<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Chinese Malware</title>
	<atom:link href="http://www.thedarkvisitor.com/category/chinese-malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>McAfee PDF on &#8220;Night Dragon&#8221;</title>
		<link>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/</link>
		<comments>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 16:47:22 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[Hacking for money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2197</guid>
		<description><![CDATA[Link to McAfee&#8217;s PDF white paper Global Energy Cyberattacks: &#8220;Night Dragon&#8221; that primarily originated in China.]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img id="rg_hi" src="data:image/jpg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBhAQDxAUEA8QFBAPDw8QDw8PEBAQDxAQFBAVFBQQEhQXHCYeFxkjGRUUHy8gIycpLCwsFR4xNTAqNSYrLCkBCQoKDQwOFA8PFykcFBwpKSkpKSkpKSkpKSkpKTApLikpKSkqKTUpKSwuKTUpLCwsNSwpKSkqKSkpNSopKSkpKf/AABEIAKcBLgMBIgACEQEDEQH/xAAbAAACAwEBAQAAAAAAAAAAAAAAAQIDBAUGB//EADoQAAIBAgMFBgQEBAcBAAAAAAABAgMRBCExBRJBUWEGInGBkaETMlKxQsHR4WJyovAHFCMzQ5KyFf/EABgBAQEBAQEAAAAAAAAAAAAAAAABAgME/8QAIBEBAQEBAAIDAAMBAAAAAAAAAAERAgMhEjFBUXGRE//aAAwDAQACEQMRAD8A+HAAASg1dXV1dXSdm1xV+BKvub3cb3cmt5Waus49bPK/HWy0Kyc2m8k0ssm7vTPOy4lEQAAGkO33tbiIdgBDsCQygsBKMG3ka6WGS8S4iinhm+hqp4dLh5sujAthTNYKowLY0y+FIs+EUUqmPcL1AlGHMYKowJqkXRpoujTRcGR0hOma5QSIumtbjBjlTKJQOp8NFc8OnoMHLcGJRN0sMyv/AC/Mg51bAp6ZPp+hjrYeUdVlzWn7HVxVaEPmfkvmfkcqttFv5VZdc2ZuCnLiyLmQuBjVO5NN+Ouudr8hQQ2BFr3ESEAgHKLWqaeTzyyauga9wIgMQAAAAEpRa14pPVPJiABpgAwAaBDRQEoQuxJGujTsiyInSp20NNOmRpwL4I2Jwol0KQqaNEIlAqYF8EJUi4K1EkqZdGmWQplxGZUicVY0fBJKj9uJcFUkimUDT8IUqQwZt5iV2XukRdMgok2lqrLVv7nnsftmUm1Tdo8180uvRGjb+0M/hReS+d9fpOGc+qobAAMAEMCYqcGSsVR6FviWBCJMV+HB8AFJ319yJIRAhDABAA0AABKUm3du7ebbzbAAQDRQIYJDKLaELs2wiU0I2RogjSLYIvhEqgjTBFFlNGqkiiETbRgbkEoxRe8Pl9iVGmrmxwXI3IjnxoPkXww392NCivXyL6bja1l1ZrE1XTw8bKyd+b0KqtHM6OHpeRfLC3RcZ1xFSFOidV4J8PPoVvCO4xdcz4Jy9u7RjQpZf7s7qC5LjNrp9zobW2osNZ1KFbcct1VEobrdr5d6/B62PAY/GyrVJTlrJ6cEuEUcuus9T7aihu76vUVhgZnKogSFYzecCGlcR19j4JW33rdqK+7/ACMiGEwW6ryXef8AT+5VjaNndcdfHmdWpEy1oXTXMuDlCWud/LUk1ZiZlUWDY2hGRFgMQCGhDAnKMd2NpXk770d227yz43IhG189ONtbAA0NCQ0UMlFEScNUWI20y+CKKZopmxfA0Qy1KaY8ThviQcb2u07+DKNVLFQ3lFSi5PRJps200eVxOxJ0+9CSaTus92Wl7r9mZK20qs47sqknHlfXx5+Y+efZj6Fg4cb6GxtWPn3Z3FTVWNNVZQhUbvbca3rZO0lboe7w+HaylUlN85KCt/1SOvHXyjNa6dFvQ008HzHhkrGuLOjIo4e3A1qgiNPMvQZZ/goSpI07pBxA8h/iDsN1aHxYyaeHi5OnrCUW1vS/mS9kfMkj7vicOpwlGXyzjKEvCSs/Znw7EYd05zhL5qc5Ql4xbT90c/jL03zfSrdFYkOx1/5RdQAbQHK8Yuo2PT4CP+jTt9PvfM83Toyk7Ri2+STZ3tkU6lOLjUi0m+67p2b4NcDlmKvqRMlVG6oYqhKOXio2k+uZSacYs15mYxQmIbERSEMRAhiGAE5QcXZpp5ZPrmiAwGiUVoKDWd1fJ2ztZ8GBQyUdSJIsRtpmmBkou5pgzcGumaaZjgzVRkWCE9iqrUcpzbhZWgnaz4+RcuyFGTvvVEvpTTs+d2jXSkjbTr5WRucyo8xtLsjOmt6lJ1EtY2tNLmuf3M+y+09ai0pNzgst2T7yX8L/AF8D2kHf8jg9ptgb0XWpq04q9SK/GuMvFe/3l4+Pvk/t6bYu04YimpQkuG9G+cZP8L8/U7NOm+Z8YweLnSnGcHaUZRkrq6vF3V1xzR9U7OdpKWKhk92ql36T1Wnejzjnqb48ny9frNmO7SjbiXRZnjMkpHVlqVQrbKt8HIiHJnyDtdu/5/Ebum+r/wA+6t7+q59Q2ntanQg51ZJRjouMn9MVxZ8cxVd1JynJ3lOTlJ85N3f3Gfv8NcoAFwuejZjQtfQ7uz+zWSlWur/8aydv4nw8C3srs9Z1pfhbjTXW2cve3qdurI83fQzRowgrQiorklb15lE2X1GZps41pTVkY6jNFaRkqSMDFi3p5mYuxLz8EUmaEIbEZUmIYiBDQgAZOVsrX0V721426EAAkLeGCKIuTEWicEMCjVktGy2OOmuXoUuDDcfJ+hPcHQobW+qPmv0Z0sNioTyjLPlo/c878GX0v0YOnJap+aZvnrPuI9hTlbU1Uqx4yhtGrDSbtyfeXo9Dr4Tb8GrVE4yv80VvQfitV5XO3N5v1f8AUenp4jqaKNe+tvyOJhsdCfyzUvB5+mpshXsblR5PtDsz4FeSS7k+/T5WesfJ5ehkwGPqUKkZ05WlH0a4prij0vabcnSV5RU4Pegm+809Ul1y9DyJw6mX01H1Xs/2lhiYXWVSPz075p810OxTxF9fY+LYfETpyUoScZLSUXZo3VO0eKlDcdae7ndp2lJcnJZtG55pnv7ZvL6JtbtphsO91ydSotYUrO3SUnkvdnmcb/iNiJ3VKnCmvqlepL3svY8nFcvUmkejjxd+T3uRPUXY7aFbES3q1SU5aJvJJcopZJeBSkWQpSk7Ri2+UU2/Y2Utg4mSuqMkucrQ/wDTR6+fHx4/32m65slyFc7keyld/M6cfGTb9kN9lJcasfKLZ5/JZu8tR1NhZYan13n6zf7GipMowlN0qcYXT3E0pL8Su3pweYqlQ81qlORnqTJVKhmqTMVVdSRlqyLKkjJiKmXiZGao7tkWANmAmJIGJkUMQAQIAABgIYDGiKYwJDF9878un5jRQyynOxWCNajdCZdCoYIVLGiEyjRPDwlrFeKyfsZnsjNWl3eOWa/UvjMthUGQZ/8A4n01M+sbe6ZRXrYilk5zs9GpNp+DOtCQ6ii4tStbinoXB5qUm3dttvVvNiLsXCCk/htuPXh06ijhJuO8otx5o51VQABkNSO/2XpYerOUasG5pb0bye40tVZcfFnnzRgMT8KrCf0yTaXFcV6XO3j8vXPqX0lj6XTlGCtCKiuUUor0RTOsc6jtOFRXhJPw1XiuASxB3vWs401K5nqVSmVYplVM2qlOZTOoQnVKJVDFqpVKhnnMU6hnqVDIKlQxTndkqlS5WZtAK/h+YCZlQSpVXF3Vr2ks0nk009ejICIAAEAAAEAMQFDHcQASBBGVr5LNWzWnVdRATuNprXXkyBIodycJ2Kx3NI1RqFrrKKuzDoyUnfUo0z2l9Cb6tZFTjUqq7kt3gr5eiLKc0tPEnTSV7ceHAgWH2fFZye900X7nQpTSyWS1yMqkSUzU9B43Z8Kma7suLWj8Uc6ts2cU3k0s20+HgzpqsDmmmno1Z+BLzKOCBprYGSeWa6a+aKKlKUdU0c8qpUMRKElKLs1/dmd7B7VjU6S4r9GedHGTTTTs1oWdWD1E6xVKsYqWL3knx4rqEqx03UXzqlMqpROuUSrMgvqVjNOdyOoiaAVwbFcyoAe9lay1vvZ72mngKMW3ZJt8lmyBMQAACAAAAAgAAAAYWEUMaEAEguRHcCQ7kSTSsrO91mrWs76dSgQ7kbjuUSTJRqPmVgXUXquTVczXC40a/jD+N1MdwuXRs+MJ1eZkuFyC6cIPhbwyMklYtbF5Eqqk7FqrN6shKBEyLriIb494uiVxCuAAIGIgLkoTcXdNprRp2a8yIAAiU93K19O9e3zdOhEAAdxAIYgIGAhgO+Wr1vbh4iAAAAAoYCGgHcLiACQER3Akn/fLwBMiNMolcLkQuBK4MjcAJXC5EAJXFcQAO5FoLgQRsNDfUVgJxqNXt+JWeS0un+RC4AAAFxAA5SvboraJZCYgGAhkABOtXlOTlOTlKWspO7fDNkAEAAAAAAMAAAAAAAACiyvQcHZ67sZeUoqS9misAAYAAAAAAXC4AA7gAAFwuAAFwXjYAAQAADbvqIAAQ7iAABMAAcnd3er1FYAIJU92/eTtZ/K0ne2WvWxEAAQAAH//2Q==" alt="" width="302" height="167" /></p>
<p>Link to McAfee&#8217;s PDF white paper <em><a href="http://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf">Global Energy Cyberattacks: &#8220;Night Dragon&#8221;</a></em> that primarily originated in China.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2011/03/mcafee-pdf-on-night-dragon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft vs. Chinese hacker hero</title>
		<link>http://www.thedarkvisitor.com/2009/08/microsoft-vs-chinese-hacker-hero/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/microsoft-vs-chinese-hacker-hero/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 02:42:32 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Nationalism]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=2049</guid>
		<description><![CDATA[Hong Lei More on Tomato Garden and the arrest of Hong Lei, the author of the pirated software.  Online polls show massive support for Hong Lei as a nationalist hero: The Chinese IT community is abuzz with news of the arrest of Hong Lei, distributor of the popular &#8220;Tomato Garden&#8221; pirate version of Windows XP, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone" src="http://images.china.cn/attachement/jpg/site1007/20081022/0019b91ec8450a68bd2e09.jpg" alt="" width="296" height="352" /></p>
<p style="text-align: center;">Hong Lei</p>
<p>More on Tomato Garden and the arrest of Hong Lei, the author of the pirated software.  Online polls show massive support for <a href="http://www.china.org.cn/china/mictosoft_anti_piracy/content_16645754.htm">Hong Lei as a nationalist hero</a>:</p>
<blockquote><p>The Chinese IT community is abuzz with news of the arrest of Hong Lei, distributor of the popular &#8220;Tomato Garden&#8221; pirate version of Windows XP, which means the popular unlocked version of the Microsoft software will no longer be available.</p>
<p>According to Sina.com, more than 90 percent of users they surveyed are or were users of Tomato Garden pirate editions. And 79 percent said they were on Tomato Garden’s side. Less than 5 percent said they supported Microsoft.</p></blockquote>
<p>The <em>Wall Street Journal</em> has some <a href="http://online.wsj.com/article/SB125174411034873381.html?mod=googlenews_wsj">interesting interviews</a> with people inside China concerning the case and the drivers behind the software theft.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/microsoft-vs-chinese-hacker-hero/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Chinese hacker e-mail espionage?</title>
		<link>http://www.thedarkvisitor.com/2009/08/chinese-hacker-e-mail-espionage/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/chinese-hacker-e-mail-espionage/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 23:35:22 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[Australia]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1942</guid>
		<description><![CDATA[It seems that even prior to the Melbourne Film Festival controversy, Australia&#8217;s diplomats may have been the targets of e-mail espionage attempts: AUSTRALIA&#8217;S diplomats have been warned about a fake email amid concerns it could be part of a cyber espionage attempt, possibly originating from China. The Department of Foreign Affairs and Trade confirmed yesterday [...]]]></description>
			<content:encoded><![CDATA[<p>It seems that even prior to the Melbourne Film Festival controversy, Australia&#8217;s diplomats may have been the targets of <a href="http://www.smh.com.au/technology/security/fake-email-could-be-cyber-espionage-20090817-enp0.html">e-mail espionage attempts</a>:</p>
<blockquote><p>AUSTRALIA&#8217;S diplomats have been warned about a fake email amid concerns it could be part of a cyber espionage attempt, possibly originating from China.</p>
<p>The Department of Foreign Affairs and Trade confirmed yesterday staff had been briefed about a suspicious email sent to several staff last month. The source of the email is under investigation by the department&#8217;s communications experts.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/chinese-hacker-e-mail-espionage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware: The &#8220;Maritime Girl&#8221;</title>
		<link>http://www.thedarkvisitor.com/2009/08/beware-the-maritime-girl/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/beware-the-maritime-girl/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 12:05:27 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[China internet]]></category>
		<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1927</guid>
		<description><![CDATA[Maritime Girl In November of 2008, Chinese hackers used the popularity of the the viral video &#8220;Kappa Girl&#8221; to infect an untold number of users.  In May of 2009, Chinese hackers started using pictures of the &#8220;Maritime Girl&#8221; for exactly the same purpose. In the Mainland China Internet Security Report for the First Half of [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="attachment wp-att-1933" href="http://www.thedarkvisitor.com/2009/08/beware-the-maritime-girl/maritime-girl/"><img class="aligncenter size-full wp-image-1933" title="Maritime girl" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/08/Maritime-girl.JPG" alt="Maritime girl" width="400" height="399" /></a>Maritime Girl</p>
<p>In November of 2008, Chinese hackers used the popularity of the the viral video &#8220;<a href="http://www.thedarkvisitor.com/2008/11/chinese-hacker-and-the-kappa-girl-video/">Kappa Girl</a>&#8221; to infect an untold number of users.  In May of 2009, Chinese hackers started using pictures of the &#8220;Maritime Girl&#8221; for exactly the same purpose.</p>
<p>In the <a href="http://it.rising.com.cn/new2008/News/NewsInfo/2009-07-21/1248160663d53890.shtml"><em>Mainland China Internet Security Report for the First Half of 2009</em></a>, researchers examine a couple of case studies looking at the top-10 methods for spreading trojans and coming in at number four was the &#8220;<a href="http://it.rising.com.cn/new2008/News/NewsInfo/2009-07-21/1248160663d53890_4.shtml">Maritime Girl</a>&#8220;.</p>
<p><a href="http://www.celebrity-e.com/96290_yin-hong-shanghai-hai-yun-girl-pictures-wildly-downloaded-and-spread-in-china-yin-hong-hai-yun-gate-photos-scandal-caused-by-boyfriend-garros-zhu-hui.html">Yin Hong</a>, known now and probably forever as the &#8220;Maritime Girl&#8221;, was a student at the Shanghai Maritime University and posed in a series of very revealing photos for her boyfriend.  After they broke up,  the boyfriend spitefully posted the photos all over China&#8217;s interwebs.  A download frenzy ensues and Chinese hackers attach trojan malware primarily used to steal online gaming accounts.</p>
<p>Welcome once again to Chinese hacker social engineering 101.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/beware-the-maritime-girl/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Dark Cough &#8211; DEFCON 17</title>
		<link>http://www.thedarkvisitor.com/2009/08/the-dark-cough-defcon-17/</link>
		<comments>http://www.thedarkvisitor.com/2009/08/the-dark-cough-defcon-17/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 03:09:48 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Censorship]]></category>
		<category><![CDATA[China internet]]></category>
		<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[meetup]]></category>
		<category><![CDATA[Xiao Tian]]></category>
		<category><![CDATA[中文fail]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1873</guid>
		<description><![CDATA[Thanks to everyone who showed up to the Dark Visitor meetup at DEFCON 17.  It was a lot of fun and I had a great time joking around and talking shop with everyone.  The only gambling that I did was deciding on the Korean BBQ place close to the con hotel &#8211; the food was [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to everyone who showed up to the Dark Visitor meetup at DEFCON 17.  It was a lot of fun and I had a great time joking around and talking shop with everyone.  The only gambling that I did was deciding on the <a href="http://www.thekimchi.com/" target="_blank">Korean BBQ place</a> close to the con hotel &#8211; the food was pretty good and they reserved a nice area for the group (of 21) so I guess the gamble paid off.  I hope everyone had as much fun as I did.  There was a lot of praise for Heike&#8217;s book as well as the work we&#8217;re doing together on the blog &#8211; that was all very much appreciated.  We need to convince Heike to come out to DEFCON18 next year&#8230; Come on, Vegas isn&#8217;t so bad.</p>
<p>I spent most of my time at the con attending presentations.  There were at least <a href="https://forum.defcon.org/showthread.php?p=107203" target="_blank">two</a> <a href="http://www.defcon.org/html/defcon-17/dc-17-speakers.html#TK234" target="_blank">presentations</a> that featured a slide devoted to <a href="http://www.thedarkvisitor.com/tag/xiao-tian/" target="_blank">Xiao Tian</a> and the Dark Visitor got mentioned in two <a href="http://defcon.org/html/defcon-17/dc-17-speakers.html#Street" target="_blank">presentations</a>.  I think that we should setup a scholarship fund to sponsor Xiao Tian so she can come to Vegas next year and meet with us.</p>
<p><img class="alignleft" title="Xiao Tian" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/07/xiaotian2.jpg" alt="" width="397" height="611" /></p>
<p>So I decided to put together a give away for people who attended the meetup and settled on a CD packed full of Chinese hacker papers and videos.  I put a nice lightscribe label on all of them and included &#8220;The Dark Visitor&#8221; in Chinese characters.  Well apparently I entered the characters rather hastily and instead of 黑客, I put 黑咯, which means Dark Cough (according to Ming Zhou).  So at least I learned a new character and maybe that will be the name of the next big disease that comes out of Asia.  Who knows?  Maybe the flawed Dark Visitor CD will turn out to be the next ultra rare one-eyed beanie baby or something (I&#8217;ll start planting them on ebay tomorrow).</p>
<p><img src="http://www.thedarkvisitor.com/wp-content/uploads/2009/08/1-293x300.jpg" alt="IMG_7390.JPG" title="IMG_7390.JPG" width="293" height="300" class="alignleft size-medium wp-image-1883" /></p>
<p>Heike and I have talked about having some TDV wearable stuff.  Perhaps a <a href="http://en.wikipedia.org/wiki/Titan_Rain">Titan Rain</a> Suit?  Maybe a &#8220;Certified <a href="http://www.thedarkvisitor.com/category/censorship/">Great Firewall</a> Engineer&#8221; T-Shirt?  How about a <a href="http://www.thedarkvisitor.com/2007/12/javaphile-buddhism-andthe-public-security-bureau/">Javaphile</a> Coffee Shop baseball hat?  <a href="http://www.thedarkvisitor.com/2007/11/peoples-armed-police-officer-hacking/">Sunwear</a> tanktop?  Let us know what you think.  We&#8217;ll think of something clever to do with the proceeds like buy Xiao Tian an HD webcam.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/08/the-dark-cough-defcon-17/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Chinese firms and &#8220;Sexy Space&#8221; trojan</title>
		<link>http://www.thedarkvisitor.com/2009/07/chinese-firms-and-sexy-space-trojan/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/chinese-firms-and-sexy-space-trojan/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 10:55:12 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1845</guid>
		<description><![CDATA[Looks like we are going to have to add a new category to the blog; at least until this damn mobile phone fade is over: F-Secure&#8217;s senior security response manager, Chia Wing Fei, explained that the Trojan would have allowed attackers to simply send a link via text message to a malicious Web site and [...]]]></description>
			<content:encoded><![CDATA[<p>Looks like we are going to have to add a new category to the blog; at least until this damn mobile phone fade is over:</p>
<blockquote><p>F-Secure&#8217;s senior security response manager, Chia Wing Fei, explained that the Trojan would have allowed attackers to simply send a link via text message to a malicious Web site and prompt the mobile recipient to download the worm. Once the malware would be installed, it could send similar text messages to all contacts listed on the phone.</p>
<p>&#8220;These messages are sent in your name and from your phone,&#8221; Chia said. &#8220;It means you will pay for each SMS sent by the worm. A typical cost for a single text message might be 5 cents. If you have 500 contacts in your phone, an infection would cost you ($25).&#8221;</p></blockquote>
<p>Read more on <a href="http://news.cnet.com/8301-1009_3-10292917-83.html">&#8220;Sexy Space&#8221; trojan</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/chinese-firms-and-sexy-space-trojan/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>KnownSec stores tens of thousands of viruses found on Chinese websites</title>
		<link>http://www.thedarkvisitor.com/2009/07/knownsec-stores-tens-of-thousands-of-viruses-found-on-chinese-websites/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/knownsec-stores-tens-of-thousands-of-viruses-found-on-chinese-websites/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 00:02:39 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1694</guid>
		<description><![CDATA[KnowSec is sharing the database and also reports finding more than 100 trojan downloaders a day. The database covers more Chinese Web sites and provides more up-to-date information about their security than any other, Zhao said in the interview. China produces the majority of the world&#8217;s malware, he said. A history for each site in [...]]]></description>
			<content:encoded><![CDATA[<p><em>KnowSec</em> is <a href="http://www.pcworld.com/article/167754/chinese_security_company_shares_huge_malware_database.html?tk=rss_news">sharing the database</a> and also reports finding more than 100 trojan downloaders a day.</p>
<blockquote><p>The database covers more Chinese Web sites and provides more up-to-date information about their security than any other, Zhao said in the interview. China produces the majority of the world&#8217;s malware, he said.</p>
<p>A history for each site in the database lists dates of malware infection, the strings of malicious code placed on the sites and which antivirus products defend viewers against their attacks. The database also stores tens of thousands of viruses found being distributed by the sites.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/knownsec-stores-tens-of-thousands-of-viruses-found-on-chinese-websites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Children of a lesser malware</title>
		<link>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/#comments</comments>
		<pubDate>Fri, 03 Apr 2009 20:51:20 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1494</guid>
		<description><![CDATA[UPDATE: Added further comment by Nart Villeneuve at the bottom (Great guy!) Yep, that would be us&#8230; According to researchers at IWM, Lost33&#8242;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE:</strong> Added further comment by Nart Villeneuve at the bottom (Great guy!)</p>
<p>Yep, that would be us&#8230;</p>
<p>According to researchers at IWM, Lost33&#8242;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool<span class="body"> gh0stRAT that made up the backbone of GhostNet.</span></p>
<p><span class="body">From the <a href="http://www.securityfocus.com/brief/940">report</a> by Robert Lemos at <em>Security Focus</em>:</span></p>
<blockquote><p>However, the e-mail address was found only on two of the computers analyzed for the investigation, said Nart Villeneuve, a researcher at the CitizenLab and one of the authors of the GhostNet report. Both computers had been infected with a second piece of malware, separate from the gh0st remote access tool (gh0stRAT) that formed the backbone of the surveillance network, he said.</p>
<p>&#8220;That is a valid piece of malware but it is not the one related to the malware that connected to the admin interface for the gh0stRAT,&#8221; Villeneuve said.</p></blockquote>
<p>So it looks like we are now investigating a massive network intrusion of two computers.  One, two.  We will call our project CasperNet.</p>
<p style="text-align: center;"><a href="http://doopy1956.com/graphics/casper.jpg"><img class="aligncenter" src="http://doopy1956.com/graphics/casper.jpg" alt="" width="350" height="271" /></a></p>
<p>Spoke with Jumper earlier today and he still feels it is worthwhile to pursue.  So, he will continue his conversation with Lost33 tonight.</p>
<p><strong>UPDATE:</strong> Wanted to add this comment left by <a href="http://www.nartv.org/">Nart Villeneuve</a> because I thought it was super nice of him.  I botched up his report but he was still kind enough to stop by and offer these words of encouragement:</p>
<p>&#8220;I wouldn’t say lesser at all — just different. The CasperNet (www.lookbytheway.net/www.macfeeresponse.org) which sounds way better than what I’ve been calling it (CGI after their use of CGI scripts) was the one that was found to be retrieving a sensitive document related to the Dalai Lama’s negotiating position. In addition to being found at the OHHDL it was also found at the Tibetan NGO Drewla.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>GhostNet: Beijing or NGO Chinese hackers?</title>
		<link>http://www.thedarkvisitor.com/2009/04/ghostnet-beijing-or-ngo-chinese-hackers/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/ghostnet-beijing-or-ngo-chinese-hackers/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 11:31:39 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[Ghostnet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1439</guid>
		<description><![CDATA[Ashok Sharma, from the AP, asked me this question yesterday and here was my response from his article Dalai Lama condemns hacking of computers: Scott Henderson, author of The Dark Visitor, a self-published book about Chinese hackers, said he thought it was feasible that the attacks described in the report could have been carried out [...]]]></description>
			<content:encoded><![CDATA[<p>Ashok Sharma, from the <em>AP,</em> asked me this question yesterday and here was my response from his article <a href="http://www.google.com/hostednews/ap/article/ALeqM5iC6dv7wEDjot7sicxn1c_gNI_2wQD9793DGG0"><em>Dalai Lama condemns hacking of computers</em></a>:</p>
<blockquote><p>Scott Henderson, author of The Dark Visitor, a self-published book about Chinese hackers, said he thought it was feasible that the attacks described in the report could have been carried out by an individual over the course of a year or so.</p>
<p>Henderson said it wouldn&#8217;t be unusual for a Chinese hacker to want to infiltrate the Dalai Lama&#8217;s computers because most of the mainland hackers he has researched &#8220;place as much importance on sovereignty (over Tibet and other contentious areas) as Beijing does.&#8221;</p></blockquote>
<p>To be fair to the researhers at <a href="http://www.infowar-monitor.net/">IWM</a>, they never said it was the government either.  At least that is my interpretation of their conclusions.</p>
<p>So, do we have any evidence that this could have been done by a group other than the Chinese government?</p>
<p>Stay tuned&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/ghostnet-beijing-or-ngo-chinese-hackers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Israeli company uses Chinese hacker tool against Hezbollah</title>
		<link>http://www.thedarkvisitor.com/2009/03/israeli-company-uses-chinese-hacker-tool-against-hezbollah/</link>
		<comments>http://www.thedarkvisitor.com/2009/03/israeli-company-uses-chinese-hacker-tool-against-hezbollah/#comments</comments>
		<pubDate>Sat, 28 Mar 2009 15:11:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Applicure]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1432</guid>
		<description><![CDATA[Just damn, damn, damn. When a reporter makes several attempts to contact you, get back with the guy.  The author of this article, Oded Yaron, tried numerous times to get in touch with me and we missed each other.  My fault, not his.  He still gave our website a plug without mentioning that one of [...]]]></description>
			<content:encoded><![CDATA[<p>Just damn, damn, damn.</p>
<p>When a reporter makes several attempts to contact you, get back with the guy.  The author of this article, Oded Yaron, tried numerous times to get in touch with me and we missed each other.  My fault, not his.  He still gave our website a plug without mentioning that one of the people that blogs here is a real jackass.  Thanks!</p>
<p>My apologies to Mr. Yaron and from his report, <em><a href="http://haaretz.com/hasen/spages/1073531.html">Virtual battleground attacks Hezbollah&#8217;s soft underbelly</a>:</em></p>
<blockquote><p>Last week, while trying out breaking-in tools developed by Chinese hackers, an Israeli Network security company, Applicure, brought down the Hezbollah Web site (hizbollah.tv), using no more than 10 bots, which are computers controlled by hackers.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/03/israeli-company-uses-chinese-hacker-tool-against-hezbollah/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

