Canadian research uncovers cyber espionage network
Malware-spreading computers based mainly in China
Last Updated: Sunday, March 29, 2009 | 10:03 AM ET
CBC News
Related
Video
- Laurie Graham reports: Canadian research uncovers cyber espionage network (Runs: 2:41)
- Play: QuickTime »
- Play: Real Media »
- Jacquie Perrin interviews Rafal Rohozinski with the SecDev Group on newly uncovered internet spy network (Runs: 4:30)
- Play: QuickTime »
- Play: Real Media »
- Jacquie Perrin interviews Greg Walton, one of the field investigators on newly uncovered internet spy network (Runs: 3:28)
- Play: Real Media »
- Play: QuickTime »
Canadian researchers have uncovered an internet spy network, based mostly in China, that has hacked into computers owned by governments and private organizations in 103 countries.
The findings released Sunday follow a 10-month investigation by researchers from the Ottawa-based think tank SecDev Group and the Munk Centre for International Studies at the University of Toronto.
The group was initially asked to look into allegations that the Chinese were hacking into computers set up by the Tibetan exile community, but their work eventually led them to a much wider network of compromised computers.
Once the hackers infiltrated the systems, they installed malware — software that sends and receives data. By doing this, they were able to gain control of the electronic mail server computers of the Dalai Lama’s organization, the group said.
The researchers said the spy network, dubbed GhostNet, infiltrated at least 1,295 computers, many belonging to embassies, foreign ministries and other government offices, as well as the Dalai Lama’s Tibetan exile centres in India, Brussels, London and New York.
Embassies, foreign affairs ministries targeted
"Significantly, close to 30 per cent of the infected computers can be considered high-value and include the ministries of foreign affairs in Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados and Bhutan," the researchers said.
Other compromised computers were discovered at embassies of India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal, Germany and Pakistan.
The list continues with the network infiltrating economic organizations in Southeast Asia, news organizations, and an unclassified computer located at NATO headquarters.
Although almost all the hackers were based in China, the researchers could not say whether they are working for the government.
A spokesman for the Chinese consulate in New York dismissed the idea that China was involved.
The spokesman, Wenqi Gao, told The New York Times these are "old stories" and "nonsense."
A 'wakeup call' for international community
"This is a wakeup call for the international community," said Rafal Rohozinski of SecDev Group, who is one of the principal authors of the report. "At the moment there is no clear legal framework for how you deal with a spy network."
Rohozinski said three out of the four servers in the network are based in China and one is in the United States, complicating any efforts to launch a criminal investigation.
"It's all a question of jurisdiction. Obviously the Chinese government would have a capability — a legal jurisdiction — to investigate the servers located on their territory. But that is ultimately up to them," he told CBC News.
"Certainly in the States — because one of the control servers happens to be located there — we fully expect the DHS [Department of Homeland Security] or the FBI will be investigating," Rohozinski said.
One of several infections that have been installed gives the hacker full control over the compromised computer, giving the culprit the ability to look at all files, including emails.
"They can surreptitiously turn on the [computer's] microphone or the video camera and record you. And moreover, because what we found is a trojan which at this moment is undetectable by exisiting firewalls or virus technologies, it can essentially do a data infinitum.
"In fact, some of the computers on this network have been lit up — meaning they have been compromised — for over 400 days," Rohozinski said.
Share Tools
Top News Headlines
- Greece passes new austerity deal amid rioting
- Greek lawmakers have approved harsh new austerity measures demanded by bailout creditors to save the debt-crippled nation from bankruptcy, after riots in Athens and other cities left stores looted and burned and more than 120 people hurt. more »
- Quebec town 'heartbroken' after killing of woman, sisters
- A small Quebec town is in mourning Sunday after a Quebec man was charged with killing his nieces and his mother, who were found dead in their family home. more »
- Houston autopsy results withheld by police
- Whitney Houston was found in a hotel bathtub but it'll take weeks to determine precisely how she died, a Los Angeles coroner's official says. more »
- Musicians who died before their time
- The growing list of musicians who have died young. more »
Latest Technology & Science News Headlines
- Ancient Antarctic lake may harbour microbial life
- If scientists find microbes in a frigid lake 3.2 kilometres beneath the thick ice of Antarctica, it will illustrate once again that somehow life finds a way to survive in the strangest and harshest places, and it will offer hope that life exists beyond Earth. more »
- B.C. killer whale habitat protection ruled a legal duty
- The federal minister of fisheries has no discretion when it comes to protecting the critical habitat of B.C.'s southern resident killer whales, the Federal Court of Appeal has ruled. more »
- Game developer seeks $400K, makes $1M in a day
- Videogame studio Double Fine went on the website Kickstarter to raise $400K US in a month to develop a new game. They reached that target in a matter of hours. more »
- McGill asbestos study review criticized
- A group of anti-asbestos activists and scientists are criticizing McGill University's plans for an internal review of a major asbestos research study that has been called into question. more »
Bob McDonald's Blog
Glacier Discovery Walk: Will the visitor centre enhance the view? Feb. 10, 2012 3:17 PM Environment minister Peter Kent has announced the construction of a new Glacier Discovery Walk and visitor centre on the Icefields Parkway in Jasper National Park. It raises the issue of how to balance commercial development in our National Parks against the preservation of the last refuges of wilderness.
Quirks & Quarks
- February 11: Inside the Mind of a Neandertal Feb. 10, 2012 4:01 PM Can we get inside the mind of a species that's been dead for 30,000 years? A new book, How to Think Like a Neanderthal, suggests we can. The authors reconstruct a creature like us in many ways, but with important differences.
Latest Features
- Pop queen Whitney Houston dies at 48
- Whitney Houston's body set for autopsy
- Greece passes new austerity deal amid rioting
- Carleton University confirms death of student
- Quebec town 'heartbroken' after killing of woman, sisters
- Ultimate Tazer Ball combines shock and soccer
- Adele, Kanye West each take 3 Grammys
- Adults-only trade show cancelled in B.C. Bible belt
- Manitoba man dies after falling off moving SUV

