You are here

China-based campaign breaches satellite, defence firms: Symantec

San Francisco

A SOPHISTICATED hacking campaign launched from computers in China burrowed deeply into satellite operators, defence contractors and telecommunications companies in the United States and South-east Asia, security researchers at Symantec Corp said on Tuesday.

Symantec said that the effort appeared to be driven by national espionage goals, such as the interception of military and civilian communications. Such interception capabilities are rare but not unheard of, and the researchers could not say what communications, if any, were taken.

More disturbingly in this case, the hackers infected computers that controlled the satellites, so that they could have changed the positions of the orbiting devices and disrupted data traffic, Symantec said. "Disruption to satellites could leave civilian as well as military installations subject to huge (real world) disruptions," said Vikram Thakur, technical director at Symantec. "We are extremely dependent on their functionality."

Satellites are critical to phone and some Internet links as well as mapping and positioning data. Symantec, based in Mountain View, California, described its findings to Reuters exclusively ahead of a planned public release. It said that the hackers had been removed from infected systems. Symantec said that it has already shared technical information about the hack with the US Federal Bureau of Investigation (FBI) and Department of Homeland Security, along with public defence agencies in Asia and other security companies. The FBI did not respond to a request for comment.

Your feedback is important to us

Tell us what you think. Email us at

Mr Thakur said that Symantec detected the misuse of common software tools at client sites in January, leading to the campaign's discovery at unnamed targets. He attributed the effort to a group that Symantec calls Thrip, which may be called different names by other companies. Thrip was active from 2013 on and then vanished from the radar for about a year until the last campaign started a year ago. In that period, it developed new tools and began using more widely available administrative and criminal programs, Mr Thakur said.

Other security analysts have also recently tied sophisticated attacks to Chinese groups that had been out of sight for awhile, and there could be overlap. FireEye Inc in March said that a group it called Temp.Periscope reappeared last summer and went after defence companies and shippers. REUTERS

BT is now on Telegram!

For daily updates on weekdays and specially selected content for the weekend. Subscribe to