Night Dragon hackers smash energy multinationals
By Tom Brewster,
Hackers have used a range of techniques in a dedicated attack against global energy companies, a report has indicated.
An unnamed selection of oil, energy and petrochemical firms have been targeted by cyber criminals in attacks that may have started as long ago as 2007, McAfee said.
Under the so-called Night Dragon operation, the attacks appeared to have been coordinated from a central point, the recently-acquired security firm claimed.
The hackers probed the companies for inside information, such as oil and gas production data, potential areas where the multinationals were looking to work and schematics on how systems worked.
McAfee could not reveal any of the specific details about the firms involved, but noted law enforcement had been brought in to investigate.
Whilst the seemingly coordinated attack has been going on for some time, McAfee was only able to “join the dots” together in recent weeks, said Greg Day, director of security strategy at McAfee.
“For us visibility has only happened in the last week or so, and I would suspect law enforcement may have only happened once they had a bigger understanding of the problem,” Day told IT PRO.
Chinese involvement?
There were a number of indicators that the hackers were from China, although these were not guarantees, Day said.
Firstly, the individual responsible for providing the command and control centre infrastructure was located in the Shandong Province.
McAfee also discovered all of the identified data theft activity occurred from Beijing-based IP addresses and was carried out within the victim companies on weekdays between 09:00 and 17:00 Beijing time.
Furthermore, the hacking tools used in the attacks were of Chinese origin and can be bought together on Chinese underground hacking forums.
Part of the password string to get to the remote access control service contained the word ‘China’ in it as well, but this could just be a red herring, Day said.
“What seems very evident to us is that they weren’t being very careful about covering up their tracks,” he added.
“You have to question whether that was an intentional thing or was that accidental.”
Whilst it seems the attacks were the doing of a centrally-organised body, members could have been spread across the globe, Day said.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector Analysis & Insight
The Digital Economy Act: Is it doomed to never happen?
As a further delay hits part of the implementation of the Digital Economy Act, is this just a small hiccup, or is the Act being rendered toothless already? Simon Brew takes a look.
- Does the government want to snoop on your data?
- Q&A: Rajeeb Dey, CEO Enternships
- Government IT: Apples for the mandarins
- Striving to solve the security skills crisis
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






RE:
Night Dragon signifies the new trend of co-ordinated attacks http://bit.ly/dUhEsV, highlighting the fact that cybercriminals are no longer lone hackers, but organised professionals, with clear motives. Data protection is therefore paramount to maintaining an impeccable reputation.
By MSC_247 on Wednesday Feb 16