Chinese Hackers Exploit Zero-Day Acrobat Security Hole in Heist on Google and Other Companies
Chinese hackers exploited a zero-day security hole in Adobe Reader to breach the defenses of Google and other companies, including Adobe itself, according to iDefense, the VeriSign managed security unit. This sophisticated cyber-attack, dubbed Project Aurora, targeted employees with administrative access and inserted a Trojan horse into the machines, creating a backdoor for the hackers to scoop out proprietary source code, intellectual property, and other sensitive information. The attack bears similarities to another cyber-attack on 100 tech companies last July, and experts believe that the targets could have been compromised since then.
Key Takeaways:
- The zero-day security hole in Adobe Reader was exploited by Chinese hackers to breach the defenses of Google, Adobe, and other companies.
- The attack, dubbed Project Aurora, targeted employees with administrative access and inserted a Trojan horse into the machines, creating a backdoor for the hackers to scoop out proprietary source code, intellectual property, and other sensitive information.
- The hackers used e-mail containing a corrupt PDF file to deliver the Trojan, which was released when opened by employees with administrative access.
- The attack bears similarities to another cyber-attack on 100 tech companies last July, and experts believe that the targets could have been compromised since then.
- The investigation has linked the attack to a foreign entity, possibly the Chinese state or its proxies, and identified a XEN VPS hosting company in New Jersey as the IP address track back to.
- McAfee claims that a vulnerability in Internet Explorer let the hackers in, but Adobe and Microsoft disputed this claim.
- Adobe confirmed that the attack it experienced appears connected to the attack on Google, and Google stated that the attack netted the hacker some unidentified intellectual property.
Statistics:
- Over 30 companies were targeted in the attack, more than the 20 mentioned in Google's initial disclosure.
- The attack on Google was described as "sophisticated" because of the employees targeted.
- The hackers used a corrupt PDF file to deliver the Trojan, which was released when opened by employees with administrative access.
- The investigation has linked the attack to a foreign entity, possibly the Chinese state or its proxies.
- The stolen code was stored on servers at Rackspace, another hoster which says it's been assisting in the investigation.
- The command-and-control servers are somewhere in Taiwan.
Sources:
- iDefense, "Chinese hackers target Google, Adobe, and other companies" [1]
- McAfee, "McAfee Statement on Project Aurora Attack" [2]
- Adobe, "Security incident" [3]
- Google, "Security incident" [4]
- Dark Reading, "Investigation Uncovers Complexity of Aurora Attack" [5]