Risk
5/2/2013
01:02 PM
50%
50%

China Tied To 3-Year Hack Of Defense Contractor

U.S. defense contractor QinetiQ ignored persistent attack warning signs, lost terabytes of secret information, say investigators.

Anonymous: 10 Things We Have Learned In 2013
Anonymous: 10 Things We Have Learned In 2013
(click image for larger view and for slideshow)
For three years, boutique defense contractor QinetiQ was compromised by an advanced persistent threat (APT) attack group operating from China. During that time, attackers accessed information about cutting-edge U.S. military drone and robot weapons systems and brought competing products to market.

Those allegations surfaced against QinetiQ North America Wednesday in a report from Bloomberg, which cited investigators hired by QinetiQ -- as well as HBGary emails that were stolen and leaked by Anonymous -- as sources. HBGary was one of several firms hired by the defense contractor to investigate apparent intrusions.

Investigators told Bloomberg that the ongoing attacks against QinetiQ (pronounced "kinetic") were launched by the Shanghai-based Comment Crew. Earlier this year, a report from security firm Mandiant tied the group -- which it dubbed APT1 -- to attacks that compromised 141 businesses, none of which it named, across 20 industries. According to Mandiant, the attackers weren't just supported by China, but actually part of the People's Liberation Army (PLA) Unit 61398, which is an elite military hacking unit. Chinese officials denied those allegations.

[ How should your business react to the Chinese allegations? Read China Hack Attacks: Play Offense Or Defense? ]

Investigators hired by QinetiQ said that despite ongoing warnings from numerous organizations, including NASA and the Naval Criminal Investigative Unit, that the defense contractor's networks had been compromised, QinetiQ officials failed to realize that attackers were maintaining a persistent presence in their network and react accordingly.

"We found traces of the intruders in many of their divisions and across most of their product lines," Christopher Day -- until February, a senior VP at Verizon’s Terremark security division, which QinetiQ twice hired to investigate apparent intrusions -- told Bloomberg. "There was virtually no place we looked where we didn't find them."

As a result, investigators said that terabytes of data, including classified information relating to military robotics, drones and the Army's helicopter fleet, including PIN codes that could now be used to identify helicopters' deployment and combat-readiness, were stolen.

A QinetiQ spokesman didn't immediately respond to an emailed request for comment on the report, or what information security changes the business might have made as a result.

Attacks that aim to steal military secrets from defense contractors and their subcontractors are nothing new. A 2010 report from the Defense Security Service branch of the Department of Defense warned that "the United States' technical lead, competitive edge, and strategic military advantage are at risk; and our national security interests could be compromised" by what it said were an escalating number of "pervasive, relentless, and unfortunately, at times, successful" information security attacks against defense contractors.

But many reported incidents, such as the theft of information relating to the advanced Lockheed Martin F-35 stealth fighter jet in 2009, have been far more extensive than public accounts have suggested. Interestingly, China conducted the first test flight of its own stealth fighter in November 2012. Meanwhile, Bloomberg reported that the theft of information relating to the Lockheed Martin F-22 Raptor lead some intelligence officials to suggest that it might be unsuitable for combat because stolen information might be used to compromise critical systems.

The QinetiQ hack attack campaign recalls the 10-year breach of Nortel, during which time attackers maintained a persistent presence inside the company's network. Attackers stole numerous telecommunications and networking secrets, despite persistent signs that the Nortel network had been compromised.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?