ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Night Dragon hackers smash energy multinationals

Hackers target global energy firms as they seek to gain insider information, McAfee reveals.

By Tom Brewster, 10 Feb 2011 at 15:36

Oil

Hackers have used a range of techniques in a dedicated attack against global energy companies, a report has indicated.

An unnamed selection of oil, energy and petrochemical firms have been targeted by cyber criminals in attacks that may have started as long ago as 2007, McAfee said.

Under the so-called Night Dragon operation, the attacks appeared to have been coordinated from a central point, the recently-acquired security firm claimed.

The hackers probed the companies for inside information, such as oil and gas production data, potential areas where the multinationals were looking to work and schematics on how systems worked.

McAfee could not reveal any of the specific details about the firms involved, but noted law enforcement had been brought in to investigate.

Whilst the seemingly coordinated attack has been going on for some time, McAfee was only able to “join the dots” together in recent weeks, said Greg Day, director of security strategy at McAfee.

“For us visibility has only happened in the last week or so, and I would suspect law enforcement may have only happened once they had a bigger understanding of the problem,” Day told IT PRO.

Chinese involvement?

There were a number of indicators that the hackers were from China, although these were not guarantees, Day said.

Firstly, the individual responsible for providing the command and control centre infrastructure was located in the Shandong Province.

McAfee also discovered all of the identified data theft activity occurred from Beijing-based IP addresses and was carried out within the victim companies on weekdays between 09:00 and 17:00 Beijing time.

Furthermore, the hacking tools used in the attacks were of Chinese origin and can be bought together on Chinese underground hacking forums.

Part of the password string to get to the remote access control service contained the word ‘China’ in it as well, but this could just be a red herring, Day said.

“What seems very evident to us is that they weren’t being very careful about covering up their tracks,” he added.

“You have to question whether that was an intentional thing or was that accidental.”

Whilst it seems the attacks were the doing of a centrally-organised body, members could have been spread across the globe, Day said.

Email to a friend

Print this page

Previous
1 2
< Previous   Public Sector : News Next >

1 comments

You need to Login or Register to comment.

RE:

Night Dragon signifies the new trend of co-ordinated attacks http://bit.ly/dUhEsV, highlighting the fact that cybercriminals are no longer lone hackers, but organised professionals, with clear motives. Data protection is therefore paramount to maintaining an impeccable reputation.

By MSC_247 on Wednesday Feb 16

1 people out of 1 found this comment useful.

Did you find it useful?

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement