• Welcome
    Sponsors
  • Director
    Members
    Advisory Board
    International Advisory Council
    Research Affiliates
    IPilogue Editors
    Alumni
  • IPilogue
    Events
    Publications
  • JD
    Graduate Program
    Clinical
    Prizes & Awards
  • The IPIGRAM Archive
    Events Archive
    IP in the News
    IP Poll of the Week
    IP Pick of the Week
    Gowlings IPilogue Prize
  • Legislation
    Journals
    Government
  • Contact Us
    Subscribe

Canadian Researchers Reveal the Shadowy Side of Cyber-Espionage

April 29, 2010 by Stuart Freen (IPilogue Editor)

Stuart Freen is a JD candidate at Osgoode Hall Law School.

Earlier this month a joint team of researchers from the Information Warfare Monitor and the Shadowserver Foundation released a new report entitled Shadows in the Cloud. The report details a complex cyber-espionage network operating out of China which has compromised computers and stolen hundreds of files from targets including the Indian government, the Tibetan Government-in-Exile and the Office of the Dalai Lama. More sophisticated than your average hackers, the report reveals how one particular group of anonymous cyber-criminals targeted, hacked, and infiltrated government agencies by exploiting security holes in common software applications and using free social networking services like Facebook, Twitter and Yahoo Mail.

The Shadows report comes a year after the same team released the Tracking GhostNet report which uncovered cyber-espionage activities against the Tibetan government. In many respects Shadows in the Cloud can be considered a continuation of the work started in GhostNet, though it focuses on a different group of hackers with new and updated techniques. Among the authors is Ron Deibert, who recently spoke about cyber warfare at the IP Osgoode/Nathanson Centre Workshop on Media Suppression (watch a video of his presentation here). The report has garnered a fair amount of media attention, perhaps due in part to increased public awareness of cyber-espionage following the Chinese attacks on Google servers in December 2009.

Shadows in the Cloud reveals how Chinese hackers were able to target and compromise numerous computers belonging to nearby governments, with India bearing the brunt of the attacks. While the report is careful not to jump to conclusions regarding the involvement of the Chinese government, it notes the inter-related nature of government, organized crime and the public in some parts of the country. Targets were typically tricked via email or social networking sites into opening infected PDF or Microsoft Office files which would load malicious programs onto their computers. From there, the compromised computers were remotely instructed to upload sensitive documents to online repositories. Notably, the hackers made use of free web services like Twitter and Yahoo Mail to both issue commands to compromised computers and to receive uploaded files.

While many of the techniques used by the cyber-spies were not new and the actual scope of the espionage was fairly small, what is notable is the targeted approach the hackers took to gathering sensitive government documents. The report notes several specific instances where secret or classified documents were successfully “exfiltrated” from compromised computers. As opposed to the broad, scattered approach taken by traditional hackers who are mostly interested in extracting user passwords and causing havoc, this network was apparently focused on certain government agencies. The report suggests that hacking groups are, for whatever reason, moving from traditional areas of cyber-crime into political espionage.

Reading the report, one is struck by the shadowy and anonymous nature of the hacking community. At only one part of the report is an attacker actually traced back to a real person (who happened to be a university student in Chengdu). As with any illegal activity, the actual scope of cyber-espionage remains a mystery. Similarly, the actual motivations behind the spying remain unclear. It’s hard to tell whether the network the team uncovered is a small part of a larger government program, or simply a bunch of patriotic students with too much time on their hands. Nevertheless, the report provides a thorough and technical view into the workings of this particular network, and raises some important concerns regarding the militarization of the internet and the emergence of cyber-espionage.

Posted in Internet, Privacy

Leave a Reply

All replies and responses are moderated and will not appear on the site immediately. Please see our response policy.

« Biobank Governance, Privacy, and Informed Consent | To License or Not to License? »

Career Opportunities
Osgoode IP Club
Writing Competitions
IP Research Guide

Follow @IPilogue

RSS Follow Comments via RSS
  • Denise Brunsdon on The Living Daylights (…Scents, Tastes, and Sounds): Bill C-56 Forebodes Drastic Trade-mark Reform
  • Denise Brunsdon on Must Every Canadian Patent Application Include the Inventor’s Best Mode of Working the Invention?
  • Matt on Mario Bouchard: Copyright Quintet opus 1. no.1, by McLachlin et al
  • Danny Titolo on The ‘Myriad’ with the Golden ‘Gene’: Australia Upholds Breast Cancer Gene Patents
  • Tracy Ayodele on Exceptions which Circumvent Logic
  • Nancy Situ on Military Tactics and Rock Star Patent Lawyers; the Patent System under Stress
  • Laura on The Rise and Fall [and Rise Again?] of BlackBerry
  • Howard Knopf on How Music Can Help You, And You Can Help Music – An Interview With Graham Henderson
  • Paul Atkinson on Bill C-56 Remedies: Rights Holders Can All Feel a Little Safer
  • Bart Cormier on The Living Daylights (…Scents, Tastes, and Sounds): Bill C-56 Forebodes Drastic Trade-mark Reform
RSS Follow Posts via RSS
  • New Step for the Modernization of Copyright Law in the US – Progress or Regress?
  • Reminder: Canada’s IP Writing Challenge 2013
  • Property in Brands
  • Strike Three, Viacom
  • New Book – The Copyright Pentalogy: How the Supreme Court of Canada Shook the Foundations of Canadian Copyright Law
  • The Curious Case of Fake Beijing Olympics Merchandise
  • About the Boundaries of Fairness in Fair Use
  • Who Inherits Your Likes?
  • Game of Thones – Piracy is Coming
  • AEREO, Cable, What’s The Difference?
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • 2013
  • 2012
  • 2011
  • 2010
  • 2009
  • 2008
  • 2007
  • Advisory Board (9)
  • Announcements (31)
  • Blogs (24)
  • Book Review (5)
  • Broadcasting Regulatory Policy (8)
  • Cloud Services (11)
  • Commercialization (90)
  • Competition (19)
  • Competition Law (14)
  • Contracts (69)
  • copyright reform (158)
  • defamation (19)
  • Design (15)
  • Development (6)
  • European Union (54)
  • events (88)
  • Fashion Industry (22)
  • Feature Post (206)
  • Freedom of Speech (22)
  • Freedom of the Press (17)
  • Gaming (9)
  • General (151)
  • Human Rights (10)
  • Image (6)
  • Innovation (156)
  • Internet (274)
  • IP (1242)
    • Copyright (617)
      • CD Levy (10)
      • Digital Downloads (78)
      • Digital Libraries (7)
      • Digital Locks (34)
      • Fair Dealing (79)
        • Parody (2)
        • Satire (1)
      • Infringement (157)
      • Internet Sharing (96)
      • Literary Works (65)
      • Moral Rights (15)
      • Movies (53)
      • Music Industry (104)
      • Originality (33)
      • Ownership (107)
        • Licensees (39)
      • Secondary (ISP) Liability (18)
      • Subsidiary Rights (5)
    • IP Reform (37)
    • Patents (381)
      • Access to Medicines (21)
      • Cross Border Issues (50)
      • Electronic Processes (20)
      • Infringement (72)
      • Patent Practice (27)
      • Patent Trolls (21)
      • Patentability (109)
      • Pharmaceutical Drugs (75)
    • Trademarks (243)
      • Domain Names (44)
      • Famous Marks (20)
      • Official Marks (11)
      • Parallel Importation (4)
      • Personality Rights (12)
  • IP Course Topic (13)
  • IP Intensive (26)
  • IP Litigation Practice (17)
  • Jurisdiction (176)
    • Canada (80)
    • Indonesia (1)
    • Japan (2)
    • UK (41)
    • US (74)
  • Law & Music Course Topic (21)
  • Links (3)
  • MediaLaws (17)
  • Music Industry (85)
  • Open-Source (18)
  • Osgoode Alumnus (14)
  • Patents Course Topic (28)
  • Privacy (188)
    • Electronic Databases (42)
    • Human Rights Issues (31)
    • Identity Theft (14)
  • Regulatory Policy (64)
  • Reputation Management (4)
  • Smartphones (14)
  • Social Justice (4)
    • United Nations Development Programme (2)
  • Social Media (30)
  • Supreme Court of Canada (34)
  • Tech Transfer (31)
  • Technology (245)
  • Telecommunications (89)
  • Trade Secrets (9)
  • UK (19)
  • Uncategorized (102)
  • US-Canada Relations (4)
  • WIPO (16)
  • Log in

Home   |   Contact Us   |   Feedback  |   Privacy   

© 2008 Osgoode Hall Law School York University
4700 Keele Street Toronto, Canada M3J 1P3
T:416.736.5030   F:416.736.5736