What Was Operation Aurora? The Attack That Went for the Source Code
The operation is named after a folder on the attacker's computer.
When McAfee's researchers pulled apart the binaries, part of the file path from the machine they had been compiled on was still embedded in two of them, the way build paths so often are. One of the directories was called Aurora. That is the whole etymology. An intelligence operation that reshaped a decade of security spending is known to history by whatever its author happened to have named a folder.
It is a good introduction to the incident, because almost everything widely repeated about Aurora is the second most interesting version of the fact.
What was Operation Aurora?
Operation Aurora was a set of intrusions running from roughly the middle of 2009 through December of that year, against Google, Adobe Systems, Juniper Networks, Rackspace and a longer list that later reporting put at more than thirty organisations.
Google disclosed it on 12 January 2010, in a post titled A new approach to China — the same post in which it announced it would stop censoring results on google.cn, a decision that ended with Google leaving the mainland Chinese search market.
The initial access was a use-after-free vulnerability in Internet Explorer, affecting versions 6, 6 SP1, 7 and 8, exploited in the wild through December 2009 and January 2010. It was eventually assigned CVE-2010-0249 and patched out of band as MS10-002.
Targeted employees were sent links. The page served the exploit. The exploit dropped a backdoor. From that foothold the attackers moved laterally and went looking for specific things.
The dissident accounts, honestly
This is the detail everyone remembers, and it deserves precision rather than repetition.
Google's own disclosure said two things about the Gmail accounts of Chinese human rights activists. First, that a primary goal of the attackers appeared to be accessing them. Second — and this is the part that gets dropped — that the attack itself had not succeeded in doing so beyond two accounts, and that in those two cases the access was limited to account information such as when the account was created and the subject lines of messages. Not the contents.
Google's separate finding, in the same post, was that dozens of activist accounts had been routinely accessed by third parties — but through phishing and malware on the users' own machines, not through this intrusion.
Two different problems, reported in the same paragraph, permanently merged in the retelling. The human rights dimension of Aurora is real and it drove Google's China decision. It is not what the intruders actually got out of Google's network.
What they were really after
When McAfee looked across the wider victim set, the pattern was consistent, and it was not customer data.
The targets were software configuration management systems — the repositories where source code lives, along with its full history, its branches, its unreleased work and its unfixed bugs.
Dmitri Alperovitch, then running threat research at McAfee, described what they found:
[The SCMs] were wide open. No one ever thought about securing them, yet these were the crown jewels of most of these companies in many ways — much more valuable than any financial or personally identifiable data that they may have and spend so much time and effort protecting.
That sentence is the whole incident. These systems were built in the 2000s for collaboration among trusted colleagues. They assumed the network boundary did the security. Access control was coarse, logging was thin, and integrity checking on what came out of them was largely absent — in several cases you could pull the entire history without anything anywhere recording that you had.
Meanwhile every one of those companies had a compliance programme, an encrypted customer database and an auditor. The asset that actually constituted the business had none of it.
Why source code is worth more than data
Stolen customer records have a decay curve. Cards get reissued, passwords get rotated, and the value of the copy falls toward zero.
Source code does not decay. It gives you the product, but more usefully it gives you the ability to read for vulnerabilities at your leisure, offline, in code that is deployed at every customer of that vendor. And where the product is infrastructure — Juniper builds routers and firewalls — the reading list is other people's networks.
The distinction that got lost is between the smash-and-grab and the long game. Aurora was not a breach in the sense of a data breach. It was industrial acquisition.
The thirty-four number
The figure repeated everywhere is that Aurora hit 34 companies. It is worth being clear about where it comes from, because it is not a confirmed count.
Google's post said it had evidence that at least twenty other large companies from a range of sectors had been similarly targeted. Later reporting, drawing on the security firms doing the incident response, put the number above thirty and settled on thirty-four.
Only a handful ever confirmed publicly — Google, Adobe, Juniper and Rackspace named themselves. Names such as Yahoo, Symantec, Northrop Grumman, Dow Chemical and Morgan Stanley circulated in reporting without company confirmation at the time.
So thirty-four is a researcher's tally of victim infrastructure, not a roll call. The honest version: four confirmed, at least twenty on Google's own evidence, and a broader campaign that the responders put in the mid-thirties.
The browser, and two governments
Working exploit code for CVE-2010-0249 was public within days of the disclosure, and in Metasploit shortly after. A targeted nation-state zero-day became a commodity in under a week, which is the usual half-life and still surprises people.
What was genuinely unusual was the official response. The German federal security office advised the public to stop using Internet Explorer until a patch existed. France issued comparable advice, and so did Australia. National governments telling their citizens to abandon a specific commercial browser had not happened before.
Microsoft shipped the out-of-band patch on 21 January 2010.
What it actually changed
Three things, and only one of them was technical.
The term advanced persistent threat existed before Aurora — it comes out of US Air Force usage in 2006. Aurora is when it escaped into the commercial vocabulary, and within two years every vendor had an APT product. The concept it named was real: an intruder with an objective and a budget, who does not leave when the first door closes.
Second, it made attribution speakable. Google's post pointed at China in public, by a company with a great deal to lose by doing so. That was a change in norms more than in evidence.
Third — and this is the one with a lasting engineering legacy — Aurora is the origin story Google itself gives for BeyondCorp, its move away from trusting the corporate network perimeter. The intrusion demonstrated that once someone is inside, a flat trusted network hands them everything. What grew out of that is most of what the industry now sells as zero trust.
Further reading
- Google Official Blog — A new approach to China, 12 January 2010.
- McAfee Labs — Operation Aurora analysis and George Kurtz's blog post on the naming, January 2010.
- Microsoft Security Bulletin
MS10-002and NIST NVD entry forCVE-2010-0249. - Wired — Google Hack Attack Was Ultra Sophisticated, New Details Show, January 2010, including the Alperovitch interview.
- Google — the BeyondCorp research papers, 2014 onward, for the architectural consequence.
EXHIBIT 0022 — OPERATION AURORA
We put it on a shirt. A wooden drafting table drawn as an engraving, with a large architectural blueprint pinned flat across it, a T-square along one edge and a roll of tracing paper on the corner. Not the machine. The drawing of the machine.
In the blueprint's title block, in the corner where a draughtsman signs the sheet, is \Aurora_Src\ — the folder the whole operation got its name from, left in the file path of the binaries.
The callouts say it plainly: THEY CAME FOR THE BLUEPRINTS, NOT THE PRODUCT, SOURCE REPOSITORIES WERE WIDE OPEN, NAMED FROM THE ATTACKER'S OWN FOLDER.
That's the whole idea.