Tracking GhostNet: Investigating a Cyber Espionage Network
Information Warfare Monitor
March 29, 2009
https://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network
| Notes |
|---|
| cyberespionage |
| China |
| spy |
| Tibet |
| 1295 infected hosts in 103 countries |
| .. 30% of infected hosts considered “high-value” |
| .. ministries of foreign affairs, embassies, international organizations, news media, NGOs, … |
| China considers cyberspace a strategic domain |
| United States |
| malware |
| intelligence |
| Internet |
| China is the world’s largest Internet population |
| digital native |
| cybercrime |
| cybercrime kit |
| social engineering |
| trojan |
| malware propagation |
| India |
| Europe |
| Greg Walton - SecDev Fellow at the Citizen Lab |
| Dr. Shishir Nagaraja - Security Laboratory, Cambridge University |
| Dharamsala |
| Nart Villenueve - CTO of Psiphon Inc, Psiphon Fellow at the Citizen Lab |
| command and control |
| log file |
| Ronald Deibert |
| Arnav Manchanda |
| Rafal Rohozinski |
| Greg Walton |
| Jane Gowan |
| Belinda Bruce |
| James Tay |
| Private Office of his Holiness the Dali Lama |
| Tibetan Government-in-Exile |
| London, Brussels, New York, Drewla |
| insecure command and control servers used by the operators |
| Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados, Bhutan |
| India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal |
| Germany, Pakistan |
| ASEN (Association of Southeast Asian Nations) |
| SAARC (South Asian Association for Regional Cooperation) |
| Asian Development Bank |
| NATO |
| gh0st RAT |
| Hainan, China |
| phishing |
| SIGINT |
| information age |
| lack of incentive for software to be secure |
| contact information |
| PowerPoint |
| identity theft |
| United States, Israel, United Kingdom |
| strategic domains: land, air, sea, space, cyber |
| PLA |
| Russia-Georgia conflict |
| Gaza |
| Israel’s January 2009 Gaza offensive |
| Estonia |
| DoS |
| attribution |
| intelligence service |
| OpenNet Initiative |
| Kyrgyzstan, Belarus, Georgia |
| FBI estimates cybercrime is responsible for $10 billion in losses |
| cybercrime is asymmetrical |
| targeted malware |
| chances of getting caught are low |
| Cooperative Cyber Defence Centre of Excellence |
| Tallinn, Estonia |
| International Telecommunication Union |
| IMPACT |
| circumstantial evidence |
| Europe, North America, Asia |
| Britain, France, Germany, South Korea, Taiwan |
| intellectual property |
| USDOJ |
| Titan Rain |
| DoD |
| Darfur, Sudan |
| Falun Gong |
| web defacements |
| virus |
| Sino-American, Sino-Taiwanese tensions |
| the attribution problem: attribution is hard |
| April 2001 collision of Chinese and American planes |
| forensics |
| in situ |
| Wireshark |
| IP lookup |
| WHOIS |
| Palantir |
| data visualization |
| data analysis |
| data fusion |
| Thubten Samphel - Department for Information and International Relations |
| firewall logs |
| Tibetan Computing Resource Centre |
| Phuntsok Dorjee - director, TibTec |
| human rights |
| trade union |
| labor organizer |
| payload |
| 2008 Beijing Olympics |
| malicious attachment, malicious link |
| campaigns@freetibet.org |
| Microsoft Word |
| maldoc |
| Translation of Freedom Movement ID Book for Tibetans in Exile.doc |
| VirusTotal |
| packer |
| obfuscation |
| anti-virus |
| RAT |
| gh0st RAT |
| phishing lure |
| DNS |
| dynamic DNS - 3322.org |
| packet capture |
| PHP |
| reuse of infrastructure |
| reuse of email address when registering domains |
| “macfeeresponse.org” |
| HTTP GET, HTTP POST |
| exfiltration |
| Lodi Gyari - Executive Chairman of the Board of the International Campaign for Tibet (ICT) |
| malware retrieved JPEG file that wasn’t an image but contained IP address and port numbers |
| NamBu TV |
| Seoul |
| New York OOT |
| Drewla |
| incommunicado |
| chat |
| honeypot |
| DSL |
| Hainan Island |
| Jiangsu, Guandong, Sichuan |
| Hong Kong |
| keylogger |
| gh0stRAT can use proxy servers |
| spear phishing |
| PDF, DOC attachments |
| backdoor |
| propagation via contact list |
| geoIP |
| attacker changes checkin IP to 127.0.0.1 when unavailable |
| webcam viewer |
| audio capture |
| broadband Internet |
| earliest infected computer: May 22, 2007 |
| dwell time: 400+ days |
| spikes in infection: December 2007, August 2008 |
| PetroVietnam |
| Deloitte |
| Net Trade - Taiwan |
| software piracy |
| DVD piracy |
| DIY SIGINT |
| per se |
| SecDev Group |
| Ottawa |
| Munk Centre for International Studies, University of Toronto |