{"id":71245,"date":"2013-09-19T19:42:59","date_gmt":"2013-09-19T18:42:59","guid":{"rendered":"http:\/\/rinf.com\/alt-news\/breaking-news\/hackers-for-hire-chinese-group-accused-of-economic-espionage-against-us-companies\/71245\/"},"modified":"2013-09-19T19:42:59","modified_gmt":"2013-09-19T18:42:59","slug":"hackers-for-hire-chinese-group-accused-of-economic-espionage-against-us-companies","status":"publish","type":"post","link":"http:\/\/rinf.com\/alt-news\/breaking-news\/hackers-for-hire-chinese-group-accused-of-economic-espionage-against-us-companies\/","title":{"rendered":"Hackers-for-hire: Chinese group accused of economic espionage against US companies"},"content":{"rendered":"<div class=\"ftpimagefix\" style=\"float:none\"><a target=\"_blank\" href=\"http:\/\/rt.com\/usa\/hackers-china-hidden-lynx-092\/\"><img decoding=\"async\" width=\"150\" src=\"http:\/\/rt.com\/files\/news\/20\/7e\/40\/00\/6.jpg\"\/><\/a><\/div>\n<div>\n<div>\n\t\t\t\t\t\t<!-- time --><br \/>\n                        <span><br \/>\n                            Published time: September 19, 2013 18:40                                                    <\/span><br \/>\n                        <!--\/\/ time --><\/p><\/div>\n<div>\n<p>Reuters \/ Pichi Chuang <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Computer security experts at Symantec say they&#8217;ve identified an elite group of Chinese hackers who have targeted the systems of Google, Adobe and other big name United States-based companies.<\/p>\n<p>\n  A 28-page report released by the Silicon Valley-based security<br \/>\n  firm this week accused the group &ldquo;Hidden Lynx&rdquo; with an array of<br \/>\n  high-profile hacks that have targeted major technology companies<br \/>\n  and government contractors alike since at least 2009.\n<\/p>\n<p>\n  Symantec has blamed the group for Operation Aurora, a 2009<br \/>\n  cyber-attack that set its sights on dozens of victims, including<br \/>\n  Yahoo, Northrup Grumman, Dow Chemical and even Symantec itself.<br \/>\n  Google was the first company to break news of the attack early<br \/>\n  the next year and admitted that the hackers attempted to breach<br \/>\n  Gmail and read communications between human rights activists.\n<\/p>\n<p>\n  According to Symantec, the group involved in the exploits<br \/>\n  consists of 50 to 100 professional &ldquo;<i>hackers for hire<\/i>,&rdquo; and<br \/>\n  is among the most advanced troops of its kind.\n<\/p>\n<p>\n  &ldquo;<i>This group has a hunger and drive that surpass other<br \/>\n  well-known groups<\/i>,&rdquo; Symantec acknowledged in a blog post<br \/>\n  published on Tuesday, and characterized the unit as demonstrating<br \/>\n  vast technical prowess, agility, organization, patience and<br \/>\n  &ldquo;<i>sheer resourcefulness<\/i>.&rdquo;\n<\/p>\n<p>\n  &ldquo;<i>These attributes are shown by the relentless campaigns waged<br \/>\n  against multiple concurrent targets over a sustained period of<br \/>\n  time<\/i>,&rdquo; Symantec said.\n<\/p>\n<p>\n  But whereas other recent reports identified other powerful<br \/>\n  Chinese hacking groups tied to the country&#8217;s government, Symantec<br \/>\n  failed to directly accuse the computer pros as being state<br \/>\n  agents.\n<\/p>\n<p>\n  &ldquo;<i>Given the breadth and number of targets and regions involved,<br \/>\n  we infer that this group is most likely a professional<br \/>\n  hacker-for-hire operation that are contracted by clients to<br \/>\n  provide information<\/i>,&rdquo; Symantec said. &ldquo;<i>They steal on<br \/>\n  demand, whatever their clients are interested in, hence the wide<br \/>\n  variety and range of targets<\/i>.&rdquo;\n<\/p>\n<p>\n  Among those targets is Bit9, the self-proclaimed &ldquo;<i>leader in a<br \/>\n  new generation of endpoint and server security based on real-time<br \/>\n  visibility and malware protection<\/i>.&rdquo; The United States<br \/>\n  government is just one of the clients of Bit9, a  firm that<br \/>\n  analyzes software to make sure it&#8217;s secure enough to run on<br \/>\n  certain systems. It was breached in June 2012 by a group now<br \/>\n  identified by Symantec as Hidden Lynx.\n<\/p>\n<p>\n  &ldquo;<i>Since November 2011, hundreds of organizations worldwide have<br \/>\n  been targeted<\/i>&rdquo; by the group, Symantec said in the report.<br \/>\n  More than half of those targets are US-based, and around a<br \/>\n  quarter are linked to the financial sector.\n<\/p>\n<p>\n  &ldquo;<i>There is almost certainly a financial motivation behind these<br \/>\n  attacks<\/i>,&rdquo; Symantec said, accusing Hidden Lynx of mass<br \/>\n  corporate espionage as well as attacks against nation-states and<br \/>\n  governmental contractors alike.\n<\/p>\n<p>\n  Speaking to Reuters, the chief technologist at competing security<br \/>\n  firm CrowdStrike said he thinks the group has worked solely for<br \/>\n  the Chinese government and state-owned enterprises, despite<br \/>\n  Symantec&#8217;s falling short of make such accusations.\n<\/p>\n<p>\n  &#8220;<i>Whether they are formally a military unit or a defense<br \/>\n  contractor, that is unknown<\/i>,&#8221; CrowdStrike&#8217;s <span>Dmitri<br \/>\n  Alperovitch<\/span> told the newswire.\n<\/p>\n<p>\n  Weighing in with the Wall Street Journal,<br \/>\n  <span>Alperovitch<\/span> added, &ldquo;<i>There is no question they&#8217;re<br \/>\n  working on behalf of the Chinese government<\/i>.&rdquo;\n<\/p>\n<p>\n  Earlier this year, Virginia-based security firm Mandiant released<br \/>\n  a <a target=\"_blank\" href=\"http:\/\/rt.com\/usa\/cyber-china-war-unit-604\/\">report<\/a> accusing a group directly tied to the Chinese<br \/>\n  government with comprising the systems of over 140 companies,<br \/>\n  including many US-based corporations, such as Coca-Cola.\n<\/p>\n<p>\n  Comparing Hidden Lynx with other Chinese hacking firms,<br \/>\n  Symantec&#8217;s <span>Samir Kapuria, the company&#8217;s vice president of<br \/>\n  business strategy and secure intelligence, told ABC News,<br \/>\n  &ldquo;<i>These guys are a lot more precise and surgical<\/i>.&rdquo;<\/span>\n<\/p>\n<p>\n  &#8220;<i>The tactics and tools that they employ are things that they<br \/>\n  like to keep hidden&hellip; This is when there&#8217;s a specific mission in<br \/>\n  mind: &#8216;How do we infiltrate the supply chain of our ultimate<br \/>\n  target? How do we tailor some specific attack that allows us to<br \/>\n  go under the radar<\/i>?'&#8221; he said.\n<\/p>\n<p>\n  In the official report, embedded below, Symantec said the group<br \/>\n  is highly organized and &ldquo;<i>can gain advanced access to zero-day<br \/>\n  vulnerabilities<\/i>.&rdquo; RT reported earlier this week that the US&#8217;<br \/>\n  National Security Agency entered a contract last year with a<br \/>\n  French hacking firm named <a target=\"_blank\" href=\"http:\/\/rt.com\/usa\/nsa-vupen-exploit-hack-978\/\">Vupen<\/a> that sells subscriptions to a service that<br \/>\n  provides clients, including major governments, with details about<br \/>\n  these vulnerabilities, named as such because manufacturers have<br \/>\n  no time to patch up security flaws.\n<\/p>\n<p>\n  &ldquo;<i>Major software vendors such as Microsoft and Adobe usually<br \/>\n  take 6 to 9 months to release a security patch for a critical<br \/>\n  vulnerability affecting their products, and this long delay<br \/>\n  between the discovery of a vulnerability and the release of a<br \/>\n  patch creates a window of exposure during which criminals<br \/>\n  can rediscover a previously reported but unpatched vulnerability,<br \/>\n  and target any organization running the vulnerable software<\/i>,&rdquo;<br \/>\n  Vupen acknowledged on its website.\n<\/p>\n<p>Copyright: <a href=\"http:\/\/rt.com\/usa\/hackers-china-hidden-lynx-092\/\" target=\"_blank\" title=\"Hackers-for-hire: Chinese group accused of economic espionage against US companies\">RT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Published time: September 19, 2013 18:40 Reuters \/ Pichi Chuang Computer security experts at Symantec say they&#8217;ve identified an elite group of Chinese hackers who have targeted the systems of Google, Adobe and other big name United States-based companies. A 28-page report released by the Silicon Valley-based security firm this week accused the group &ldquo;Hidden [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":71246,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[487],"tags":[],"class_list":{"0":"post-71245","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-breaking-news"},"_links":{"self":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/71245","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/comments?post=71245"}],"version-history":[{"count":0,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/71245\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media\/71246"}],"wp:attachment":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media?parent=71245"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/categories?post=71245"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/tags?post=71245"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}