Bonum Certa Men Certa

Chinese Google 'Attack' Involves Microsoft Windows Flaws

China satellite image



Summary: It is not Google's fault but Microsoft's fault that China managed to compromise accounts not just of Google but of over 20 other companies, by Microsoft's own admission

YESTERDAY we mentioned Google's reaction to attacks from China, which are now confirmed to be targeting different companies. It was not something against Google as Google is one among several victims and some people doubt there will be an exit from the largest Internet market.



How would leaving the Chinese market actually prevent Chinese crackers from connecting to Google servers? It would not.

Hacking Risks Persist Even If Companies Withdraw From China



Google and other enterprises still face a bleak computer security landscape that makes their companies vulnerable to hackers, whether they do business in China or not, analysts say.


Perhaps the most interesting revelation, which was found buried deep inside reports, is the role of Windows in these attacks on Google. Check this one out for example: (the emphasis in red is ours)

More sources are now claiming the Chinese government is behind the recent cyberattacks against Google and 33 other Silicon Valley companies, reports security firm Verisign iDefense. The attacks, revealed yesterday via a posting on Google's official blog, were hacking attempts on the technology infrastructure of Google and other major corporations in sectors that included finance, technology, media and chemical, said Dave Girouard, president of Google Enterprise.

[...]

While July's attacks were detected early and were largely uneventful, December's attacks did find some success. In addition, these same sources claim that the files in both cases share similar characteristics. For example, both attacks used a backdoor Trojan in the form of a Windows DLL, and both share two similar hosts for the command-and-control (C&C) communication. In layman's terms, if the cyberattack was a ground assault during a war, the C&C would be the general barking out the orders. Also in both incidents, the IP addresses used for C&C are in the same subnet and only six addresses apart from each other. That means both attacks are likely to have been instigated by the same entity and may imply that the recent victims' technology infrastructure has been compromised since July.


When one in two Windows PCs is said to be a zombie PC, the above should not be surprising. This was a targeted attack which must have relied on China activists' use of Microsoft Windows.

As the name suggests, the carefully crafted assaults differ from the net-cast-wide malware most often seen. A targeted attack specifically selects its victim and generally sends an e-mail using that person's name and perhaps business title. The body of the message might reference an attached list of business contacts, or describe it as an invoice, or use any other hook that would allay suspicion and convince the victim to double-click the attachment.


Real activists do not use Windows and should use GNU/Linux. A few moments ago, our reader Jose added information that confirms the above. It's an AP article titled "Microsoft's browser flaw exposed Google to hackers" and it says (in the opening): "Microsoft says a security flaw in its Internet Explorer browser played a role in the recent computer attacks against Google and at least 20 other companies."

In other news, a bank server has just been compromised and Baidu got hit by the same group that exploited Windows botnets to take down Twitter [1, 2, 3, 4, 5, 6]. We mentioned this story here and there's more from The Register:

The same group that used a DNS attack to hijack Twitter last month has defaced the home page of Chinese search engine Baidu.

Surfers visiting Baidu site on Monday night were confronted by the message "This site has been hacked by Iranian Cyber Army", together with an image of the Iranian flag. Early speculation suggests the attack involved changing Baidu's DNS records rather than a direct attack on the site itself, but this remains unconfirmed.


Baidu -- unlike Google -- was not a victim of customers who use Windows. Google should tell customers that it's not Google that's vulnerable; it's Windows. Customers should therefore rethink their platform preferences. The same already goes for banks, for similar reasons.

Comments

Recent Techrights' Posts

Apple's Last Leader Died After He Had Been Sacked by Apple
Cult-like worship leads to dictatorships, not redemption from dictatorships
 
Financial Misery: The Failures of the Solicitors Regulation Authority (SRA) to Regulate Have Cost Many Thousands of Brits Over 50 Million Dollars (Stolen, Embezzled, Defrauded)
There's plenty of revolving doors-like activity
There Are Still Many Debian Developers (Alternative to IBM)
Some Debian Developers are on Microsoft's payroll
Sense of Panic at Microsoft, the Slop (for "Entertainment") in Windows is Backfiring
We'll probably find out soon
The Register MS Has Just Published Another SPAM 'Article' for Slop Grifters. It Says "AI" 33 Times!
The Register MS is not a good publisher
Microsoft Lunduke Never Liked Free Speech
Microsoft Lunduke does not speak truth to power. He farts words to 4Chan "bros"
"Linux" Sites That Knock Themselves Out by 'Pivoting' to LLM Slop
People don't need like 100 "Linux" sites to follow, only a handful that they can truly trust
The European Patent Office (EPO) Needs More Scrutiny, Contact Your Officials Tonight or Tomorrow
The European Patent Office (EPO) or the European Patent Organisation (also EPO) are disgracing Europe and the European Union (EU)
Slop in "AI" Clothing is Such a Miserable Failure That IBM is Allegedly Firing Entire Teams That Do Slop (the Media Didn't Report This; It Said the Opposite!)
Gaslighting, lying media that engages in deceit will not outlast this bubble
Huge Microsoft Layoffs Coming Shortly (With Financial Report)
There will be lost of slop layoffs. Be ready. It's a bubble.
The Corrupt Lecture the Non-Corrupt - Part III - "Ethics" Explained by Unethical People, Lots of Buzzwords Included
Imagine being the person (or PR agency) that wrote this with a straight face, possibly commissioned by some frequent cocaine user who runs the Office
Gemini Links 21/04/2026: Dystemia, Protocol Group Chat Gone Wrong, and More
Links for the day
Links 21/04/2026: Drunken Kash Patel Sues The Atlantic for Reporting, California Accuses Amazon of Price-Fixing
Links for the day
EPO Cocainegate Escalates - Part III - Connected Families - The Cocaine User Luis Berenguer and António Campinos
not just bromance between Luis and António
FOSS Linux (fosslinux.com) Has Become a Slopfarm
Slopfarming is the last incarnation of sites that die or are dead
Gemini Links 21/04/2026: NeoVim, GeminiMDB, and Another New Gemini Client (Called Titan II)
Links for the day
Links 21/04/2026: Internet Shutdowns, Bluesky Crippled by DDoS Attack
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, April 20, 2026
IRC logs for Monday, April 20, 2026
3,400 Gemini Capsules Accessible and Known to Lupa, A Geminispace Crawler
We're about to exceed 3,400 some time soon
When and Why I Quit Writing "Classical" GNU/Linux Advocacy Articles
I'd love to write more about why GNU/Linux is great [...] We always try to cover unique issues and break stories (exclusives)
IBM Had Mass Layoffs Every Month This Year (Including at HashiCorp, Confluent, and Red Hat), 'Results' Due in 2 Days' Time
IBM's "media partners" seem to be engaging (propaganda and puff piece) ahead of the serenade to Wall Street
Dr. Andy Farnell on Privacy Failings and Shallow Media Coverage
Bad media paves the way for failed societies
Gemini Links 20/04/2026: Fahrenheit 451, Small Web Advocacy, and Offgrid Holdout
Links for the day
Debian Has a New Project Leader (DPL)
We plan to upgrade Debian some time this month
This Morning The Register MS Published SPAM With "AI" 36 Times in It. This is What The Register MS is Paid to Publish.
It's selling out to Ponzi schemers
Links 20/04/2026: Chatbots Motivate Manslaughter, GAFAM’s ‘Tobacco Moment’
Links for the day
Throwing Rocks in Houses of Glass
Lots of "virtue-signalling" against ICE
The Corrupt Lecture the Non-Corrupt - Part II - It's About Politics, Not Science
Tomorrow we'll discuss what the cocaine proponents (or apologists) deem to be "ethics"
SLAPP Censorship - Part 52 Out of 200: Phil Golding Appointed Bar Standards Board (BSB) Chief, Misogyny Must End
How many rules will they "bend" or even breach?
Links 20/04/2026: Brave Origin Nightly, Scuttling USAID Gives 'Soft Power' to China, and White House Gives Money to Russia (Through Oil Sales)
Links for the day
EPO Cocainegate Escalates - Part II - "Cocaine Communication Manager" Luis Berenguer is Back Without Punishment
Latest on Luis Berenguer
Gemini Links 20/04/2026: "I Hate Computers" and "Why I de-Googled"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, April 19, 2026
IRC logs for Sunday, April 19, 2026
If You're Against War, Why Would You Pay IBM Red Hat?
Red Hat's largest clients aren't geeks; they're militaries
Uplifting Mood in Manchester
Looking behind - and ahead - after a day of relaxation
SLAPP Censorship - Part 51 Out of 200: On Perjury and What It Means to Take Third-Party Funding to Attack Reporter and His Family (in Another Continent)
threats of prison sent to my wife
The Corrupt Lecture the Non-Corrupt - Part I - EPO Management Talks About "Ethics" While Cocaine Users Run the Office
Let's start with the basics
EPO Cocainegate Escalates - Part I - Cocaine Abuse in Family of Campinos (President’s Office)
at the EPO's management you can do illegal drugs and still represent Europe's second-largest institution
Gemini Links 19/04/2026: Big Brother and the Telescreen, Syncing Gemini Capsule With a Makefile
Links for the day
Links 19/04/2026: Introducing “Fighting Fascism” Podcast and Kyiv Mass Shooting
Links for the day
Links 19/04/2026: Mass Layoffs at GAFAM Again (10% Laid Off), Azure Capacity Problems (Enshittification)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 18, 2026
IRC logs for Saturday, April 18, 2026