About Me

George Kurtz

George Kurtz
Worldwide CTO

Chief Technology Officer & Executive Vice President Former CEO of Foundstone, and current worldwide ...

Read More

Feeds & Podcasts

Corporate Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Dealing With “Operation Aurora” Related Attacks

Sunday, January 17, 2010 at 1:47pm by George Kurtz
George Kurtz

At McAfee we continue to work around the clock, investigating the attack we call “Operation Aurora” that hit multiple companies and was publicly disclosed by Google on Tuesday, January 12, 2010.

As I have written before, I believe this is the largest and most sophisticated cyberattack we have seen in years targeted at specific corporations. While the malware was sophisticated, we see lots of attacks that use complex malware combined with zero day exploits. What really makes this is a watershed moment in cybersecurity is the targeted and coordinated nature of the attack with the main goal appearing to be to steal core intellectual property.

The list of organizations reported to have been hit by the cyberattack continues to grow. As a result, many companies and governments are asking us how they can determine if they were targeted in the same sophisticated cyberattack that hit Google. The high profile cyberattack, linked to China by Google, targeted valuable intellectual property.

We’re also getting a lot of questions about the yet-to-be-patched vulnerability in Internet Explorer that was exploited in the cyberattack. That’s an important question as well, because Internet Explorer users currently face a real and present danger due to the public disclosure of the vulnerability and release of attack code, increasing the possibility of widespread attacks.

To help our customers respond to this threat, McAfee published a special Web page at http://www.mcafee.com/operationaurora with information about Operation Aurora and to answer questions related to protection and remediation.

Meanwhile we’re waiting for Microsoft to provide a fix for the serious vulnerability in Internet Explorer. Typically Microsoft releases security fixes on a monthly basis on what’s known as Patch Tuesday, the second Tuesday of every month. However, Microsoft is known to release patches out of cycle if there is a serious threat to its customers. The Microsoft team has been very responsive and I continue to thank them for their efforts. It will be interesting to see if this vulnerability forces and out of cycle patch update. We shall see…

We will continue to investigate Operation Aurora and watch for any attacks that exploit the Internet Explorer vulnerability. Internet users should be cautious with clicking links and opening e-mails that may be malicious. As hackers like to exploit current events, one attack we should watch out for, as despicable as it may sound, would be the combination of a phished email that exploited the IE vulnerability delivered as a “solicitation for donations” to help the struggling Haitian people.

We are already starting to see the bad guys mobilize their efforts to take advantage of the earthquake in Haiti. Our research teams have noted an increase in search engine scams and malicious sites are starting to appear. We have also seen e-mail scams related to Haiti as well as a spike in registration of domain names that refer to the Haiti disaster in some way. I hope we will be spared such attacks, but proceed with caution.

To get real time updates on this story follow me on Twitter at http://www.twitter.com/george_kurtzCTO

George

Bookmark and Share

Tags: , ,

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (2)

  • Adam Johnson January 19, 2010 3:00PM

    I just got a spoof email that claimed to be from George Kurtz – reasonably legitimate looking, no obvious spelling or grammatical errors, with links with the visible text of www.mcafee.com/aurora, with a target of now.eloqua.com/

    Other links were to app.en25.com/, including a footer img src=

    The link to your Twitter web page was accurate however.

    • Joris Evers January 19, 2010 6:59PM

      This is actually a legitimate e-mail from McAfee that was sent using a third party. We apologize for any confusion and thank you for asking us whether this is real or not.
      Joris Evers
      McAfee