The Office of His Holiness the Dalai Lama in Dharamsala had emailed an invitation on his behalf to a foreign diplomat. Before its staff could follow up with a courtesy telephone call, the diplomat's office was contacted by the Chinese government and warned not to go ahead with the meeting. That, by the account in a Cambridge technical report, was when the office began to wonder about its computers. Help was close by. Greg Walton, a field researcher for the Information Warfare Monitor — the Citizen Lab at the University of Toronto's Munk Centre and the SecDev Group in Ottawa — had been in Dharamsala since July 2008 gathering samples of malware aimed at Tibetan groups, and the Dalai Lama's representative in Geneva, Tseten Samdup, asked him to review the office's systems.
During a five-day visit in September the team ran a packet-capture program on one of the 23 computers on the office network, and watched documents leave for a server named macfeeresponse.org: one held thousands of email addresses, another discussed the negotiating position of the Dalai Lama's envoy. The machine had been infected in August. Emails that seemed to come from colleagues had carried Word and PDF attachments laced with exploit code; one monk, the Cambridge report said, claimed to have seen his Outlook Express open by itself and send infected attachments on. In Toronto, Nart Villeneuve and his colleagues followed the traffic to web-based control panels on four servers and got into them by guessing file paths and names. Why the attackers had not secured them, the report said, remained unclear.
The panels showed every computer that had reported in, a form for sending commands and a log of results. The researchers infected a machine of their own, ordered it through the attackers' interface to fetch gh0st RAT, an open-source remote-control Trojan written by Chinese programmers, and watched commands arrive from a DSL range on Hainan island; the tool offered keystroke logging, a remote shell, webcam view and audio capture. The list held 1,295 computers in 103 countries; the earliest had called home on 22 May 2007. The researchers identified 397 with confidence as high-value: the foreign ministries of Iran, Bangladesh, Latvia, Indonesia, the Philippines, Brunei, Barbados and Bhutan; embassies of India, South Korea, Germany, Pakistan and seven more countries; the ASEAN secretariat; and an unclassified computer at NATO headquarters.
They called it GhostNet. Their report, dated 29 March, went online the day before, with John Markoff's story in the New York Times. Its authors found the circumstantial evidence tilted most strongly towards the Chinese state, weighed criminals, patriotic hackers and another state using Chinese computers, and concluded: "we do not know the motivation or the identity of the attacker(s)". "This could well be the C.I.A. or the Russians," said the Citizen Lab's Ron Deibert. A Cambridge report, The snooping dragon, by Shishir Nagaraja and Ross Anderson, attributed the intrusion to agents of the Chinese government. China's consulate in New York called the claims "nonsense"; on 31 March its foreign ministry called them fabricated. The network was still running; a year later the team traced another to documents identified as the Indian government's.
Five Weeks of Funding
On 5 March 2009 Rod Beckstrom, a Silicon Valley entrepreneur appointed in March 2008 to run the Department of Homeland Security's new National Cyber Security Center, wrote to the secretary, Janet Napolitano, resigning from Friday 13 March. The centre, he wrote, had received "only five weeks of funding" in the past year, "due to various roadblocks engineered within the department and by the Office of Management and Budget". His larger complaint was the National Security Agency, which in his account effectively controlled the department's cyber efforts "through detailees, technology insertions" and a proposed move of the centre and the department's National Protection and Programs Directorate to an NSA facility at Fort Meade. That was "bad strategy on multiple grounds". "The intelligence culture," he wrote, "is very different than a network operations or security culture", and putting all top-level government network security and monitoring with one organisation endangered "our democratic processes". The department said it thanked him for his service and regretted his departure. On 26 June ICANN's board, meeting in Sydney, chose him as its president and chief executive.
Twenty-Two Thousand Machines
On 12 March 2009 the BBC's technology programme Click disclosed what it would broadcast that weekend: it had taken control of a botnet of about 22,000 compromised Windows computers. "The process began in chatrooms where hackers advertise their services," wrote its presenter, Spencer Kelly; months and a few thousand dollars later it had been bought from hackers in Russia and Ukraine. Click had the machines send spam to two accounts it had opened at Gmail and Hotmail and, by prior agreement, flood a backup site run by the security firm Prevx; sixty were enough. It then changed the machines' wallpaper to tell owners how to clean them, and said it had destroyed the network. Struan Robertson, a lawyer at Pinsent Masons, said the BBC appeared to have broken the Computer Misuse Act: criminal intent was not needed, and there was no public-interest defence. The BBC cited "the powerful public interest in demonstrating the ease with which such malware can be obtained and used". The Metropolitan Police's computer crime unit, The Register reported, would act only on a victim's complaint; Click had chosen machines outside Britain and the United States.
A War Game Called Divine Matrix
In the last week of March 2009, days before GhostNet went public, the Hindustan Times reported a secret exercise by the Army's military operations directorate. Called Divine Matrix, it was a three-day war game, preceded by six months' study of scenarios, that pictured a war with China before 2017 — "a short, swift war", in the words of an officer who took part, and "very much within the realm of possibility". The novelty was the opening move. In the Army's assessment, China would rely on information warfare to bring India to its knees before any offensive, and the generals worried about People's Liberation Army information-warfare battalions carrying out hacker attacks for military espionage and intelligence collection, paralysing communication systems, compromising airport security, damaging the banking system and disabling power grids. None of the officers was named.
The year 2017 brought not a war but a stand-off at Doklam, from 16 June to 28 August. The list aged better than the date, though not always from the direction the war game assumed. In October 2019 malware carrying the Kudankulam nuclear plant's own network credentials surfaced, and researchers linked it to the Lazarus Group, associated with North Korea. In early 2021 Recorded Future reported that a China-linked group it called RedEcho had placed malware across India's power sector, while saying it could not confirm any link to Mumbai's blackout of 12 October 2020. What Divine Matrix pictured as a prelude to an offensive became a standing condition; the duty to report such intrusions within hours is set out on our India desk.
A thought lifts ASIMO's arm
On 31 March 2009 Honda Research Institute Japan, with ATR and Shimadzu, showed a brain-machine interface that let a person direct Honda's ASIMO robot by thought. A helmet measured the scalp's electrical activity by electroencephalography and blood flow by near-infrared spectroscopy; statistical software judged whether the wearer imagined moving the left hand, right hand, tongue or feet, and Honda put its accuracy above 90 per cent. In a video, several seconds after a man thought of moving his right hand, ASIMO lifted its right arm. It was not shown live, Honda said, as the wearer's attention might wander, and each person's brain patterns needed about two to three hours' study first; "Practical uses are still way into the future," said Yasuhisa Arai, an executive at the institute. On 23 March the government-backed laboratory AIST had sent HRP-4C, a humanoid built to a young Japanese woman's average proportions, down a Japan Fashion Week catwalk in Tokyo. ASIMO's regular shows ended on 31 March 2022, thirteen years to the day later, its development already halted.
False alarms start to cost awards
In late March 2009 the Austrian lab AV-Comparatives published its February on-demand test, its first in which false alarms lowered awards. Of seventeen products, judged on nearly 1.3 million samples, only Symantec, ESET, Kaspersky and McAfee reached the top grade, Advanced+. G DATA detected the most, 99.8 per cent, but 44 false alarms cost it a grade; eight others were also marked down. McAfee's 99.1 per cent included Artemis, which checked fingerprints of suspicious files over the internet; offline the product found 95.2 per cent, a grade lower. Symantec's month was less tidy. On 9 March it sent users of its 2006 and 2007 Norton products a diagnostic patch, PIFTS.exe, that through what it called "human error" carried no digital signature, so Norton's own firewall asked whether to let it online. Posts about the patch vanished from Norton's forums, which Symantec blamed on a spam flood; on 12 March it reposted the legitimate ones with an apology. Cloud lookups spread: a year later the lab was measuring what other products lost offline.
⏳ Time capsule — March 2009
- On 7 March, at 03:49:57 UTC — the evening of 6 March in Florida — a Delta II rocket launched NASA's Kepler space telescope from Cape Canaveral to look for Earth-sized planets around other stars. By the time its retirement was announced, on 30 October 2018, it had observed 530,506 stars and found 2,662 exoplanets.
- On 9 March the Dow Jones Industrial Average closed at 6,547.05, its lowest close since April 1997 and less than half its peak of October 2007. The record it had fallen from was not matched until March 2013.
- On 24 March the Board of Control for Cricket in India announced that the Indian Premier League's second season would be played in South Africa, after the government declined to commit paramilitary forces to its security during the general election. It opened at Newlands in Cape Town on 18 April, and Deccan Chargers beat Royal Challengers Bangalore in the final in Johannesburg on 24 May.
- On 28 March Earth Hour asked people to switch off their lights from 8.30 to 9.30 in the evening, local time; WWF, which had begun it in Sydney in 2007, reported 4,159 cities in 88 countries taking part. The Sphinx and the pyramids of Giza went dark, and the United Nations headquarters in New York joined for the first time.
From declining to naming
In March 2009 the people who had watched the operators work would still not say whose they were; the caution was the method. What followed was a progression of naming. In January 2010 a company, Google, named a country; in February 2013 Mandiant published a unit's designation and its building's address in Shanghai; in May 2014 the Justice Department put five officers' photographs on wanted posters. Beijing's answer barely moved across those five years — hacking is illegal in China, the claims fabricated — and the Tibetan community stayed a target: in June 2022 Proofpoint reported a campaign impersonating the Central Tibetan Administration. GhostNet's lesson for everyone else was humbler. The spies' main tool was free to download, and the way in was an email that seemed to come from a colleague.
Beckstrom's quarrel outlived his tenure. Cyber Command, run by the NSA's own director, reached initial operational capability at Fort Meade in May 2010, as June 2010 records, and in June 2013 the Snowden documents showed how far that agency's collection reached; a civilian agency of the kind he had argued for arrived in November 2018, when the directorate once slated for Fort Meade became the Cybersecurity and Infrastructure Security Agency. What Click bought became a retail trade: by January 2015 floods were sold as a service. And the Citizen Lab kept following victims back to tools — to an Emirati activist's phone in August 2016, and to a zero-click exploit in September 2021.