Mandiant says it has documented 141 hacking intrusions led by Comment Crew since 2006. Given the IP addresses and clues gleaned from individual members with hacker handles including UglyGorilla and DOTA, the authors conclude that the campaign is almost surely sponsored by the Chinese government or military. The only other option, according to the report: “A secret, resourced organization full of mainland Chinese speakers with direct access to Shanghai-based telecommunications infrastructure is engaged in a multi-year, enterprise scale computer espionage campaign right outside of Unit 61398’s gates, performing tasks similar to Unit 61398’s known mission.”
According to Mandiant, Comment Crew has for years vacuumed up the proprietary secrets of more than 100 targets, including technology blueprints, manufacturing processes, clinical trial results, pricing documents, and negotiation strategies. Of more concern, Comment Crew hackers have most recently tuned their focus to computer systems used to control dams, gasoline refineries, and other critical infrastructure. One recent target is the Chertoff Group, which is headed by the former secretary of the Department of Homeland Security, Michael Chertoff. Other targets include the National Geospatial-Intelligence Agency, the National Electrical Manufacturers Association, and the Canadian arm of Telvent. As Ars reported in September, hackers compromised the company, which provides software that allows oil and gas pipeline companies to remotely monitor and control sensitive equipment.
“This is terrifying because—forget about the country—if someone hired me and told me they wanted to have the offensive capability to take out as many critical systems as possible, I would be going after the vendors and do things like what happened to Telvent,” Dale Peterson, who is CEO of industrial control security firm Digital Bond, told the NYT.
The article also recounts a recent attempt to compromise Digital Bond itself by purportedly sending a fraudulent e-mail from Peterson to a part-time employee. The message, which used perfect English to discuss a security weakness in industrial systems, was laced with malware that “would have given the attackers control over the employee’s computer and potentially given them a front-row seat to confidential information about Digital Bond’s clients, which include a major water project, a power plant, and a mining company.”