Chinese Hackers Exploit Zero-Day Acrobat Security Hole in Heist on Google and Other Companies

Chinese hackers exploited a zero-day security hole in Adobe Reader to breach the defenses of Google and other companies, including Adobe itself, according to iDefense, the VeriSign managed security unit. This sophisticated cyber-attack, dubbed Project Aurora, targeted employees with administrative access and inserted a Trojan horse into the machines, creating a backdoor for the hackers to scoop out proprietary source code, intellectual property, and other sensitive information. The attack bears similarities to another cyber-attack on 100 tech companies last July, and experts believe that the targets could have been compromised since then.

Key Takeaways:

  • The zero-day security hole in Adobe Reader was exploited by Chinese hackers to breach the defenses of Google, Adobe, and other companies.
  • The attack, dubbed Project Aurora, targeted employees with administrative access and inserted a Trojan horse into the machines, creating a backdoor for the hackers to scoop out proprietary source code, intellectual property, and other sensitive information.
  • The hackers used e-mail containing a corrupt PDF file to deliver the Trojan, which was released when opened by employees with administrative access.
  • The attack bears similarities to another cyber-attack on 100 tech companies last July, and experts believe that the targets could have been compromised since then.
  • The investigation has linked the attack to a foreign entity, possibly the Chinese state or its proxies, and identified a XEN VPS hosting company in New Jersey as the IP address track back to.
  • McAfee claims that a vulnerability in Internet Explorer let the hackers in, but Adobe and Microsoft disputed this claim.
  • Adobe confirmed that the attack it experienced appears connected to the attack on Google, and Google stated that the attack netted the hacker some unidentified intellectual property.

Statistics:

  • Over 30 companies were targeted in the attack, more than the 20 mentioned in Google's initial disclosure.
  • The attack on Google was described as "sophisticated" because of the employees targeted.
  • The hackers used a corrupt PDF file to deliver the Trojan, which was released when opened by employees with administrative access.
  • The investigation has linked the attack to a foreign entity, possibly the Chinese state or its proxies.
  • The stolen code was stored on servers at Rackspace, another hoster which says it's been assisting in the investigation.
  • The command-and-control servers are somewhere in Taiwan.

Sources:

  • iDefense, "Chinese hackers target Google, Adobe, and other companies" [1]
  • McAfee, "McAfee Statement on Project Aurora Attack" [2]
  • Adobe, "Security incident" [3]
  • Google, "Security incident" [4]
  • Dark Reading, "Investigation Uncovers Complexity of Aurora Attack" [5]