The Mac Observer

Analyst: Google Hacked by Amateurs

TMO Talk (4)

Reports that China's government was behind cyber attacks on Google and several other companies may be wrong, and instead was the work of amateurs, according to the technology security company Damballa.

The company recently completed its own analysis of the attacks designed to access Gmail accounts along with company secrets and found that the tools used by the hackers seem to indicate they weren't professionals. In its report, Damballa said "The attack is most notable, not for its advanced use of an Internet Explorer 6 Zero-Day exploit, but rather for its unsophisticated design and a pedigree that points to a fast-learning but nevertheless amateur criminal botnet team."

The company's statement contradicts Google's assertion that the attacks were orchestrated by professionals and were most likely directed by the Chinese government. The Damballa report also claims that the attacks most likely weren't targeted, as Google suggests, but instead were fairly generalized.

At the time, Google stated "We have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists."

Apparently the attacks on Google can be traced back to July 2009 and some test runs of a botnet. By December, when Google became aware of the hacker's work, at least seven countries had already been affected by the attacks. By January 12, 2010, the number of affected countries had jumped to 22.

By mid February, a U.S. government investigation had linked a Chinese security expert's work to the attacks, and seemed to tie his research to government activities.

"Based on a thorough analysis of deeper data surrounding the attacks... it appears that Aurora can be best classified as just another increasingly common botnet attack, and one that is more amateur than average," the Damballa report said.

Using more rudimentary tools to carry out a cyber attack don't necessarily rule out government involvement. They do, however, serve as a reminder that even unsophisticated attacks can be effective when given enough time.

[Thanks to Computerworld for the heads up.]

Post A Comment or Log-in. Need an account? Register here.

4 Observer Comments

   Actions Lee Dronick said on March 4th, 2010 at 10:04 AM (Edited: 10/18/2011 6:20 PM):

Is it possible that the attack was done by professionals, but made to look like amateurs. A red herring if not a red panda.

   Actions geoduck said on March 4th, 2010 at 11:29 AM (Edited: 01/26/2012 2:46 PM):

That was my first reaction too. China does not want it traced back to them. One good way of hiding their involvement is to make it look like a bunch of kids who were “a fast-learning but nevertheless amateur criminal botnet team.” Look at the targets. The accounts of Human Rights activists. A bunch of kids wouldn’t be interested in them. The Chinese government would be.

   Actions mactoid said on March 4th, 2010 at 3:06 PM (Edited: 10/25/2011 8:44 PM):

It also occurs to me that Google would prefer the perception that they were hacked by professionals using advanced, technically sophisticated techniques, as opposed to amateurs using relatively unsophisticated, and generally available techniques.  Google is now a prime target of every socially maladjusted teenage hacker out to make a name for themselves; and they now know its possible.

   Actions Lee Dronick said on March 4th, 2010 at 3:50 PM (Edited: 10/18/2011 6:20 PM):

t also occurs to me that Google would prefer the perception that they were hacked by professionals using advanced, technically sophisticated techniques…

Yes there is certainly the possibility of that scenario.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated May 26th

Sat, 10:00 AM
MacOS KenDensed - MacOS KenDensed: Apple’s Patent Lawsuit & Antitrust Shuffle
Fri, 5:58 PM
News - Sotheby’s to Auction Steve Jobs Atari Memo (Photo Gallery)
5:42 PM
Free on iTunes - 3 Free iOS Apps for News Hounds
3:00 PM
Rumor - Nest Thermostat Reportedly Coming to Apple Retail Stores
2:40 PM
Particle Debris - The TV Industry’s Dreadful Little Secret
2:33 PM
News - Mobile Devices Account for 20% of Web Traffic in US, Canada
12:49 PM
News - Apple Now Offering “Free App of the Week” for iOS
12:21 PM
News - Tim Cook Declines $75 Million Dividend Payout
11:25 AM
News - Absinthe 2.0 Provides Untethered Jailbreak for iOS 5.1.1
11:09 AM
Quick Look Review - F18 Carrier Landing (iOS) is a Boatload of Fun
10:51 AM
TMO Appearances - Jeff Gamet talks Cool Apps & Accessories on Not Another Mac Podcast
10:12 AM
Hot Forum Topic - Forum Poll: Which is Your Favorite Photo Sharing Service?
 

The Mac Observer Reader Specials

  • Macsales Add 2nd Hard Drive or SSD to Mac mini, MacBook or MacBook Pro. 1TB of Hard Drive or SSD Capacity from $64.99! Video Guides Make it easy - OWC DataDoubler - Macsales.com
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Macpokeronline.com If you're using a Mac, then you've gotta check out PokerOnAMac.com. Online casinos and poker rooms are literally giving away cash and the casino sites at Poker on a Mac do the unthinkable, they actually reward! Join today, the download is free!
  •  Looking to find online casinos for mac? We can help you find the best real money casino sites where you can play your favorite casino games including blackjack and slots.

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal