CBCnews
Story Tools: EMAIL | PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK | Bookmark and Share

Canadian research uncovers cyber espionage network

Malware-spreading computers based mainly in China

Last Updated: Sunday, March 29, 2009 | 10:03 AM ET

Canadian researchers have uncovered an internet spy network, based mostly in China, that has hacked into computers owned by governments and private organizations in 103 countries.

The findings released Sunday follow a 10-month investigation by researchers from the Ottawa-based think tank SecDev Group and the Munk Centre for International Studies at the University of Toronto.

The group was initially asked to look into allegations that the Chinese were hacking into computers set up by the Tibetan exile community, but their work eventually led them to a much wider network of compromised computers.

Once the hackers infiltrated the systems, they installed malware — software that sends and receives data. By doing this, they were able to gain control of the electronic mail server computers of the Dalai Lama’s organization, the group said.

The researchers said the spy network, dubbed GhostNet, infiltrated at least 1,295 computers, many belonging to embassies, foreign ministries and other government offices, as well as the Dalai Lama’s Tibetan exile centres in India, Brussels, London and New York.

Embassies, foreign affairs ministries targeted

"Significantly, close to 30 per cent of the infected computers can be considered high-value and include the ministries of foreign affairs in Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados and Bhutan," the researchers said.

Other compromised computers were discovered at embassies of India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal, Germany and Pakistan.

The list continues with the network infiltrating economic organizations in Southeast Asia, news organizations, and an unclassified computer located at NATO headquarters.

Although almost all the hackers were based in China, the researchers could not say whether they are working for the government.

A spokesman for the Chinese consulate in New York dismissed the idea that China was involved.

The spokesman, Wenqi Gao, told The New York Times these are "old stories" and "nonsense."

A 'wakeup call' for international community

"This is a wakeup call for the international community," said Rafal Rohozinski of SecDev Group, who is one of the principal authors of the report. "At the moment there is no clear legal framework for how you deal with a spy network."

Rohozinski said three out of the four servers in the network are based in China and one is in the United States, complicating any efforts to launch a criminal investigation.

"It's all a question of jurisdiction. Obviously the Chinese government would have a capability — a legal jurisdiction — to investigate the servers located on their territory. But that is ultimately up to them," he told CBC News.

"Certainly in the States — because one of the control servers happens to be located there — we fully expect the DHS [Department of Homeland Security] or the FBI will be investigating," Rohozinski said.

One of several infections that have been installed gives the hacker full control over the compromised computer, giving the culprit the ability to look at all files, including emails.

"They can surreptitiously turn on the [computer's] microphone or the video camera and record you. And moreover, because what we found is a trojan which at this moment is undetectable by exisiting firewalls or virus technologies, it can essentially do a data infinitum.

"In fact, some of the computers on this network have been lit up — meaning they have been compromised — for over 400 days," Rohozinski said.

  •  
Story Tools: EMAIL | PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK | Bookmark and Share
 

Related

Video

Laurie Graham reports: Canadian research uncovers cyber espionage network (Runs: 2:41)
Play: QuickTime »
Play: Real Media »
Jacquie Perrin interviews Rafal Rohozinski with the SecDev Group on newly uncovered internet spy network (Runs: 4:30)
Play: QuickTime »
Play: Real Media »
Jacquie Perrin interviews Greg Walton, one of the field investigators on newly uncovered internet spy network (Runs: 3:28)
Play: Real Media »
Play: QuickTime »

Technology & Science Headlines

Bell quietly drops system access fee
The cellphone system access fee is all but extinct. Bell Canada has quietly axed the charge, joining rivals Rogers and Telus.
Beam sent around Large Hadron Collider
The operators of the Large Hadron Collider have successfully sent a beam of particles around the ring of the world's largest particle collider in Switzerland.
Astronauts complete 6-hour spacewalk
Astronauts from space shuttle Atlantis completed the second of three scheduled spacewalks Saturday, spending just over six hours installing equipment on the International Space Station.
Asian carp close to Great Lakes
U.S. officials say the despised Asian carp may have breached an electronic barrier designed to prevent it from invading the Great Lakes.
Billy Bragg, NDP push for new law on music downloads
British folk singer Billy Bragg teamed up with Canadian songwriters and the NDP to advocate for copyright reform and a new approach to music downloads while on tour in Ottawa Friday.

People who read this also read …

Top CBCNews.ca Headlines

Headlines

McCain argues against Afghanistan exit date Video
U.S. Senator John McCain says military exit dates and exit strategies in Afghanistan should not even be discussed until NATO gets the upper hand in its fight against Taliban militants.
U.S. health-care bill clears Senate hurdle
Democrats united Saturday night to narrowly push historic health-care legislation past a key U.S. Senate hurdle over the opposition of Republicans eager to inflict a punishing defeat on President Barack Obama.
Disgraced N.S. bishop's replacement named Video
The Roman Catholic Church has appointed a replacement for Bishop Raymond Lahey, of the Diocese of Antigonish, N.S., who is facing child pornography charges.
Rocket hits luxury hotel in Afghan capital
At least two people were hurt when a rocket struck a wall of the heavily guarded Serena Hotel in Kabul, the Interior Ministry says.
Vancouver Island evacuation order lifted Video
An evacuation order has been lifted for hundreds of south Vancouver Island residents forced from their homes by flooding.