Dalai Lama's China site hacked, infects others: Kaspersky

Advertisement
By Reuters | Updated: 13 August 2013 14:28 IST
A prominent computer security firm warned that the Dalai Lama's Chinese-language website has been hacked and is infecting visitors' computers with viruses in what may to be an effort to spy on human rights activists who frequently visit the site.

Kaspersky Lab researcher Kurt Baumgartner told Reuters on Monday that he is advising web surfers to stay away from the Chinese-language site of the Central Tibetan Administration, or CTA, until the organization fixes the bug. He described the attack on his company's blog.

Technical evidence suggests the group behind the campaign was also responsible for previous breaches on that site as well as attacks on groups that focus on human rights in Asia, Baumgartner said.

Advertisement

Those breaches involved a two-stage attack technique known as "water holing," where hackers first infect a site that is frequently visited by people whose computers they want to control. That compromised site automatically seeks to infect the PCs of all visitors, downloading malicious software that the hackers can use to take control of their computers.

Officials with the Office of Tibet in New York could not be reached for comment. That office is the official representative to the United States for the Dalai Lama, Tibet's 78-year-old exiled spiritual leader, who fled China to India in 1959 after an abortive uprising against Chinese rule.

Advertisement

Beijing considers the globe-trotting monk and author a violent separatist and Chinese state media routinely vilify him. The Dalai Lama, who is based in India, says he is merely seeking greater autonomy for his Himalayan homeland.

Baumgartner said that the Chinese-language site of the Central Tibetan Administration, which is the official organ of the Dali Lama's government in exile, has been under constant attack from the same group of hackers since 2011, though breaches have been quietly identified and repaired before garnering significant attention.

Advertisement

Same group of attackers
"They have been trying repeatedly to find vulnerabilities in the site," he said.

He said that it is safe to visit the group's English and Tibetan sites.

Advertisement

He said he believes the same group of attackers has repeatedly infected the site with malicious software that automatically drops viruses on computers running Microsoft Corp's Windows and Apple Inc's Mac operating systems.

They infect machines by exploiting security bugs in Oracle Corp's Java software, he said. An Oracle spokeswoman had no immediate comment.

That gives them "back doors" into those computers. "This is the initial foothold. From there they can download arbitrary files and execute them on the system," Baumgartner said.

Will Gragido, a researcher with the RSA security division of EMC Corp who is an expert on water holing, said the attack on the Tibetan site had the look of a type of campaign known as an "advanced persistent threat," or APT.

In some cases APTs are launched through tainted emails. In others this is done through "water holes," which are named after specific locations that lions stake out to attack their prey, rather than traveling the wild to hunt them out.

"The CTA is a site most people are not going to traverse," Gragido said. "They are less likely to see my grandmother traversing that site than they are somebody with a vested interest in seeing what's going on in Tibet."

In March of last year, the cybersecurity firm AlienVault Labs reported that it identified cyber attacks on Tibetan organizations including CTA and the International Campaign for Tibet.

AlienVault said those attacks were engineered by a Chinese APT group also responsible for the "Nitro" attacks on dozens of companies identified by Symantec Corp in 2011.

The report of the cyber attack is the latest to involve human rights groups in greater China.

Human rights groups and other NGOs focused on China were hit by denial of service attacks that disrupted their websites and several said their emails were infiltrated during a spate of cyber attacks attributed to China in 2010 and 2011.

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Moto G47 Debuts Globally With a 108-Megapixel Camera at This Price
  2. The iQOO Neo 10 Is Now Available in These New Colour Variants in India
  3. OnePlus Pad 4 Launched in India With Flagship Chip and These Features
  4. These Four Xiaomi Phones Are Now Eligible to Get Android 17 Beta Updates
  5. Moto G37 Power, Moto G37 Launched With Dimensity 6300 Chip: See Price
  6. ULA Atlas V Launches 29 Amazon Kuiper Satellites in Return Mission
  7. This Intel Processor Will Likely Rival the MacBook Neo's A18 Pro Chip
  8. Vivo X Fold 6 Leaks Reveal 200-Megapixel Camera and 7,000mAh Battery
  9. CMF Watch 3 Pro India Launch Finally Confirmed, Here's What to Expect
  1. ULA Atlas V Launches 29 Amazon Kuiper Satellites in Return Mission
  2. Moto Buds 2 Plus Launched in India With Hi-Res Audio, Up to 40 Hours of Total Playback Time: Price, Features
  3. iQOO Z11 Global Variant Spotted on Geekbench Database With Snapdragon Chipset, Unlike Chinese Model
  4. Samsung Reportedly Plans to Launch Galaxy Book Models With Android-Based One UI 9 Soon
  5. PS5 Linux Loader Gets Public Release, Allowing Users to Run Steam and PC Games on Console
  6. Nine Crypto Scam Centres Targeting US Users Shut Down in Joint Operation Involving UAE, US and China
  7. Google Photos Unveils New AI-Powered Wardrobe Feature to Help You Decide What to Wear
  8. OpenAI CEO Sam Altman Teases GPT-5.5 Cyber AI Model Rollout, Could Take On Anthropic’s Claude Mythos
  9. Vivo X Fold 6 Leaks Hint at 200-Megapixel Camera, MediaTek Dimensity 9500 Chip and 7,000mAh Battery
  10. Raakaasa OTT Release Date Confirmed: Know When and Where to Watch it Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.