Google disclosed that a highly coordinated intrusion targeted its corporate network and the Gmail accounts of Chinese human rights advocates, and investigators said the same campaign hit at least 30 to 34 other organizations across the technology, defense, finance, and research sectors, including Adobe, Yahoo, Symantec, Northrop Grumman, and Dow Chemical. Security reporting tied the operation—widely known as Operation Aurora—to spear-phishing and exploitation of a previously unknown Microsoft Internet Explorer flaw, with attackers then moving laterally through victim environments using techniques such as malicious email access. Researchers also identified command-and-control infrastructure used to manage the malware, while later investigations traced activity through servers in Taiwan to computers associated with Shanghai Jiaotong University and Lanxiang Vocational School, though analysts cautioned that those systems may have been intermediaries rather than definitive proof of attribution.
Subsequent U.S. reporting said the attackers reached a sensitive Google database containing years of lawful surveillance-order records, including classified FISA information, suggesting a counterintelligence objective beyond theft of source code, trade secrets, and activist communications. The breach prompted FBI and Justice Department scrutiny, briefings for senior U.S. officials, and public warnings from France and Germany to avoid Internet Explorer after the exploit became widely weaponized in drive-by attacks and added to Metasploit. Google said the attack originated from China and threatened to reconsider its China operations, while outside experts and intelligence-linked investigators assessed that the campaign was likely conducted by Chinese state actors or proxies, a claim Beijing denied.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
U.S. officials disclosed that the 2009 Google breach also reached a sensitive internal database containing years of lawful surveillance requests, including classified FISA orders. The revelation intensified concern in Washington, prompted FBI and Justice Department scrutiny, and highlighted a possible counterintelligence motive.
Investigators reported that systems involved in the attacks were traced beyond Taiwan to computers at Shanghai Jiaotong University and Lanxiang Vocational School in China. Analysts cautioned that the schools' role was uncertain and could reflect direct involvement, camouflage, or false-flag use.
By January 19, 2010, attackers were using the same unpatched Internet Explorer vulnerability in drive-by attacks, and exploit code had been added to the Metasploit framework. Security researchers warned that public weaponization of the flaw sharply increased the risk beyond the original targeted intrusions.
A report said investigators were examining whether insiders in Google's China operations may have helped facilitate the attack. This introduced a new line of inquiry into how the intruders may have gained access.
After the Internet Explorer flaw tied to the Google attacks became public, French and German government security agencies advised users to stop using Internet Explorer and switch to alternative browsers until a fix was available. Microsoft said observed attacks were limited and mainly affected IE6.
VeriSign's iDefense released technical details on the attack, including command-and-control servers and an assessment that the operation was likely conducted by the Chinese government or proxies. It initially said malicious PDFs were involved, but that specific claim was later retracted after Adobe disputed it and McAfee pointed to an Internet Explorer exploit instead.
Reporting on the campaign said at least 34 organizations were targeted, including firms such as Yahoo, Symantec, Adobe, Northrop Grumman, and Dow Chemical, along with research institutions and human rights groups. Experts described the operation as unusually sophisticated and coordinated.
Google announced that it had been targeted in a highly organized attack originating from China and said the apparent goal included accessing information on political dissidents. The company also said it would no longer censor search results in China and might shut down its China operations.
In late 2009, attackers used spear-phishing and a previously unknown Internet Explorer vulnerability to penetrate Google's corporate network as part of a broader campaign affecting more than 30 other companies. During the intrusion, they also accessed Gmail accounts of Chinese human rights advocates.
Investigators later said the intrusion campaign against Google and dozens of other U.S. organizations may have started as early as April 2009. The operation targeted trade secrets, source code, and Gmail accounts belonging to Chinese human rights activists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
14 references tracked. Mallory keeps watching after this page renders.
technologyreview.com
Open sourcearstechnica.com
Open sourcewashingtonpost.com
Open sourcecomputerworld.com
Open sourcecnet.com
Open sourcearstechnica.com
Open sourcewashingtonpost.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.