The nature of Cyberwarfare in the People's Republic of China is difficult to assess. Government officials in India and the United States have traced various attacks on corporate and infrastructure computer systems in their countries to computers in the People's Republic of China. However, "It is nearly impossible to know whether or not an attack is government-sponsored because of the difficulty in tracking true identities in cyberspace." China has denied accusations of cyberwarfare, and has accused the United States of engaging in cyberwarfare against it, which the US government denies. A number of private computer security firms have stated that they have growing evidence of cyber-espionage efforts originating from China.
Organization[edit | edit source]
Washington-based analyst James Mulvenon[who?] says that the organization of Chinese operations in cyberwarfare is very clandestine and decentralised, organized around a constantly changing hybrid of official, civilian, and semi-civilian groups. Nationalist groups, he says, such as "patriotic hacker associations", are often used as "foot soldiers" or "proxies".
By nation[edit | edit source]
United States[edit | edit source]
The United States has accused the People's Republic of China of implementing cyberwarfare and cyberespionage against American interests, accessing the networks of important military, commercial, research, and industrial organisations. A Congress advisory group has declared China "the single greatest risk to the security of American technologies" and that "there has been a marked increase in cyber intrusions originating in China and targeting U.S. government and defense-related computer systems". According to the Washington Post, China allegedly manipulates security exploits existing in websites, sending out hijacked email attachments with malicious software. Intrusion is especially worrying since the intruder can control the hijacked computer from a remote location, with the ability to steal important files, monitor the user's activity, and read the user's email. Users are typically unaware that they are being spied; the infected attachment is disguised as a mundane topic from a familiar contact, fooling the user into unwittingly setting off a program that silently infects the person's computer. Traces of the malware are hidden by rootkits, which prevent the person from being aware that data is being stolen.
In January 2010, Google reported on targeted attacks on its corporate infrastructure originating from China "that resulted in the theft of intellectual property from Google". Apparently, the Gmail accounts of two human rights activists were compromised in the raid on Google's password system. American security experts connected the Google attack to various other political and corporate espionage efforts originating from China, including espionage against military, commercial, research, and industrial corporations. Obama administration officials have called the cyberattacks "an increasingly serious cyber threat to US critical industries".
In addition to Google, at least 34 companies have been attacked. Reported cases include: Northrop Grumman, Symantec, Yahoo, Dow Chemical, and Adobe Systems. Cyberespionage has been aimed at both commercial and military interests, especially areas in which China lags. Technology companies have claimed that China has sought out source code, along with general information on weapon systems, to develop the software that China needs in both its economic and military pursuits. The source code was stolen using vulnerabilities found in Adobe Reader, which the hackers used to spread malicious software. Chinese cyberattacks have emphasised what senior US Government officials have said is an increasingly serious cyber threat to US critical industries.
China has denied accusations of cyberwarfare, and has accused the United States of engaging in cyberwarfare against it, accusations which the United States denies. Wang Baodong of the Chinese Embassy in the United States responded that the accusations are a result of sinophobic paranoia. He states that, "China would never do anything to harm sovereignty or security of other countries. In conformity with such national policies, the Chinese government has never employed, nor will it employ so-called civilian hackers in collecting information or intelligence of other countries. Allegations against China in this respect are totally unwarranted, which only reflect the dark mentality of certain people who always regard China as a threat."
India[edit | edit source]
Officials in the Indian government have alleged that attacks on Indian government networks, such as that of the Indian National Security Council, have originated in China. According to the government, Chinese hackers are experts in operating up botnets.
Canada[edit | edit source]
Officials in the Canadian government claim that Chinese hackers have comprised several departments within the federal government in early 2011, though the Chinese government has refused involvement.
Stuxnet[edit | edit source]
Although the vast majority of experts have concluded that the Stuxnet virus targeting Iran originated from Israel, which is known to engage in cyberwarfare, American cyberwarfare expert Jeffrey Carr has implicated China as one of the possible states where Stuxnet could have originated. His rationale is that the countries Stuxnet targeted happened to be rich in resources such as copper, gold, and iron ore, that are especially important for China in a period of high economic growth. However, China has also been a victim of the Stuxnet virus. The virus has reportedly infected millions of computers in the nation, wreaking much havoc, because the virus can control industrial machinery.
IP hijacking[edit | edit source]
In late November 2010, a U.S. Defense Department spokesman said the department was aware that Internet traffic was rerouted briefly through China earlier in the year. The United States-China Economic and Security Review Commission charged in its annual report that state-owned China Telecom advertised erroneous network routes that instructed "massive volumes" of U.S. and other foreign Internet traffic to go through Chinese servers during an 18-minute stretch on April 8. China's Foreign Ministry condemned the commission's report, while China Telecom separately denied the charge that it "hijacked" U.S. Internet traffic.
See also[edit | edit source]
- Operation Aurora
- Operation Shady RAT
- 2011 Canadian government hackings
- Google China
- Honker Union
- Titan Rain
- Chinese intelligence operations in the United States
- Chinese intelligence activity in other countries
References[edit | edit source]
- Gorman, Siobhan (April 8, 2009). "Electricity Grid in U.S. Penetrated By Spies". The Wall Street Journal. http://online.wsj.com/article/SB123914805204099085.html. Retrieved November 2, 2010.
- Fox News: Video
- "China's Response to BusinessWeek". Bloomberg Businessweek. April 10, 2008. http://www.businessweek.com/magazine/content/08_16/b4080032243361.htm. Retrieved October 23, 2010.
- Zetter, Kim (January 25, 2010). "China Accuses US of Cyberwarfare". Wired. http://www.wired.com/threatlevel/2010/01/china-accuses-us/. Retrieved October 23, 2010.
- Nakashima, Ellen, "Report on ‘Operation Shady RAT’ identifies widespread cyber-spying", Washington Post, August 3, 2011.
- Anderlini, Jamil (January 15, 2010). "The Chinese dissident’s ‘unknown visitors’". Financial Times. http://www.ft.com/cms/s/0/c590cdd0-016a-11df-8c54-00144feabdc0.html.
- "China Denies Role in Reported Government of Canada Hack". PCWorld. February 17, 2011. http://www.pcworld.com/businesscenter/article/219906/china_denies_role_in_reported_government_of_canada_hack.html. Retrieved February 17, 2011.
- Macartney, Jane (December 5, 2007). "China hits back at 'slanderous and prejudiced' alert over cyber spies". The Times (London). http://www.timesonline.co.uk/tol/news/world/asia/article3000697.ece. Retrieved April 7, 2008.
- Barnes, Julian E. (March 4, 2008). "China's computer hacking worries Pentagon". Los Angeles Times. Archived from the original on March 10, 2008. http://web.archive.org/web/20080310042216/http://www.latimes.com/news/nationworld/world/la-fg-uschina4mar04,1,3559963.story. Retrieved March 4, 2008.
- Brookes, Peter (March 13, 2008). "Flashpoint: The Cyber Challenge: Cyber attacks are growing in number and sophistication". Family Security Matters. http://www.familysecuritymatters.org/homeland.php?id=1386912. Retrieved April 7, 2008.
- Riley, Michael, and Dune Lawrence, "Hackers Linked to China’s Army Seen From EU to D.C.", Bloomberg L.P., 27 July 2012
- Elegant, Simon (November 18, 2009). "Cyberwarfare: The Issue China Won't Touch". Time Magazine. http://www.time.com/time/world/article/0,8599,1940009,00.html. Retrieved October 25, 2010.
- Beech, Hannah. "Meet China's Newest Soldiers: An Online Blue Army." Time Magazine, May 27, 2011.
- Claburn, Thomas. "China Cyber Espionage Threatens U.S., Report Says". InformationWeek. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=221900505. Retrieved November 1, 2010.
- Cha, Ariana Eunjung and Ellen Nakashima, "Google China cyberattack part of vast espionage campaign, experts say," The Washington Post, January 14, 2010.
- McMillan, Robert. "Report Says China Ready for Cyber-war, Espionage". PC World. http://www.pcworld.com/article/174210/report_says_china_ready_for_cyberwar_espionage.html. Retrieved November 1, 2010.
- "Google cyberattack hit password system" NY Times, Reuters, April 19, 2010.
- Jacobs, Andrew; Helft, Miguel (January 12, 2010). "Google, Citing Attack, Threatens to Exit China". The New York Times. http://www.nytimes.com/2010/01/13/world/asia/13beijing.html?_r=1. Retrieved November 1, 2010.
- Zetter, Kim. "Google Hackers Targeted Source Code of More Than 30 Companies". Wired. http://www.wired.com/threatlevel/2010/01/google-hack-attack/-. Retrieved November 1, 2010. [dead link]
- "US embassy cables: China uses access to Microsoft source code to help plot cyber warfare, US fears". The Guardian (London). December 4, 2010. http://www.guardian.co.uk/world/us-embassy-cables-documents/214462?INTCMP=SRCH. Retrieved December 31, 2010.
- "China mounts cyber attacks on Indian sites". Times of India (India). May 5, 2008. http://timesofindia.indiatimes.com/China_mounts_cyber_attacks_on_Indian_sites/articleshow/3010288.cms. Retrieved October 25, 2010. Cite error: Invalid
<ref>tag; name "ind" defined multiple times with different content
- "Foreign hackers attack Canadian government". CBC. February 16, 2011. http://www.cbc.ca/politics/story/2011/02/16/pol-weston-hacking.html. Retrieved February 17, 2011.
- Halliday, Josh (September 24, 2010). "Stuxnet worm is the 'work of a national government agency'". The Guardian (London). http://www.guardian.co.uk/technology/2010/sep/24/stuxnet-worm-national-agency. Retrieved September 27, 2010.
- Hounshell, Blake (September 27, 2010). "6 mysteries about Stuxnet". Foreign Policy. http://blog.foreignpolicy.com/posts/2010/09/27/6_mysteries_about_stuxnet. Retrieved September 28, 2010.
- "The Stuxnet worm: A cyber-missile aimed at Iran?". The Economist. September 24, 2010. http://www.economist.com/blogs/babbage/2010/09/stuxnet_worm. Retrieved September 28, 2010.
- Miks, Jason. "Was China Behind Stuxnet?". The Diplomat. http://the-diplomat.com/china-power/2010/10/21/was-china-behind-stuxnet/. Retrieved October 25, 2010.
- "Stuxnet 'cyber superweapon' moves to China". Yahoo! News. http://news.yahoo.com/s/afp/20100930/tc_afp/chinagermanyitsecurity. Retrieved October 25, 2010.
- Wolf, Jim (November 19, 2010). "Pentagon says "aware" of China Internet rerouting". Reuters. http://www.reuters.com/article/idUSTRE6AI4HJ20101119. Retrieved November 26, 2010.