<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Shadow_Network</id>
	<title>Shadow Network - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Shadow_Network"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Shadow_Network&amp;action=history"/>
	<updated>2026-08-04T01:32:18Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Shadow_Network&amp;diff=430221&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Shadow_Network&amp;diff=430221&amp;oldid=prev"/>
		<updated>2023-09-25T18:46:26Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|China-based computer espionage operation}}&lt;br /&gt;
The&amp;#039;&amp;#039;&amp;#039; Shadow Network&amp;#039;&amp;#039;&amp;#039; is a [[Chinese intelligence activity abroad|China-based computer espionage operation]] that stole classified documents and emails from the [[Indian government]], the office of the [[Dalai Lama]], and other high-level government networks.&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;{{Cite web|url = http://www.huffingtonpost.com/2010/04/06/shadow-network-hacker-ope_n_526625.html|title = &amp;#039;Shadow Network&amp;#039; Of Chinese Hackers Steal Dalai Lama&amp;#039;s Emails: REPORT|date = 6 April 2010|access-date = 1 Nov 2014|website = The Huffington Post|last = Anna|first = Cara}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;:1&amp;quot;&amp;gt;{{Cite web|url = https://www.theguardian.com/technology/2010/apr/06/cyber-spies-china-target-india|title = Cyber-spies based in China target Indian government and Dalai Lama|date = 6 April 2010|access-date = 1 Nov 2010|website = The Guardian|last = Branigan|first = Tania}}&amp;lt;/ref&amp;gt; This incident is the second [[cyber espionage]] operation of this sort by China, discovered by researchers at the [[Information Warfare Monitor]], following the discovery of [[GhostNet]] in March 2009.&amp;lt;ref name=&amp;quot;:2&amp;quot;&amp;gt;{{Cite magazine|url = https://www.wired.com/2010/04/shadow-network/|title = Spy Network Pilfered Classified Docs From Indian Government and Others|date = 6 April 2010|access-date = 1 Nov 2014|magazine = Wired|last = Zetter|first = Kim}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;:3&amp;quot;&amp;gt;{{Cite web|url = http://news.bbc.co.uk/2/hi/technology/8605548.stm|title = Shadow cyber spy network revealed|date = 6 April 2010|access-date = 1 Nov 2014|website = BBC News}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;:4&amp;quot;&amp;gt;{{Cite web|url = https://www.nytimes.com/2010/04/06/science/06cyber.html?pagewanted=all&amp;amp;_r=1&amp;amp;|title = Researchers Trace Data Theft to Intruders in China|date = 5 April 2010|access-date = 1 Nov 2014|website = The New York Times|last1 = Markoff|first1 = John|last2 = Barboza|first2 = David}}&amp;lt;/ref&amp;gt; The Shadow Network report &amp;quot;Shadows in the Cloud: Investigating Cyber Espionage 2.0&amp;quot; was released on 6 April 2010, approximately one year after the publication of &amp;quot;Tracking GhostNet.&amp;quot;&amp;lt;ref name=&amp;quot;:5&amp;quot;&amp;gt;{{Cite web|url = https://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0|title = SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0|date = 6 April 2010|access-date = 4 Nov 2010|website = Scribd|publisher = The SecDev Group|page = 2}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The cyber spying network made use of Internet services,&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; such as [[social networking]] and [[cloud computing]] platforms.&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt; The services included [[Twitter]], [[Google Groups]], [[Baidu]], [[Yahoo Mail]], [[Blogspot]], and [[blog.com]],&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; which were used to host [[malware]]&amp;lt;ref name=&amp;quot;:6&amp;quot;&amp;gt;{{Cite web|url = http://www.cnet.com/news/report-india-targeted-by-spy-network/|title = Report: India targeted by spy network|date = 6 April 2010|access-date = 1 Nov 2014|website = CNET|last = Mills|first = Elinor}}&amp;lt;/ref&amp;gt; and infect computers with malicious software.&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Discovery ==&lt;br /&gt;
The Shadow Net report&amp;lt;ref&amp;gt;{{Cite web|url = https://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0|title = SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0|date = 6 April 2010|access-date = 1 Nov 2014|website = Scribd|publisher = The SecDev Group}}&amp;lt;/ref&amp;gt; was released following an 8-month collaborative investigation between researchers from the Canada-based Information Warfare Monitor and the United States [[Shadowserver]] Foundation.&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:6&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{Cite web|url = https://www.theglobeandmail.com/technology/canadian-researchers-reveal-online-spy-ring-based-in-china/article1215984/|title = Canadian researchers reveal online spy ring based in China|date = 6 April 2010|access-date = 1 Nov 2014|website = The Globe and Mail|last = Robertson|first = Grant}}&amp;lt;/ref&amp;gt; The Shadow Network was discovered during the GhostNet investigation,&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt; and researchers said it was more sophisticated and difficult to detect.&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; Following the publication of the GhostNet report, several of the listed command and control servers went offline;&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:7&amp;quot;&amp;gt;{{Cite web|url = https://www.telegraph.co.uk/news/worldnews/asia/china/7559103/Chinese-hackers-steal-Dalai-Lamas-emails.html|title = Chinese hackers steal Dalai Lama&amp;#039;s emails|date = 6 April 2010|access-date = 1 Nov 2010|website = The Telegraph|last = Moore|first = Malcolm}}&amp;lt;/ref&amp;gt; however, the cyber attacks on the Tibetan community did not cease.&amp;lt;ref name=&amp;quot;:7&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The researchers conducted field research in [[Dharamshala]], India, and with the consent of the Tibetan organizations, they were able to monitor the networks in order to collect copies of the data from compromised computers and identify command and control servers used by the attackers.&amp;lt;ref name=&amp;quot;:6&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{Cite web|url = https://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0|title = SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0|date = 6 April 2010|access-date = 1 Nov 2014|website = Scribd|publisher = The SecDev Group|page = 9}}&amp;lt;/ref&amp;gt; The field research done by the Information Warfare Monitor and the Shadowserver Foundation found that computer systems in the Office of His Holiness the Dalai Lama (OHHDL) had been compromised by multiple malware networks, one of which was the Shadow Network.&amp;lt;ref&amp;gt;{{Cite web|url = https://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0|title = SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0|date = 6 April 2010|access-date = 1 Nov 2014|website = Scribd|publisher = The SecDev Group|page = 13}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Further research into the Shadow Network revealed that, while India and the Dalai Lama&amp;#039;s offices were the primary focus of the attacks,&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; the operation compromised computers on every continent except Australia and Antarctica.&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&amp;lt;ref&amp;gt;{{Cite web|url = https://www.scribd.com/doc/29435784/SHADOWS-IN-THE-CLOUD-Investigating-Cyber-Espionage-2-0|title = SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0|date = 6 April 2010|access-date = 1 Nov 2014|website = Scribd|publisher = The SecDev Group|page = 32}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The research team recovered more than 1,500 e-mails from the Dalai Lama&amp;#039;s Office&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt; along with a number of documents belonging to the Indian government.&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt; This included classified security assessments in several Indian states, reports on Indian missile systems,&amp;lt;ref name=&amp;quot;:7&amp;quot; /&amp;gt; and documents related to India&amp;#039;s relationships in the Middle East, Africa, and Russia.&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; Documents were also stolen related to the movements of [[NATO]] forces in Afghanistan,&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; and from the [[United Nations Economic and Social Commission for Asia and the Pacific]] (UNESCAP).&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt; The hackers were indiscriminate in what they took, which included sensitive information as well as financial and personal information.&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Origin ==&lt;br /&gt;
The attackers were tracked through e-mail addresses&amp;lt;ref name=&amp;quot;:3&amp;quot; /&amp;gt; to the Chinese city of [[Chengdu]] in Sichuan province.&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;:2&amp;quot; /&amp;gt; There was suspicion, but no confirmation, that one of the hackers had a connection to the [[University of Electronic Science and Technology]] in Chengdu.&amp;lt;ref name=&amp;quot;:1&amp;quot; /&amp;gt; The account of another hacker was linked to a Chengdu resident who claimed to know little about the hacking.&amp;lt;ref name=&amp;quot;:4&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
* [https://www.shadowserver.org/wiki/ Shadowserver Foundation]&lt;br /&gt;
* [https://citizenlab.org/ Citizen Lab]&lt;br /&gt;
* [http://new.secdev.com/ The SecDev Group]&lt;br /&gt;
* [http://www.infowar-monitor.net/ Information Warfare Monitor]&lt;br /&gt;
&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Cyberwarfare by China]]&lt;br /&gt;
[[Category:Spyware]]&lt;br /&gt;
[[Category:Cyberattacks]]&lt;br /&gt;
[[Category:Cyberwarfare]]&lt;br /&gt;
[[Category:Espionage projects]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>