The Shadow Net report was released following an 8-month collaborative investigation between researchers from the Canada-based Information Warfare Monitor, and the United StatesShadowserver Foundation. The Shadow Network was discovered during the GhostNet investigation, and researchers said it was more sophisticated and difficult to detect. Following the publication of the GhostNet report, several of the listed command and control servers went offline; however, the cyber attacks on the Tibetan community did not cease. The researchers conducted field research in Dharamshala, India, and with the consent of the Tibetan organizations, were able to monitor the networks in order to collect copies of the data from compromised computers and identify command and control servers used by the attackers. The field research done by the Information Warfare Monitor and the Shadowserver Foundation found that computer systems in the Office of His Holiness the Dalai Lama had been compromised by multiple malware networks, one of which was the Shadow Network. Further research into the Shadow Network revealed that, while India and the Dalai Lama's offices were the primary focus of the attacks, the operation compromised computers on every continent except Australia and Antarctica. The research team recovered more than 1,500 e-mails from the Dalai Lama's Office along with a number of documents belonging to the Indian government. This included classified security assessments in several Indian states, reports on Indian missile systems, and documents related to India's relationships in the Middle East, Africa, and Russia. Documents were also stolen related to the movements of NATO forces in Afghanistan, and from the United Nations Economic and Social Commission for Asia and the Pacific. The hackers were indiscriminate in what they took, which included sensitive information as well as financial and personal information.
Origin
The attackers were tracked through e-mail addresses to the Chinese city of Chengdu in Sichuan province. There was suspicion, but no confirmation, that one of the hackers had a connection to the University of Electronic Science and Technology in Chengdu. The account of another hacker was linked to a Chengdu resident who claimed to know little about the hacking.