Defence engineering company that included maritime applications hit by malware attack in Australia

Year

2016

Month

June

Reference number

20160601

Impact area

Shore

Incident location

Canberra

Incident country

Australia

Victim country

Australia

Victim identity

A small company (50-person aerospace engineering firm) in the network of the Australian defence industry

Victim Type

Defence Engineering Contractor

Method

Malware

Attacker country

China

Summary:

In June 2016, a small company (50-person aerospace engineering firm) in the network of the Australian defence industry got hit by a malware attack in Australia. The attackers exploited a 12-month-old vulnerability in the company’s IT Helpdesk Portal using 'China Chopper'. Those same administrative credentials gave the attacker access to the domain controller and the remote desktop server, and to email and other sensitive information. The attackers had full and unfettered access to detailed information on some of the nation’s major military defence systems – aircraft, bombs and naval vessels. The attackers exfiltrated about 30GB of data including, restricted technical information on the F-35 Joint Strike Fighter, the P-8 Poseidon maritime patrol aircraft, the C-130 transport aircraft, the Joint Direct Attack Munition (JDAM) smart bomb kit, and a few Australian naval vessels. It is uncertain who the attackers are, but it is believed to be China.

Reference URL

https://nakedsecurity.sophos.com/2017/10/13/hackers-steal-restricted-information-on-f-35-fighter-jdam-p-8-and-c-130/
https://www.zdnet.com/article/secret-f-35-p-8-c-130-data-stolen-in-australian-defence-contractor-hack/#ftag=RSSbaffb68
https://www.fifthdomain.com/global/asia-pacific/2017/10/12/f-35-data-stolen-in-australian-hackbut-no-classified-info/
https://fortune.com/2017/10/14/hacked-f-35-data/ https://www.itnews.com.au/news/hacked-aussie-defence-firm-lost-fighter-jet-bomb-ship-plans-475211