Security experts lift lid on Chinese hack attacks

By Tom Espiner, ZDNet UK
24 November 2005 08:16 AM
Tags: hacker, china, us, crack, chinese, steal, military, government
Security experts have revealed details about a group of Chinese hackers who are suspected of launching intelligence-gathering attacks against the US government.

The hackers, believed to be based in the Chinese province of Guangdong, are thought to have stolen US military secrets, including aviation specifications and flight-planning software.

The US government has coined the term "Titan Rain" to describe the hackers.

"From the Redstone Arsenal, home to the Army Aviation and Missile Command, the attackers grabbed specs for the aviation mission-planning system for Army helicopters, as well as Falconview 3.2, the flight-planning software used by the Army and Air Force," Alan Paller, the director of the SANS Institute, said on Tuesday.

The team is thought to consist of 20 hackers. Paller said that the Chinese government is the most likely recipient of the information they intercepted.

"Of course, it's the government. Governments will pay anything for control of other governments' computers. All governments will pay anything. It's so much better than tapping a phone," Paller said at an event at the British Department of Trade and Industry.

Titan Rain first came to public attention this summer, when the Washington Post reported that Web sites in China were being used to target computer networks in the Defence Department and other US agencies.

Time magazine later reported that Titan Rain had been counter-hacked by a US security expert called Shawn Carpenter.

The ongoing attacks were particularly effective on the night of November 1, 2004, said Paller, who outlined his version of how the hackers first scanned, then broke into, US government computers:

At 10:23 p.m. PST, the Titan Rain hackers exploited vulnerabilities at the US Army Information Systems Engineering Command at Fort Huachuca, Arizona.

At 1:19 a.m., they exploited the same hole in computers at the Defence Information Systems Agency in Arlington, Virginia.

At 3:25 a.m., they hit the Naval Ocean Systems Centre, a Defence Department installation in San Diego, California.

At 4:46 a.m., they struck the US Army Space and Strategic Defence installation in Huntsville, Alabama.

The United Kingdom is also under intelligence-gathering cyberattack from the Far East, according to National Infrastructure Security Co-ordination Centre. The government body cannot name the countries concerned as this may "ruin diplomatic efforts to halt the attacks," NISCC director Roger Cummings said on Tuesday.

ZDNet UK's Tom Espiner reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured