionage, the image that readily comes to mind is of the furtive spy, clad in black, taking photographs of secret dossiers with a camera disguised as a cigarette lighter. It's an image that seems quaint and dated, especially since the end of the Cold War. But the recent controversy surrounding Conservative MP Bob Dechert's flirtatious email exchanges with a Chinese journalist remind Canadians that the threat of international espionage did not vanish with the fall of the Iron Curtain.

If anything, the threat to Canadian secrets has strengthened in recent years and is something the federal government is fighting on a daily basis.

Christian Leuprecht, an associate professor of political science at the Royal Military College of Canada in Kingston, says the Dechert case represents a textbook example of international espionage.

"It is an active, long-standing intelligence tradition to use journalists, because it's easy to place them on temporary assignment somewhere for a period of time," he said. Journalists ask questions, meet people, learn things. "There seems to be something more to the story than meets the eye." But although they are still used, the need for such field operatives is declining in the online age.

More...

Selasa, 23 Agustus 2011

Chinese Military TV Show Reveals More Than Intended

theepochtimes.com



A standard, even boring, piece of Chinese military propaganda screened in mid-July included what must have been an unintended but nevertheless damaging revelation: shots from a computer screen showing a Chinese military university is engaged in cyberwarfare against entities in the United States.



The documentary itself was otherwise meant as praise to the wisdom and judgment of Chinese military strategists, and a typical condemnation of the United States as an implacable aggressor in the cyber-realm. But the fleeting shots of an apparent China-based cyber-attack somehow made their way into the final cut.



The screenshots appear as B-roll footage in the documentary for six seconds—between 11:04 and 11:10 minutes—showing custom-built Chinese software apparently launching a cyber-attack against the main website of the Falun Gong spiritual practice, by using a compromised IP address belonging to a United States university. As of Aug. 22 at 1:30pm EDT, in addition to Youtube, the whole documentary is available on the CCTV website.



The screenshots show the name of the software and the Chinese university that built it, the Electrical Engineering University of China's People's Liberation Army—direct evidence that the PLA is involved in coding cyber-attack software directed against a Chinese dissident group.



More...


Rabu, 17 Agustus 2011

Computer lab’s Chinese-made parts raise spy concerns

washingtontimes.com

A U.S. supercomputer laboratory engaged in classified military research concluded a recent dealinvolving Chinese-made components that is raising concerns in Congress about potential electronic espionage.

The concerns are based on a contract reached this summer between a computer-technology firm and the National Center for Computational Engineering at the University of Tennessee, whose supercomputers simulate flight tests for next-generation U.S. military aircraft and spacecraft, and simulate submarine warfare for the Navy.

The storage system for the contract calls for using software from U.S. cybersecurity firm Symantec installed over devices made by Huawei Technologies, a Chinese telecommunications giant that U.S. officials have said has close ties to China’s military. Huawei and Symantec formed a joint venture in 2008, with Huawei owning 51 percent of the shares of the enterprise.

More...

Senin, 08 Agustus 2011

Massive cyberspying operation targeted U.S., U.N., others

cnn.com London (CNN) -- U.S. government agencies, the United Nations, defense contractors and Olympic bodies have all been targeted by a single intruder in an "unprecedented" campaign of cyberspying, says a new report by a computer-security firm.

The operation, which targeted agencies and groups in 14 countries, bears the hallmarks of state-sponsored espionage, according to the report by security company McAfee. Other cybersecurity experts downplayed the report's findings, however.

McAfee said the attacks, which it calls Operation Shady RAT, have allowed hackers potentially to gain access to military and industrial secrets from 72 targets, most of them in the United States, over a five-year period.

McAfee did not name all the targets but said the sheer scope of victims, including 14 U.S. government bodies; the governments of Canada, India, South Korea and Taiwan; defense contractors; the International Olympic Committee; and even a cybersecurity company, indicates no one is safe.

Dmitri Alperovitch, McAfee's vice president of threat research, said attacks on political nonprofit groups indicated a "state actor" could be behind the operation. He declined to name a specific country, but media reports have pointed a finger at China.

When contacted by CNN, an official at the Chinese embassy said that the allegations were unwarranted, irresponsible and an attempt to vilify China. The official added that China, too, has been a victim of hacking and that the country wants to work with other countries to end the problem.

More...

Selasa, 14 Juni 2011

Chinese government installs spying devices on Hong Kong cars


tgdaily.com

Beijing is allegedly using audio spying devices on dual-plate Chinese-Hong Kong vehicles to gather information.

Apple Daily reports the eavesdropping devices were originally installed under the name "inspection and quarantine cards” back in July 2007. The Shenzhen Inspection and Quarantine Bureau installed the devices free of charge to thousands of vehicles across Hong Kong. The devices are about the size of a PDA, screwed into the car’s front window.

People in Hong Kong, in particular criminals, began to notice something was awry when the authorities were able to pick out cars carrying illegal goods across borders without problem or hesitation.

"For every ten cars we ran we only had [smuggled goods] in three or four to reduce the risk, but the border agents caught all of them. The accuracy was unreal!" one smuggler told Apple Daily.

More...

Kamis, 02 Juni 2011

Google breaks up Gmail spying campaign

scmagazineus.com

Google has identified and disrupted a campaign operating out of eastern China meant to hijack and monitor the Gmail accounts belonging to hundreds of users, the technology giant revealed Wednesday.

Victims included U.S. and Asian government officials -- mostly from South Korea, military members, journalists and Chinese political activists, said Eric Grosse, engineering director of the Google's security team, in a blog post.

The campaign appears to trace back to Jinan, China and involves the theft of user's Gmail passwords, likely through phishing, he said. Google was able to disrupt the campaign, secure the affected accounts and notify the targeted individuals.

"The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Grosse wrote. "Google enables you to forward your emails automatically, as well as grant others access to your account."

More...

Sabtu, 23 April 2011

Protecting Your Country While Protecting Your Clients

channelinsider.com

Think your small business customers are too small to be of interest to international spies looking to steal trade secrets and intellectual property? Think again. Corporate espionage is a real threat. Here's how you can help.

Recently I was surprised to learn how far espionage has moved from the traditional Cold War spying that focused on the Russians stealing our government secrets, to a new type of espionage designed to steal trade secrets and intellectual property. The targets aren’t all multi-national corporations, but include small businesses like the ones we service. Most of the threats come from China.

Brett Kingstone’s 80-person fiber-optic lighting company, Super Vision, was targeted by a Chinese government shell company which bribed one of Kingstone’s key employees to steal designs and process secrets. The Chinese then set up a company to duplicate Super Vision’s products and offer them at low prices, since the cost of stealing was a fraction of the cost of Super Vision’s research and development.

In his book, The Real War Against America (Specialty Publishing Company, 2005) Kingstone describes how he was challenged by his distributors when they found his company’s products being offered for much lower prices. Kingstone was confused until he was able to get samples, which matched Super Vision’s products in every way. Through a spy-thriller ordeal that included bribes, threats, shredded evidence, stolen equipment, fraudulent bankruptcy filings, an FBI investigation, and private investigators posing as Arab sheiks, Kingstone was able to get a $33.1 million civil judgment even though the culprits avoided criminal prosecution.

More...

Minggu, 10 April 2011

French probe industrial espionage at defense firm unit

ca.reuters.com

PARIS (Reuters) - France's intelligence services have unearthed a case of suspected industrial espionage at an engine subsidiary of French aerospace and defense firm Safran, Le Monde newspaper said in its weekend edition.

A Safran spokeswoman declined to comment on Sunday when contacted by Reuters about the report, which spoke of a Chinese link.

The newspaper said investigators had placed about 10 people in custody as they dig for information about a 2010 attack on the computer networks of Safran subsidiary Turbomeca, which makes helicopter engines.

It said hackers broke into the computer networks and gained access to sensitive information about propeller systems at Turbomeca, as well as Safran documents containing information about billing and the cost of various company projects.

The computer break-ins took place during the first eight months of 2010 and may have involved help from company insiders, Le Monde reported it was told by an unnamed judicial source.

More...

Kamis, 07 April 2011

China and Russia fingered in German industrial espionage alert


monstersandcritics.com

Berlin - Industrial espionage by China and Russia is becoming easier thanks to computer hacking, officials warned German business leaders on Thursday, adding that police need data logs to track computer break-ins.

A conference heard that the annual cost to German companies of data theft was at least 20 billion euros (nearly 30 billion dollars).

However it is often easier to simply buy corporate secrets from disloyal employees.

Ole Schroeder, a senior Interior Ministry official, said that in 70 per cent of known cases, staff who hated their employer or were angry that they were likely to lose their jobs were behind the leaks.

More...

Related Posts Plugin for WordPress, Blogger...