Also known as: Snooping Dragon
Cyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigation of alleged Chinese cyber spying against Tibetan institutions. The investigation, consisting of fieldwork, technical scouting, and laboratory analysis, discovered a lot more. The investigation ultimately uncovered a network of over 1,295 infected hosts in 103 countries. Up to 30% of the infected hosts are considered high-value targets and include computers located at ministries of foreign affairs, embassies, international organizations, news media, and NGOs. The Tibetan computer systems we manually investigated, and from which our investigations began, were conclusively compromised by multiple infections that gave attackers unprecedented access to potentially sensitive information. Attacks on the Dalai Lama’s Private Office The OHHDL started to suspect it was under surveillance while setting up meetings be-tween His Holiness and foreign dignitaries. They sent an email invitation on behalf of His Holiness to a foreign diplomat, but before they could follow it up with a courtesy telephone call, the diplomat’s office was contacted by the Chinese government and warned not to go ahead with the meeting. The Tibetans wondered whether a computer compromise might be the explanation; they called ONI Asia who called us. (Until May 2008, the first author was employed on a studentship funded by the OpenNet Initiative and the second author was a principal investigator for ONI.)
Executive Summary
GhostNet, also known as Snooping Dragon, is a cyber espionage group believed to originate from China. They primarily target high-value assets across various sectors including government, media, NGOs, and diplomatic entities. Their activities are focused on gathering sensitive geopolitical information for intelligence purposes.
Goals & Targeting
GhostNet's primary goal is cyber espionage, focusing on gathering sensitive information from governments, NGOs, and international organizations. Their targeting strategy is driven by geopolitical interests, particularly in regions considered vital to Chinese strategic objectives. The group's focus on high-value targets reflects an intent to influence policy-making and diplomatic processes.
Enhanced Description
GhostNet emerged in 2009 as part of an investigation into alleged Chinese cyber espionage against Tibetan institutions. The group has been known to infect over 1,295 hosts across 103 countries, with significant concentrations in ministries, embassies, and international organizations. Their operations are characterized by advanced persistent threat (APT) tactics, including long-term access and data exfiltration. GhostNet's sophisticated campaigns often involve tailored attacks using zero-day exploits and spear-phishing emails, enabling them to maintain undetected presence for extended periods. Despite being linked to the 2009 investigation, new variants of their malware continue to emerge, underscoring their adaptability and operational continuity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GhostNet's campaigns are characterized by their persistence and adaptability. They often initiate attacks through spear-phishing emails and exploit kits to establish initial access, followed by lateral movement within the network. Notable operations include targeting the Dalai Lama’s private office in 2008-2009 and compromising Tibetan institutions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the assessment of GhostNet as an APT group given extensive reporting and analysis linking it to multiple high-profile compromises. However, gaps exist regarding the full extent of their toolkit and long-term operational strategy.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics