- The Internet is such an incredible enabler for business that companies can hardly imagine how work ever got done without it.
- Unfortunately, the Internet is also a great enabler for industrial espionage.
In 2009, and possibly earlier, the Night Dragon came after global oil, energy and petrochemical companies. It’s only now that those firms are discovering what data the beast ripped out of their networks. The persistent targeted attacks aimed to harvest sensitive competitive proprietary operations and project-financing information with regards to oil and gas field bids and operations.
“This was all about stealing very key intellectual property from those oil and gas companies,” said Greg Day, director of EMEA security strategy for McAfee. “We certainly have evidence that the attacks started back in 2009 and potentially even earlier than that. It has taken so long for these attacks to come to light because Night Dragon, like other Advanced Persistent Threats (APTs), was made up of a number of different facets. I think what happened in this instance is some of those businesses may have seen parts of the attack and just defended those bits, but it has taken until now to link up all of those different elements to understand the bigger picture.”
Several energy companies, believing their networks to be compromised, brought in McAfee’s Foundstone Professional Services to do a forensic examination of their network resources. The hackers used known techniques and were sloppy in covering their tracks. Once network forensics experts began looking for the hackers’ trails, the industrial espionage was exposed.
“What we uncovered were four links to China,” Day said. “Now the hard thing about that is does it point the finger at China or is that misdirection at China? If data is stolen it has to go somewhere onto the Internet. The hackers used a third party hosting service and the person who ran that service was based in the Shandong Province in China. He very clearly offered what he called ‘bulletproof hosting’ with no logs kept.”
Day continued, “We also then discovered that a lot of the hacking tools used during this attack were found on a Chinese underground hacking website. One of the passwords within the Remote Access Trojan component actually had China within the password. I think probably the strangest facet of all, was that we only saw communication with the compromised systems during the working day Chinese time — literally 9 to 5 during their working week.”
Night Dragon involved social engineering, spear-phishing attacks, exploitation of Microsoft Windows operating systems vulnerabilities, Microsoft Active Directory compromises and the use of remote administration tools (RATs). According to McAfee, to use the RATs, the hackers first compromised network perimeter security controls through SQL injection attacking the energy company’s extranet web servers.
“Once they had compromised the extranet web servers, that allowed the hackers to break through the energy firm’s front door, so to speak,” commented Day. “Then they used a variety of fairly well known hacking tools to look at the Active Directory tree to understand the organization better and then move around inside in the internal network. This wasn’t an automated malware attack. After they found the data they were looking for, they removed it through the same tunnel they had used to enter the network. In some instances the laptops of very senior employees were attacked and a vulnerability in the virtual private network (VPN) software was used to penetrate corporate network defenses as well.”
McAfee believes the Night Dragon attacks should be a warning to enterprises that industrial espionage is on the rise. The tools employed in the Night Dragon attacks could be used against any industrial or commercial operation. In the past, attacks were more random and opportunistic. While such activity continues, hackers have become more sophisticated in hunting prey online.
“We definitely now are seeing more of these targeted attacks where criminals keep knocking and knocking at a network's door until they get in,” said Day. “These attacks are either about intellectual property (IP) theft or taking away control of service, modifying service or ransoming service. Enterprises need to take action to discover the assets in their environments, assess their configurations for vulnerabilities and protect them from misuse and attack.”

