Follow Us

New tool to detect Aurora malware behind Google hack

HBGary builds Aurora Inoculation Shot to kill corporate espionage

Security vendor HBGary has released a free software tool that can remove "Aurora" malware, linked to corporate espionage at more than 30 companies.

Called the Aurora Inoculation Shot, this utility will remotely scan Windows machines over the network for signs of Aurora and can remove the malicious software as well. It uses the Windows Management Instrumentation services to carry out the inoculation.

Although Aurora has been linked to attacks on just 34 companies, the software has captured the attention of corporate executives, because some believe that is connected to a widespread industrial espionage campaign originating from China.

Last month, Google admitted that it had been hacked by Aurora software and the company's security team gained access to a command-and-control server that held data linking the attack to other major companies such as Adobe Systems and, according to reports, Symantec, Juniper Networks, Northrop Grumman and Dow Chemical.

Security experts have now identified a dozen other Aurora command-and-control servers that may be collecting data on other companies, but many of those servers are hosted by ISPs that have not cooperated with investigations.

At this point, experts are divided on whether Aurora is important because it represents a widespread campaign, possibly condoned or even sponsored by the Chinese government, or because Google took the unusual step of admitting that it had been hacked.

According to HBGary CEO Greg Hoglund, the Aurora malware is similar to many other programs that have been used by criminals for years now. "The Aurora stuff isn't that complicated," He said. "It smells like any other criminal malware that's out there."

Although Google made the Aurora hack a point of negotiation with the People's Republic of China, "there's no hard evidence anywhere that shows that China's government has anything to do with it," Hoglund said.

Despite all the attention Aurora has received, the problem "hasn't gone away," Hoglund added. "It's still out there and operating."

That's why HBGary has made the inoculation software available. The company has also released a report outlining what is publicly known about the malware. "We're the first ones to release a concise report that brings all the data to one spot," he said.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *