Google: Malware Attacks Target Vietnam Dissidents

執筆者
Brian Prince
Brian Prince
Published: Mar 31, 2010
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Google and McAfee have uncovered evidence that a campaign of politically motivated cyber-attacks is targeting critics of a Chinese-backed mining operation in Vietnam.

In a blog post, Neel Mehta of Google’s security team noted the cyber-assault on Vietnamese activists is separate from the Aurora incident the company reported in January, and potentially involves tens of thousands of users who “downloaded Vietnamese keyboard language software and possibly other legitimate software.”

“These infected machines have been used both to spy on their owners as well as participate in distributed denial of service (DDoS) attacks against blogs containing messages of political dissent,” he wrote. “Specifically, these attacks have tried to squelch opposition to bauxite mining efforts in Vietnam, an important and emotionally charged issue in the country.”

Bauxite is one of Vietnam’s most valuable natural resources, and the mining plans-backed by the Vietnamese government and state-run Chinese aluminum firm Chinalco-have become a source of political controversy.

Mehta did not directly accuse China of participating in the attacks. However, the company has been in a tense war-of-the-words with the country’s government for months, and just a week ago closed the Chinese version of its search engine.

According to security researchers at McAfee, attackers used malware disguised as the keyboard driver VPSKeys, which is used to insert accents at the appropriate locations when using Windows. Once infected, the machines join a botnet with about a dozen command and control servers located around the globe but accessed predominantly from IP addresses inside Vietnam, McAfee reported.

“We suspect the effort to create the botnet started in late 2009, coinciding by chance with the Operation Aurora attacks,” blogged McAfee CTO George Kurtz. “While McAfee Labs identified the malware during our investigation into Operation Aurora, we believe the attacks are not related.

“We believe the attackers first compromised www.vps.org, the Web site of the Vietnamese Professionals Society (VPS), and replaced the legitimate keyboard driver with a Trojan horse,” he continued. “The attackers then sent an e-mail to targeted individuals which pointed them back to the VPS Web site, where they downloaded the Trojan instead.”

Advertisement

At the same time, news that foreign journalists working in China have once again had their e-mails hacked has raised eyebrows even further. Earlier this year, the Foreign Correspondents’ Club of China (FCCC) issued a warning to its members stating that journalists working in China had had their e-mails hacked. This time, the group has reportedly said eight members had their e-mail accounts hacked in recent weeks and that several were suspended by Yahoo March 25. Also, as of roughly 11:55 a.m. Eastern time today, the FCCC Website is down.

“We believe that malware is a general threat to the Internet, but it is especially harmful when it is used to suppress opinions of dissent,” Mehta wrote.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。