Unit 61398 - Could Avast help with Chinese Cyber Attacks?

I woke up this morning to hear about how the Chinese military are hacking into hundreds of US sites!
I found the original 76 page pdf from Kevin mandria’s Mandriant.com at:

http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf

Wow. This is no joke.

“China’s Computer Network Operations Tasking to PLA Unit 61398 (61398)” is said to be responsible for stealing our secrets.
More correctly, 141 hacking attacks (115 in US) have been traced back to a Chinese group, identified as Unit 61398. Beginning in 2006, energy, aerospace etc. firms had blueprints, contact lists, etc. stolen in cyber attacks. Hearing that make you want to read the entire 76 page Mandiant report. See link above. Know that it is a slow read.

Are all these computers being hacked by worms and viruses? or what? I’d like to hear what you suggest they do.

Do I have a chance if our military / top secret web sites are being attacked and compromised?

I’d like to know what Avast think about this.

Once you get past the jaw-drop, it’s simply a ‘shock and awe’ cyber threat. Simply scary.

docp

This is also nothing new and something that’s carried on by all the “Super Powers”.
There aren’t any angels in Cyber Space. :cry:

Hio docp,

3000 alerts to notice, detect or protect against reported there: http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip
You have read this report. China is no other than any other great power and acts accordingly.
It also protects users and acted for instance against mainland China hacker rings, like the BlackHawk that took a online training (alsoft_exploit_pack/injector etc.)
Good advice is to know where you are going on the Internet, to never open input you are not expecting. Do not react to social engineering.
Use script blocking and request policy blocking. The avast shields will also enhance your security greatly.
If you have nothing to hide, you have nothing to fear…

polonus

There is a video here :

https://www.youtube.com/watch?feature=player_embedded&v=6p7FqSav6Ho

To be honest, the U.S. is ill-prepared for a cyber attack. There is a lot to gain from hacking U.S companies than chinese companies. Lots of patents and technology. They can just get it without spending a buck in research or time by sitting in a building in Shanghai.

Well, there is not a silver bullet to protect ourselves but there is something we can do.

Just don’t click any email you don’t know and block all ports using a good firewall and keep your Windows updated and stop using Java or similar software with vulnerabilities and use a sandbox while browsing and use a VPN that doesn’t log and change your DNS to a secure DNS.

And,

Watch out for Spear-phishing.

An example :

http://cdn-static.zdnet.com/i/story/60/80/004791/phishcamp_linkedin_bill_gates_experiment.jpg

https://now-static.norton.com/now/en/pu/images/Non-Product/Misc/pull_quotes/img_spear_phisher_242x170.png

This added to avoid one-sidedness…
Commentary from China: http://news.xinhuanet.com/english/indepth/2013-02/20/c_132181511.htm (link article English dot news dot cn’s author Editor: Liu )

polonus

https://en.wikipedia.org/wiki/Xinhua_News_Agency

“Fear has big eyes” (a popular Russian proverb). I have the impression that the West is afraid of China more than it deserves. They are spying on the West and the West is spying on them - as they say, it’s all on a reciprocal basis. And all the lamentations about the “Chinese cyber threat” is a banal extortion of funding from state budgets during the global financial crisis.

Seemingly the report did not have much effect, meaning back to business as usual for the APT1-attackers, according to this report from Steven Adair: http://blog.shadowserver.org/2013/02/22/comment-group-cyber-espionage-additional-information-clarification/

polonus

Did you really expect anything else ??? :frowning: