Source: Damballa: March 2, 2010
Overview
Following the public disclosures of electronic attacks launched against Google and several other businesses, subsequently referred to as “Operation Aurora”, Damballa conducted detailed analysis to confirm that existing customers were already protected and to ascertain the sophistication of the criminal operators behind the botnet. There has been much media attention and speculation as to the nature of the attacks. Multiple publications have covered individual aspects of the threat – in particular detailed analysis of forensically recovered malware and explanations of the Advanced Persistent Threat (APT).
By contrast, Damballa has been able to compile an extensive timeline of the attack dating back to mid-2009 that identifies unique aspects to the Aurora botnet that have been previously unknown. Based upon this new information and our experience in dealing with thousands of enterprise-targeted botnets, Damballa believes that the criminal operators behind the attack are relatively unsophisticated compared other professional botnet operators. Even so, the results proved just as damaging as a sophisticated botnet since the threat was not quickly identified and neutralized.
Some key observations in this analysis report: