<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Cyber Crime</title>
	<atom:link href="http://www.thedarkvisitor.com/category/china-internet/cyber-crime-china-internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Unemployed PRC prick hacks TV contestants&#8217; webcams (RSA tokens probably not involved)</title>
		<link>http://www.thedarkvisitor.com/2011/05/unemployed-prc-prick-hacks-tv-contestants-webcams-rsa-tokens-probably-not-involved/</link>
		<comments>http://www.thedarkvisitor.com/2011/05/unemployed-prc-prick-hacks-tv-contestants-webcams-rsa-tokens-probably-not-involved/#comments</comments>
		<pubDate>Tue, 31 May 2011 02:38:37 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[cam]]></category>
		<category><![CDATA[nowedonthavethepics]]></category>
		<category><![CDATA[stalking]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2272</guid>
		<description><![CDATA[More than two years after Heike&#8217;s post about the Kapa girl video, a narrow majority of our visitors come to TDV from searches for her video. Sadly, I&#8217;m about to post something that will continue this trend of optimizing our site for desperate porn searchers. So apparently the show 非诚勿扰 (If you are the one) [...]]]></description>
			<content:encoded><![CDATA[<p>More than two years after Heike&#8217;s post about the <a href="http://www.thedarkvisitor.com/2008/11/chinese-hacker-and-the-kappa-girl-video/">Kapa girl video</a>, a narrow majority of our visitors come to TDV from searches for her video.  Sadly, I&#8217;m about to post something that will continue this trend of optimizing our site for desperate porn searchers.</p>
<p><a href="http://www.youku.com/show_page/id_z48d616e6159c11e097c0.html"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2011/05/Screen-shot-2011-05-30-at-10.27.02-PM-300x226.png" alt="" title="非诚勿扰" width="300" height="226" class="alignleft size-medium wp-image-2273" /></a></p>
<p>So <a href="http://www.penn-olson.com/2011/05/28/webcam-hacker-stalker-spies-girls/">apparently</a> the show 非诚勿扰 (If you are the one) is a dating\reality program that actually displays the contestants&#8217; QQ numbers and email addresses.  An unemployed PRC hacker used the information to target some of his favorites with a social engineering scam that included a malicious program that let him control the victims&#8217; webcams.  After capturing some nudy pics, he attempted to extort money from the victims and one or more of them went to the cops and he quickly realized that he done goofed because he was backtraced and will spend the next three years in prison.<br />
<img src="http://www.thedarkvisitor.com/wp-content/uploads/2011/05/Screen-shot-2011-05-30-at-10.32.08-PM-300x226.png" alt="" title="ID59406668" width="300" height="226" class="alignleft size-medium wp-image-2274" /></p>
<p>Thanks to Greg <a href="http://twitter.com/#!/metalabasia">@metalabasia</a> for the link.</p>
<p>Sorry, I don&#8217;t have the pics.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/05/unemployed-prc-prick-hacks-tv-contestants-webcams-rsa-tokens-probably-not-involved/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>FBI: $11 million worth of unauthorized wire transfers to China</title>
		<link>http://www.thedarkvisitor.com/2011/04/fbi-11-million-worth-of-unauthorized-wire-transfers-to-china/</link>
		<comments>http://www.thedarkvisitor.com/2011/04/fbi-11-million-worth-of-unauthorized-wire-transfers-to-china/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 12:53:28 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[China Russia Links]]></category>
		<category><![CDATA[Cyber Crime]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2258</guid>
		<description><![CDATA[Very interesting report via the Financial Services Information Sharing and Analysis Center, in cooperation with the FBI, on unauthorized wire transfers to China.  When I say &#8220;interesting,&#8221; I mean I don&#8217;t understand it&#8230;not sure what the implications are, if any.  Get the basics of the report, just not sure who the perp is supposed to [...]]]></description>
			<content:encoded><![CDATA[<p><img id="rg_hi" class="aligncenter" src="data:image/jpg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBhQSERUUEhQUFRUVGRkaGRgYFB0WHRYbFBgVFxgaFRYXHSYfFxkjHBcXHy8gIycqLCwsFx8xNTAsNSYsLCkBCQoKDgwOGg8PGiwlHCQqKiwpLCwpKSwsLCkqLCwpLCkpLSwsLCkpKSwsLCkpKSwpLCkpMSwsKSkpKSkyKS0pLP/AABEIAIwAjAMBIgACEQEDEQH/xAAcAAABBQEBAQAAAAAAAAAAAAAAAQQFBgcCAwj/xABAEAACAQIFAQUECAQCCwAAAAABAgMAEQQFEiExQQYTIlFhMnGBkQcUQnKhscHRI1Ji8BWyCCQlMzV0goOSosL/xAAZAQEAAwEBAAAAAAAAAAAAAAAAAgMEAQX/xAAmEQACAgEEAQQCAwAAAAAAAAAAAQIRAwQSITEiE0FxsSNRMpGh/9oADAMBAAIRAxEAPwDcaKKKAKKKKAKKKKAKKQmk10sHVFcGSl11y0DqikvReugWikpaAKKKKAKKKKAKKKKAKKKS9ABpnmOaxwKWkYKB/fFQ/afthHhF38Tt7Kg7n1PkPWsxxmZy4uXU+5OyqOB6KP1rz9TrFj4j2VTyV0WzNfpGkYkYdVVejMLk+oXp+NeWW9qGlHd4hpNwfGmrUd/JLAWHpUR/g7IoLden7kbVP5Dmq4WJrANI54tbTYW8THkdbCvJWpnOf5Jcf4Z1Nt8sfrg10mSJ2ZQDeOUldrcqSpa9McJjUmhYxSSQSqQG1E7G3AF+PdTnD9sZFADKrm5JJOnY8AAcW9asuWMssayAbN5jfk7GteL08z/G/v8AtFiqX8WUvDdr8Rh30TtrU8MAG9xttqHyqzL2uVDaYaR/OtyovxrBGqP47etO81yWOZbOt/I8Mvqp6Gu1wSPe6qXtpLWFyN7XPUHy99aYYs+N0pX8k4qS9yQhmDAFSCDwRvXpeqHm+ZyYMkYcC8e5j+zKlrm38rrz7jfcVZOzfaWLGR64zuNmU+0h8iPyPWtOLOp+L7JxlZM0UgoBrSTFooooAoopDQATURnWbCNHP8g39SfZUepNvnT3MsV3aFuvA954qi57hZjGPGGUB5GJFj/DRiuoja2s7bcisWpzbVtXZXOVcGfYvFvNMzyG7Em/kNzsPQVK5emmxFwR1FR2Dw3AAv8AGtCw/Y9Eiu4m1WvcKLDbgAXuL14jxzy3tMtOXRApLtXvh4Gc2RWYjoBf5+lOJMiYSiMN9m7EoRp3sfMn0q65Pg44Iwq7k7ltJux6k7belc0+ilkl5cJCGNyfJF5XlGIj0eCILcavCCwB5JJ6+41LYvASSFO7kEYRyT4b342+Wr50/OJH9g/tTaLFgE7/AGj517cMGPEtqbNSioqh9pphjT3ZEnQe1908/LZvgacHGAdT/wCJ/amWYYwFftH/ALbn/wCavm1Vok2Me0eGSS2xBUq2pdr6SbC/la/wNZiDLgsythX8fJVvCrhhrMe2xB+ydt7Vf8uxgMZDLKTEdPsEXAtp5t9nTVK7aSxtIMQIWVoxyXVdYHAYC5+Isa83I/LfdMzydOzXcnzRMRCsqcMNweVI2ZW9QdqeVjn0advbYpo8Q2kTlQgA218Ak9CePlWyCvUxT3xv3NEJblYUUUVaSCkJpaQ0BXc9xGqZUH2Rc+88fhTXH5U2Iw0iIQGksFvxZDsD6GxprPibzSt5EgfDwj8as2AisoHkBXkY2s2ST9rM8fJuzH8fgZMJJoksGABBG462IPXirNlfbmbEyxwl4oQSNT23Om2w1GwJNqne2PY765Z1fQ6KwAtcMTuurqBesiIfDTqJ4iCjKxjfbUAbjfgg25qp4ZaefD8ftHKcXx0blmWWMxDR6Q3XVfp92iDHyRsqSREg/bjJdR964BX8ahR9JGH/AIVwwLoHbcWiBH2j1byABNO8v7eYSfbXoJ2tItrg8eYt7633jUrjKmW+N8MmYM0SRiqOraebHj4V64cXLfeP5CljwyA3UKPcAPypMN7TfeP5Cr0nxZL5HFq5Za7Nc1bRIpOfYox4hlXiRRceqkg/gy/Kq1m2Rs8MzEHZGPyF6ufaeDS8cgW+5B/6lP62qGzDtShj0lfaUqbeRGn9a8jJpVKblN9dGSUfLkxZGsQRsRYgjoQQQR63t8q+ocpzNMRDHLGQVdQwI9eR7wbj4V8t4pdLFfIkfKti+g7NNWGlgJ3jk1D7rgH8616Zu6LIS5o06iiitpeFcvXVctXGDN8HjVYvvv3niHUePe4q14LOUO29VR8CpldWUHTKRfggFtrEbjmrLhcmjiGsyFVG5LkFR7y3714Wk321D9mXHd8E+u4rKPpWiZ8VGo4WMfNmY/oPlWmR5lHsO9iNzpFmAuSL2Fibm3SorMsqgxMmsyJc+DZgfEouV2+0L8c162XG5wo0SVoxdcubyp/hcEw861B+ycChizoAvtEkALwfETxsRz510vZ2AX8aeEaidQ2U7gnfYW3vWGWjbKvSZ4dlu09lWOfpsH8wNgGHTyvVqwpuW+9+1QOGy/DkKVljIY2WzDxHyG/PpzUxhLRhhqWy7nf2QRcX8hYVrwxyR4mWRTXY9Y2ppLmIHN66XGK6akYOpGxUhgfcQd6icWhc8H5gfrWhyok2Q3aPOdYsASAy/nVVly8tc6dvK/FW7MsKQuyLyvLf1DyBpgcPJY37seVgW/Mj8qojplKdsyt82zPM37O3fWt128QZTv7iNquv0L5MY2xUlwVOhBbz06j8rj516zZYJFcOzMApNvZH/rapr6MsNoimtspZNrWsQgufjt8qjHHLHmr2pjG25l1ooorYawpDS0hoCl53hdGJY9H0uPepF/yqUz/BNNl+IiiXU8kMiKLgXLoVG52Auac9ocFqUOOU/EHmmWbozYFgjlG8Fm0M42ZT41TxGM8NboTWDDj9PNJfvlFUVUmNcZkEn+o6QzmPELLIWCgqqxSIBta+nWALdBXnhOzssWLGIjWySNKZ4tgWZe87iVLGwYhtDeY034qIlGIcYLVGEIlxIk0CZoSuh9DEbOI2e2lW4PG1Lm0cgxiyRCfuEXAk7SX095MsluQTpaIyAgkr5Het5aPocmxKSYq8feR4uJXYC1lnF0ZCGY3DR6BfjwetecvZCdIZoIzqhSXDPAt9zDFL3z4drngEsq32sVB4p5k2WyRyYmGRXMMLySQuSx1jEJqCc3Pd3kX3FPKovIo5RFl/1oS9yMI4kBDk/WLx27we1r0a7E9b23tQE3meAklmw0i4coI8UZHN1uVEEkesi/JZlFtzZa8MPl2JTGvP3ZKYqFhKu143iJ7i4LENdGZDp8gabxRH/EGZhL3Iiwltayk6v419BBsJL91ruOL3r37DiZZZFkCuuhSswWSNj4mOnERyeHvrNcsnTnpQHv2WwUsWCw+HljKPDCilrqQWA8QBUnYW563qTmNjUp3fJ9Nqj5cOxOw5quubI0R+MFwPePzvXnJgxpp82XksFJA6/pXtLhPD+H41fCXNlUo2VV4rBvcan+xmF0QE/wAzX+AFhXL5YrSMttiBv5c3qwRxhQABYDYVybUpWhjhzZ3RRRUS8KKKKA5Zb1F4qOSKN+50XF2Gu5FgCT7Jvepam+Yf7qT7jf5TUdquwU/6Ne2k+ZwtO6RRxq7JpUuzXCqb3O1vFxapaLNJ8Q8v1XuVjidoy8gZ9cibOFVGXSqnw6iTuDttVM/0d/8Ahkn/ADDf5IqZZnludZXiJ3wCLicLLI83dkBihkJZhpuGG/VTY1IGidnc5mmkxEc8SxtAyKNLlw4dA+tSQPCb7C1x1p3m2ZmLTYaiTuP6R7R9/l76rn0ddvhmKyrLD9XxMJAljN+DcKw1AMNwRY8fGllzTvZJZDLGi+zEGFy4W+/tCwJvv1vQFxD3AI3B49b1WsJ2mfFzSx4IRmOB9Ek8l2UycskSIQXt1YsBxa/RlLnzJl+M0m8kMMroRcXXQxUi+/hO3y3qH/0fB/spj5zyX9dkFAWhM6xEeLhw08SHvu8ImjYhD3S30lGuVfja5FrkHoLEUGx8qSSIEg2FxxtxcEbHpyfnXMp253NcYOES7E/CkxGJVefw33odVUb7/wB+VcwwFjqYWHQeXqfWq+ekR+BcLER4m5bn0HlTsUmmlFWJUqJIWiiiugKKKKAKj85xqxwuXNgQQLKW3INhZQTUhRQGVfQKpgwTwTLJHKZncI8bodISMXuy2tsasHZXtUUw6rjllikBcB5EYiVFdgjagDZtNrqbHruLVdbUlqAoEoviMTjEjdRiEigj8BVnWPU0krAgEA6lRb7nTfqK6xORxFVCrL/VpNgRzZiwvsb+ova9X21IRQGcnB905dlJR9StGqHSI3BVl2J5W58r112BwwyhJcJOWERkMkE+klJEcLsxUeCQW3DWvfatD0etGj1pYKvL2iklxmHSBJPqx70yzFCFYiNtCLqsSL76uLgC9TOKkezFB4rbX49Kf92K6AqDjuOHimGGxO5869rUtFSSo6FFFFdAUUUUAUUUUAUUUUAUUUUAUUUUAUUUUAUUUUAUUUUAUUUUAUUUUB//2Q==" alt="" width="189" height="165" /></p>
<p>Very <em>interesting</em> report via the Financial Services Information Sharing and Analysis Center, in cooperation with the FBI, on unauthorized wire transfers to China.  When I say &#8220;interesting,&#8221; I mean I don&#8217;t understand it&#8230;not sure what the implications are, if any.  Get the basics of the report, just not sure who the perp is supposed to be? Chinese, Russian, US?  So, smart blog reading people help me out.  Full PDF report on the <a href="http://www.ic3.gov/media/2011/ChinaWireTransferFraudAlert.pdf">unauthorized wire transfers here</a> and the two paragraphs that have me scratching my head:</p>
<p><span style="font-size: small;">&#8220;<em>The unauthorized wire transfers range from $50,000 to $985,000. In most cases, they tend to be above $900,000, but the malicious actors have been more successful in receiving the funds when the unauthorized wire transfers were under $500,000. When the transfers went through successfully, the money was immediately withdrawn from or transferred out of the recipients’ accounts.</em></span> </p>
<p><em>In addition to the large wire transfers, the malicious actors also sent domestic ACH and wire transfers to money mules in the United States within minutes of conducting the overseas transfers. The domestic wire transfers range from $200 to $200,000. The intended recipients are money mules, individuals who the victim company has done business with in the past, and in one instance, a utility company located in another U.S. state. The additional ACH transfers initiated using compromised accounts range from $222,500 to $1,275,000</em>.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/04/fbi-11-million-worth-of-unauthorized-wire-transfers-to-china/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Thinking like a Chinese hacker 101: Panic is your friend</title>
		<link>http://www.thedarkvisitor.com/2011/03/thinking-like-a-chinese-hacker-101-panic-is-your-friend/</link>
		<comments>http://www.thedarkvisitor.com/2011/03/thinking-like-a-chinese-hacker-101-panic-is-your-friend/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 12:15:11 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Evil and/or Stupid]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2228</guid>
		<description><![CDATA[Think the Google vs. China gmail debate made the top 10 list in China?  Nope, according to Baidu&#8217;s weekly focus, the aftermath of the &#8220;Salt Panic&#8221;  was on everyone&#8217;s mind.  This was due to the mistaken belief that the iodine content in salt could help with the effects of radiation poisoning.  Prior to that, Chinese [...]]]></description>
			<content:encoded><![CDATA[<p><img src="file:///C:/Users/ssjhende/AppData/Local/Temp/moz-screenshot.png" alt="" /></p>
<p><img class="aligncenter" title="Salt" src="http://www.zn120.com/uploads/allimg/110317/45_110317165003_1.jpg" alt="" width="400" height="282" /></p>
<p>Think the Google vs. China gmail debate made the top 10 list in China?  Nope, according to <a href="http://translate.google.com/translate?hl=en&amp;sl=zh-CN&amp;u=http://top.baidu.com/&amp;ei=AeSJTfiBEIjUgAe3sIDQDQ&amp;sa=X&amp;oi=translate&amp;ct=result&amp;resnum=1&amp;ved=0CCYQ7gEwAA&amp;prev=/search%3Fq%3Dtop%2Bbaidu%26hl%3Den%26client%3Dfirefox-a%26hs%3DBTi%26rls%3Dorg.mozilla:en-US:official%26prmd%3Divns">Baidu&#8217;s weekly focus</a>, the aftermath of the &#8220;Salt Panic&#8221;  was on everyone&#8217;s mind.  This was due to the <a href="http://www.chinasmack.com/2011/stories/salt-panic-chinese-fearing-japan-radiation-rush-to-buy-salt.html">mistaken belief</a> that the iodine content in salt could help with the effects of radiation poisoning.  Prior to that, Chinese citizens had been searching online to purchase salt.  Chinese hackers monitor popular web searches and left a slew of <a href="http://translate.google.com/translate?hl=en&amp;sl=zh-CN&amp;u=http://www.hackbase.com/news/2011-03-21/41594.html&amp;ei=SduJTYXGNJTpgAfK0MS0DQ&amp;sa=X&amp;oi=translate&amp;ct=result&amp;resnum=1&amp;sqi=2&amp;ved=0CB0Q7gEwAA&amp;prev=/search%3Fq%3D%25E9%25BB%2591%25E5%25AE%25A2%2B%25E7%259B%2590%2Bhackbase%26hl%3Den%26client%3Dfirefox-a%26hs%3DUY2%26rls%3Dorg.mozilla:en-US:official%26prmd%3Divns">malicious web pages</a> to help balance the supply and demand ratio.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/03/thinking-like-a-chinese-hacker-101-panic-is-your-friend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US #1 perp attacking China&#8217;s classifed networks</title>
		<link>http://www.thedarkvisitor.com/2011/03/us-1-perp-attacking-chinas-classifed-networks/</link>
		<comments>http://www.thedarkvisitor.com/2011/03/us-1-perp-attacking-chinas-classifed-networks/#comments</comments>
		<pubDate>Fri, 11 Mar 2011 18:28:07 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[PRC attacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2214</guid>
		<description><![CDATA[Quick Translation: Rising’s report on China’s 2010 Corporate Security Threats  indicates that government, military, and academic research institutes were significant targets for hackers.  The report further shows that among all hacker attacks, there were a significantly higher number carried out on institutions dealing with state secrets and financial security such as:  national agencies, classified units [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" src="http://www.rising.com.cn/d/file/about/news/rising/20110311/7500010.jpg" border="0" alt="" width="447" height="263" /></p>
<p style="text-align: left;">Quick Translation:</p>
<p style="text-align: left;"><a href="http://www.rising-global.com/About-Us/About-Us/About-Us.html">Rising’s</a> report on <a href="http://www.rising.com.cn/about/news/rising/2011-03-11/9056.html"><em>China’s 2010 Corporate Security Threats</em> </a> indicates that government, military, and academic research institutes were significant targets for hackers. </p>
<p style="text-align: left;">The report further shows that among all hacker attacks, there were a significantly higher number carried out on institutions dealing with state secrets and financial security such as:  national agencies, classified units (dealing with classified/confidential  information), research institutions, and financial organizations.  Some units dealing with classified information suffered nearly a thousand different attacks a month.</p>
<p>Hackers often used the personal computers, cell phones, and thumb drives of individuals working in classified units as portals for attack.  For example, the personal computers of academic researchers involved in military projects were often the targets of attack.  Attackers attempted to use thumb drives, moveable hard disks, and cell phones as springboards for attacks on classified networks.  If successful, the leak of classified information could have grave consequences. </p>
<p>According to Rising’s estimates, in 2010 alone, there were in excess of 10 million attacks on classified networks.  Of those, 90% of the attacking IPs came from abroad with the US, Japan, and South Korea ranking as the three highest ranking sources of attack.</p>
<p class="MsoNormal" style="margin: auto 0in;"><span style="font-size: small;"><span style="font-family: Calibri;">Rising’s report on <em style="mso-bidi-font-style: normal;">China’s 2010 Corporate Security Threats</em> indicates that government, military, and academic research institutes were significant targets for hackers.<span style="mso-spacerun: yes;">  </span></span></span></p>
<p class="MsoNormal" style="margin: auto 0in;"><span style="font-family: Calibri; font-size: small;">The report further showed that among all hacker attacks, there was a significantly higher number carried out on institutions dealing with state secrets and financial security such as:<span style="mso-spacerun: yes;">  </span>national agencies, classified units (dealing with classified/confidential<span style="mso-spacerun: yes;">  </span>information), research institutions, and financial organizations. <span style="mso-spacerun: yes;"> </span>Some units dealing with classified information suffered nearly a thousand different attacks a month. </span></p>
<p class="MsoNormal" style="margin: auto 0in;"><span style="font-size: small;"><span style="font-family: Calibri;">Hackers often used the personal computers, cell phones, and thumb drives of individuals working in classified units as portals for attack. <span style="mso-spacerun: yes;"> </span>For example, the personal computers of academic researchers involved in military projects were often the targets of attack.<span style="mso-spacerun: yes;">  </span>Attackers attempted to use thumb drives, moveable hard disks, and cell phones as springboards for attacks on classified networks.<span style="mso-spacerun: yes;">  </span>If successful, the leak of classified information could have grave consequences.<span style="mso-spacerun: yes;">  </span></span></span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">According to Rising’s estimates, in 2010 alone, there were in excess of 10 million attacks on classified networks.<span style="mso-spacerun: yes;">  </span>Of those, 90% of the attacking IPs came from abroad with the US, Japan, and South Korea ranking as the three highest ranking sources of attack. </span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">IP source attacks on China&#8217;s classified networks:</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">US 21%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">Japan 17%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">South Korea 17%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">Singapore 11%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">India 8%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">Europe 6%</span></p>
<p><span style="font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: SimSun; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;">Hong Kong/Taiwan and others 20%</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/03/us-1-perp-attacking-chinas-classifed-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee PDF on &#8220;Night Dragon&#8221;</title>
		<link>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/</link>
		<comments>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 16:47:22 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Hacking for money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2197</guid>
		<description><![CDATA[Link to McAfee&#8217;s PDF white paper Global Energy Cyberattacks: &#8220;Night Dragon&#8221; that primarily originated in China.]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img id="rg_hi" src="data:image/jpg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBhAQDxAUEA8QFBAPDw8QDw8PEBAQDxAQFBAVFBQQEhQXHCYeFxkjGRUUHy8gIycpLCwsFR4xNTAqNSYrLCkBCQoKDQwOFA8PFykcFBwpKSkpKSkpKSkpKSkpKTApLikpKSkqKTUpKSwuKTUpLCwsNSwpKSkqKSkpNSopKSkpKf/AABEIAKcBLgMBIgACEQEDEQH/xAAbAAACAwEBAQAAAAAAAAAAAAAAAQIDBAUGB//EADoQAAIBAgMFBgQEBAcBAAAAAAABAgMRBCExBRJBUWEGInGBkaETMlKxQsHR4WJyovAHFCMzQ5KyFf/EABgBAQEBAQEAAAAAAAAAAAAAAAABAgME/8QAIBEBAQEBAAIDAAMBAAAAAAAAAAERAgMhEjFBUXGRE//aAAwDAQACEQMRAD8A+HAAASg1dXV1dXSdm1xV+BKvub3cb3cmt5Waus49bPK/HWy0Kyc2m8k0ssm7vTPOy4lEQAAGkO33tbiIdgBDsCQygsBKMG3ka6WGS8S4iinhm+hqp4dLh5sujAthTNYKowLY0y+FIs+EUUqmPcL1AlGHMYKowJqkXRpoujTRcGR0hOma5QSIumtbjBjlTKJQOp8NFc8OnoMHLcGJRN0sMyv/AC/Mg51bAp6ZPp+hjrYeUdVlzWn7HVxVaEPmfkvmfkcqttFv5VZdc2ZuCnLiyLmQuBjVO5NN+Ouudr8hQQ2BFr3ESEAgHKLWqaeTzyyauga9wIgMQAAAAEpRa14pPVPJiABpgAwAaBDRQEoQuxJGujTsiyInSp20NNOmRpwL4I2Jwol0KQqaNEIlAqYF8EJUi4K1EkqZdGmWQplxGZUicVY0fBJKj9uJcFUkimUDT8IUqQwZt5iV2XukRdMgok2lqrLVv7nnsftmUm1Tdo8180uvRGjb+0M/hReS+d9fpOGc+qobAAMAEMCYqcGSsVR6FviWBCJMV+HB8AFJ319yJIRAhDABAA0AABKUm3du7ebbzbAAQDRQIYJDKLaELs2wiU0I2RogjSLYIvhEqgjTBFFlNGqkiiETbRgbkEoxRe8Pl9iVGmrmxwXI3IjnxoPkXww392NCivXyL6bja1l1ZrE1XTw8bKyd+b0KqtHM6OHpeRfLC3RcZ1xFSFOidV4J8PPoVvCO4xdcz4Jy9u7RjQpZf7s7qC5LjNrp9zobW2osNZ1KFbcct1VEobrdr5d6/B62PAY/GyrVJTlrJ6cEuEUcuus9T7aihu76vUVhgZnKogSFYzecCGlcR19j4JW33rdqK+7/ACMiGEwW6ryXef8AT+5VjaNndcdfHmdWpEy1oXTXMuDlCWud/LUk1ZiZlUWDY2hGRFgMQCGhDAnKMd2NpXk770d227yz43IhG189ONtbAA0NCQ0UMlFEScNUWI20y+CKKZopmxfA0Qy1KaY8ThviQcb2u07+DKNVLFQ3lFSi5PRJps200eVxOxJ0+9CSaTus92Wl7r9mZK20qs47sqknHlfXx5+Y+efZj6Fg4cb6GxtWPn3Z3FTVWNNVZQhUbvbca3rZO0lboe7w+HaylUlN85KCt/1SOvHXyjNa6dFvQ008HzHhkrGuLOjIo4e3A1qgiNPMvQZZ/goSpI07pBxA8h/iDsN1aHxYyaeHi5OnrCUW1vS/mS9kfMkj7vicOpwlGXyzjKEvCSs/Znw7EYd05zhL5qc5Ql4xbT90c/jL03zfSrdFYkOx1/5RdQAbQHK8Yuo2PT4CP+jTt9PvfM83Toyk7Ri2+STZ3tkU6lOLjUi0m+67p2b4NcDlmKvqRMlVG6oYqhKOXio2k+uZSacYs15mYxQmIbERSEMRAhiGAE5QcXZpp5ZPrmiAwGiUVoKDWd1fJ2ztZ8GBQyUdSJIsRtpmmBkou5pgzcGumaaZjgzVRkWCE9iqrUcpzbhZWgnaz4+RcuyFGTvvVEvpTTs+d2jXSkjbTr5WRucyo8xtLsjOmt6lJ1EtY2tNLmuf3M+y+09ai0pNzgst2T7yX8L/AF8D2kHf8jg9ptgb0XWpq04q9SK/GuMvFe/3l4+Pvk/t6bYu04YimpQkuG9G+cZP8L8/U7NOm+Z8YweLnSnGcHaUZRkrq6vF3V1xzR9U7OdpKWKhk92ql36T1Wnejzjnqb48ny9frNmO7SjbiXRZnjMkpHVlqVQrbKt8HIiHJnyDtdu/5/Ebum+r/wA+6t7+q59Q2ntanQg51ZJRjouMn9MVxZ8cxVd1JynJ3lOTlJ85N3f3Gfv8NcoAFwuejZjQtfQ7uz+zWSlWur/8aydv4nw8C3srs9Z1pfhbjTXW2cve3qdurI83fQzRowgrQiorklb15lE2X1GZps41pTVkY6jNFaRkqSMDFi3p5mYuxLz8EUmaEIbEZUmIYiBDQgAZOVsrX0V721426EAAkLeGCKIuTEWicEMCjVktGy2OOmuXoUuDDcfJ+hPcHQobW+qPmv0Z0sNioTyjLPlo/c878GX0v0YOnJap+aZvnrPuI9hTlbU1Uqx4yhtGrDSbtyfeXo9Dr4Tb8GrVE4yv80VvQfitV5XO3N5v1f8AUenp4jqaKNe+tvyOJhsdCfyzUvB5+mpshXsblR5PtDsz4FeSS7k+/T5WesfJ5ehkwGPqUKkZ05WlH0a4prij0vabcnSV5RU4Pegm+809Ul1y9DyJw6mX01H1Xs/2lhiYXWVSPz075p810OxTxF9fY+LYfETpyUoScZLSUXZo3VO0eKlDcdae7ndp2lJcnJZtG55pnv7ZvL6JtbtphsO91ydSotYUrO3SUnkvdnmcb/iNiJ3VKnCmvqlepL3svY8nFcvUmkejjxd+T3uRPUXY7aFbES3q1SU5aJvJJcopZJeBSkWQpSk7Ri2+UU2/Y2Utg4mSuqMkucrQ/wDTR6+fHx4/32m65slyFc7keyld/M6cfGTb9kN9lJcasfKLZ5/JZu8tR1NhZYan13n6zf7GipMowlN0qcYXT3E0pL8Su3pweYqlQ81qlORnqTJVKhmqTMVVdSRlqyLKkjJiKmXiZGao7tkWANmAmJIGJkUMQAQIAABgIYDGiKYwJDF9878un5jRQyynOxWCNajdCZdCoYIVLGiEyjRPDwlrFeKyfsZnsjNWl3eOWa/UvjMthUGQZ/8A4n01M+sbe6ZRXrYilk5zs9GpNp+DOtCQ6ii4tStbinoXB5qUm3dttvVvNiLsXCCk/htuPXh06ijhJuO8otx5o51VQABkNSO/2XpYerOUasG5pb0bye40tVZcfFnnzRgMT8KrCf0yTaXFcV6XO3j8vXPqX0lj6XTlGCtCKiuUUor0RTOsc6jtOFRXhJPw1XiuASxB3vWs401K5nqVSmVYplVM2qlOZTOoQnVKJVDFqpVKhnnMU6hnqVDIKlQxTndkqlS5WZtAK/h+YCZlQSpVXF3Vr2ks0nk009ejICIAAEAAAEAMQFDHcQASBBGVr5LNWzWnVdRATuNprXXkyBIodycJ2Kx3NI1RqFrrKKuzDoyUnfUo0z2l9Cb6tZFTjUqq7kt3gr5eiLKc0tPEnTSV7ceHAgWH2fFZye900X7nQpTSyWS1yMqkSUzU9B43Z8Kma7suLWj8Uc6ts2cU3k0s20+HgzpqsDmmmno1Z+BLzKOCBprYGSeWa6a+aKKlKUdU0c8qpUMRKElKLs1/dmd7B7VjU6S4r9GedHGTTTTs1oWdWD1E6xVKsYqWL3knx4rqEqx03UXzqlMqpROuUSrMgvqVjNOdyOoiaAVwbFcyoAe9lay1vvZ72mngKMW3ZJt8lmyBMQAACAAAAAgAAAAYWEUMaEAEguRHcCQ7kSTSsrO91mrWs76dSgQ7kbjuUSTJRqPmVgXUXquTVczXC40a/jD+N1MdwuXRs+MJ1eZkuFyC6cIPhbwyMklYtbF5Eqqk7FqrN6shKBEyLriIb494uiVxCuAAIGIgLkoTcXdNprRp2a8yIAAiU93K19O9e3zdOhEAAdxAIYgIGAhgO+Wr1vbh4iAAAAAoYCGgHcLiACQER3Akn/fLwBMiNMolcLkQuBK4MjcAJXC5EAJXFcQAO5FoLgQRsNDfUVgJxqNXt+JWeS0un+RC4AAAFxAA5SvboraJZCYgGAhkABOtXlOTlOTlKWspO7fDNkAEAAAAAAMAAAAAAAACiyvQcHZ67sZeUoqS9misAAYAAAAAAXC4AA7gAAFwuAAFwXjYAAQAADbvqIAAQ7iAABMAAcnd3er1FYAIJU92/eTtZ/K0ne2WvWxEAAQAAH//2Q==" alt="" width="302" height="167" /></p>
<p>Link to McAfee&#8217;s PDF white paper <em><a href="http://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf">Global Energy Cyberattacks: &#8220;Night Dragon&#8221;</a></em> that primarily originated in China.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PRC based members of carders.cc</title>
		<link>http://www.thedarkvisitor.com/2010/05/prc-hacker-n-skyline-member-of-carders-cc/</link>
		<comments>http://www.thedarkvisitor.com/2010/05/prc-hacker-n-skyline-member-of-carders-cc/#comments</comments>
		<pubDate>Wed, 19 May 2010 20:57:52 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[BFD]]></category>
		<category><![CDATA[carders.cc]]></category>
		<category><![CDATA[skyline]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2153</guid>
		<description><![CDATA[@Jhaddix posted something that caught my attention on twitter earlier today. It mentioned that the well-known cc trading site carders.cc had been compromised and that all of the user accounts, password hashes and some IP access logs were exposed here. I thought it might be interesting to find out if there were any well-known PRC [...]]]></description>
			<content:encoded><![CDATA[<p>@Jhaddix posted something that caught my attention on twitter earlier today.  It mentioned that the well-known cc trading site carders.cc had been compromised and that all of the user accounts, password hashes and some IP access logs were exposed <a href="http://pastebin.de/6648">here</a>.  I thought it might be interesting to find out if there were any well-known PRC connections so I quickly wrote a script to geolocate the IP addresses and found only one China-based IP (with a .ru email tld):</p>
<p>7742:N-Skyline:222.73.19.174:11.May,2010,17:44:34 (Beijing)<br />
N-Skyline:da1e1cdcc8d48037855f2ee2763b4064126fb5ea::n-skyline@qip.ru</p>
<p>There were some .cn email addresses too:<br />
FinnX:01203eb70433505a23d9dbddddaa303e56f6da46::php-dev@jublo.cn<br />
darkc0der:a5ecae753b068cf1f25b95665ad04f8f::cyberatack@w.cn<br />
Out:ec980574500aee917c8266655cbc547d::offshore@w.cn<br />
PWND # MESUT:7e1869df98aa93e3e5b5c473063499ca::PWNEDMESUT@w.cn<br />
0grish:abe3eda164cb318f91cb9aefb654b56790bc7613:lol109:ogrish@w.cn</p>
<p>This is also interesting:</p>
<p>12519:bifrostilo:202.67.236.74:12.May,2010,00:00:09 (HK)<br />
bifrostilo:4c6216cbe0ee90f22eee0bb3e7160999::renehuebner.de@gmx.de</p>
<p>BFD. </p>
<p>As an afterthought &#8211; before people start commenting, I thought I should mention that I&#8217;m aware that .cn and geoip do not necessarily mean that the person using that IP address or tld is/are physically located in the PRC.  Thanks for not commenting about that.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2010/05/prc-hacker-n-skyline-member-of-carders-cc/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

