trackingghostnet-infowarmonitor2009

2026-09-11

Tracking GhostNet: Investigating a Cyber Espionage Network

Information Warfare Monitor

March 29, 2009

https://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network

Notes
cyberespionage
China
spy
Tibet
1295 infected hosts in 103 countries
.. 30% of infected hosts considered “high-value”
.. ministries of foreign affairs, embassies, international organizations, news media, NGOs, …
China considers cyberspace a strategic domain
United States
malware
intelligence
Internet
China is the world’s largest Internet population
digital native
cybercrime
cybercrime kit
social engineering
trojan
malware propagation
India
Europe
Greg Walton - SecDev Fellow at the Citizen Lab
Dr. Shishir Nagaraja - Security Laboratory, Cambridge University
Dharamsala
Nart Villenueve - CTO of Psiphon Inc, Psiphon Fellow at the Citizen Lab
command and control
log file
Ronald Deibert
Arnav Manchanda
Rafal Rohozinski
Greg Walton
Jane Gowan
Belinda Bruce
James Tay
Private Office of his Holiness the Dali Lama
Tibetan Government-in-Exile
London, Brussels, New York, Drewla
insecure command and control servers used by the operators
Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados, Bhutan
India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal
Germany, Pakistan
ASEN (Association of Southeast Asian Nations)
SAARC (South Asian Association for Regional Cooperation)
Asian Development Bank
NATO
gh0st RAT
Hainan, China
phishing
SIGINT
information age
lack of incentive for software to be secure
email
contact information
PowerPoint
identity theft
United States, Israel, United Kingdom
strategic domains: land, air, sea, space, cyber
PLA
Russia-Georgia conflict
Gaza
Israel’s January 2009 Gaza offensive
Estonia
DoS
attribution
intelligence service
OpenNet Initiative
Kyrgyzstan, Belarus, Georgia
FBI estimates cybercrime is responsible for $10 billion in losses
cybercrime is asymmetrical
targeted malware
chances of getting caught are low
Cooperative Cyber Defence Centre of Excellence
Tallinn, Estonia
International Telecommunication Union
IMPACT
circumstantial evidence
Europe, North America, Asia
Britain, France, Germany, South Korea, Taiwan
intellectual property
USDOJ
Titan Rain
DoD
Darfur, Sudan
Falun Gong
web defacements
virus
Sino-American, Sino-Taiwanese tensions
the attribution problem: attribution is hard
April 2001 collision of Chinese and American planes
forensics
in situ
Wireshark
IP lookup
WHOIS
Palantir
data visualization
data analysis
data fusion
Thubten Samphel - Department for Information and International Relations
firewall logs
Tibetan Computing Resource Centre
Phuntsok Dorjee - director, TibTec
human rights
trade union
labor organizer
payload
2008 Beijing Olympics
malicious attachment, malicious link
campaigns@freetibet.org
Microsoft Word
maldoc
Translation of Freedom Movement ID Book for Tibetans in Exile.doc
VirusTotal
packer
obfuscation
anti-virus
RAT
gh0st RAT
phishing lure
DNS
dynamic DNS - 3322.org
packet capture
PHP
reuse of infrastructure
reuse of email address when registering domains
“macfeeresponse.org”
HTTP GET, HTTP POST
exfiltration
Lodi Gyari - Executive Chairman of the Board of the International Campaign for Tibet (ICT)
malware retrieved JPEG file that wasn’t an image but contained IP address and port numbers
NamBu TV
Seoul
New York OOT
Drewla
incommunicado
chat
honeypot
DSL
Hainan Island
Jiangsu, Guandong, Sichuan
Hong Kong
keylogger
gh0stRAT can use proxy servers
spear phishing
PDF, DOC attachments
backdoor
propagation via contact list
geoIP
attacker changes checkin IP to 127.0.0.1 when unavailable
webcam viewer
audio capture
broadband Internet
earliest infected computer: May 22, 2007
dwell time: 400+ days
spikes in infection: December 2007, August 2008
PetroVietnam
Deloitte
Net Trade - Taiwan
software piracy
DVD piracy
DIY SIGINT
per se
SecDev Group
Ottawa
Munk Centre for International Studies, University of Toronto

Links to this note