Year2016 |
MonthJune |
Reference number20160601 |
Impact areaShore |
Incident locationCanberra |
Incident countryAustralia |
Victim countryAustralia |
Victim identityA small company (50-person aerospace engineering firm) in the network of the Australian defence industry |
Victim TypeDefence Engineering Contractor |
MethodMalware |
Attacker countryChina |
In June 2016, a small company (50-person aerospace engineering firm) in the network of the Australian defence industry got hit by a malware attack in Australia. The attackers exploited a 12-month-old vulnerability in the company’s IT Helpdesk Portal using 'China Chopper'. Those same administrative credentials gave the attacker access to the domain controller and the remote desktop server, and to email and other sensitive information. The attackers had full and unfettered access to detailed information on some of the nation’s major military defence systems – aircraft, bombs and naval vessels. The attackers exfiltrated about 30GB of data including, restricted technical information on the F-35 Joint Strike Fighter, the P-8 Poseidon maritime patrol aircraft, the C-130 transport aircraft, the Joint Direct Attack Munition (JDAM) smart bomb kit, and a few Australian naval vessels. It is uncertain who the attackers are, but it is believed to be China.