EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/operation-aurora-2010
374/430

File EL-0057CriticalResolvedEspionage Operation / Nation-State Cyber Intrusion

Operation Aurora

Also filed as Elderwood Group Attack · China APT Google Hack

Operation Aurora was a series of sophisticated cyberattacks launched in late 2009 and disclosed in 2010, targeting major US technology and defense firms. The attackers, attributed to China, sought to steal valuable intellectual property and source code. The incident marked a watershed moment, as it was one of the first times a major Western tech company publicly accused a nation-state of conducting a sophisticated hack.

  • #apt
  • #china
  • #google
  • #source-code-theft
  • #zero-day-exploit
  • #cyber-espionage
Notoriety9/10
Event
12 Jan 2010
Disclosed
12 Jan 2010
Target
Google
Actor
Elderwood Group
Scale
Unknown (High volume of source code and documents)
Status
Resolved

01Summary

The attacks, carried out by the group known as Elderwood, targeted high-profile organizations including Google, Adobe, and RSA Security. The primary goal was espionage, focusing on stealing source code, proprietary algorithms, and sensitive corporate data. The attackers utilized a zero-day vulnerability in Internet Explorer, allowing them to bypass standard security measures and gain initial access. The intrusion was highly sophisticated, demonstrating advanced capabilities in reconnaissance, lateral movement, and data exfiltration. The public disclosure of the hack led to significant geopolitical fallout, most notably prompting Google to announce a withdrawal from the Chinese market due to the targeting of human rights activists' Gmail accounts. This event significantly raised global awareness regarding the threat of state-sponsored cyber espionage.

02Background

Prior to Operation Aurora, cyberattacks were often viewed as criminal acts, but this incident demonstrated the capability and scope of state-sponsored cyber warfare. The targeting of activists' accounts specifically highlighted the use of cyber tools for political suppression and surveillance, moving the focus from mere theft to geopolitical control.

03Key revelations

  1. 01The successful theft of proprietary source code from multiple global tech leaders.
  2. 02The direct targeting of Gmail accounts belonging to human rights activists in China, linking the hack to political suppression.
  3. 03The public confirmation of a nation-state actor's involvement in cyber espionage against Western interests.

04Technical analysis

The attackers exploited a zero-day vulnerability in Internet Explorer, which allowed them to execute malicious code and gain initial access. The attack methodology involved spear-phishing emails containing malicious attachments, which then downloaded and executed sophisticated malware. The attackers demonstrated advanced techniques for maintaining persistence and exfiltrating large volumes of data, including source code and confidential documents, without detection.

Attack vector
Spear-phishing emails containing malicious attachments.
Attack method
Espionage and Intellectual Property Theft
Initial access
Spear-phishing
Lateral movement
Exploitation of internal network vulnerabilities
Persistence
Malicious implants/Backdoors
Exfiltration
Encrypted channels/Staging servers
Tool / malware
Custom malware/Exploits
Malware type
Spyware/Backdoor

Vulnerabilities exploited

  • Internet Explorer Zero-Day Vulnerability

MITRE ATT&CK techniques

  • T1566.001
  • T1071.001
  • T1190

05Threat actor

The Elderwood Group is widely believed to be a proxy unit of the People's Liberation Army (PLA) of China. Their operations are characterized by high sophistication, zero-day exploit usage, and a clear focus on acquiring strategic intellectual property and monitoring political dissent.

Aliases

  • APT1
  • China State Hackers
  • PLA Unit

APT designations

  • APT1

MITRE groups

  • T1071.001
  • T1190

Attribution sources

  • Google
  • The New York Times
  • Security Industry Reports

06Victims and impact

Additional victims

  • Adobe Systems
  • RSA Security
  • Dow Chemical
  • Over 20 US Technology and Defense Contractors

Countries affected

  • United States
  • China

07Data exposed

Data types

  • Source Code
  • Intellectual Property
  • Confidential Corporate Communications
  • Personal Communications (Activists)

Notable documents

  • Source Code Repositories
  • Internal Corporate Strategy Documents

08Financial damage

Damage estimate is based on lost IP value and market disruption, not a direct ransom payment.

09Timeline

  1. 2009-12-01Initial attacks begin targeting Google, Adobe, and other US firms.
  2. 2010-01-12Google publicly discloses the sophisticated nature and origin of the cyberattack.

10Key figures

  • GoogleVictim/Accuser · Google LLCAmericanAnnounced withdrawal from China market

11On the record

We have been the target of a sophisticated cyberattack by a nation-state.

Google Spokesperson, Initial public statement following the discovery of the intrusion.

12Reaction and fallout

Public reaction

The incident caused widespread alarm in the tech industry, leading to increased investment in cybersecurity defenses and raising public awareness about digital sovereignty. It spurred international debate regarding the legal boundaries of cyber warfare.

Political impact

It significantly heightened US-China cyber tensions, leading to increased diplomatic scrutiny of technology transfer and data security. It also influenced subsequent US government policy regarding critical infrastructure protection.

Geopolitical consequences

The most immediate consequence was Google's decision to cease censoring search results in China and eventually withdraw its services, marking a major commercial and political setback for the Chinese government's internet control efforts.

13Legal

No specific international legal action was taken against the perpetrators, but the incident contributed to the development of national cyber defense strategies and international norms of behavior.

Civil lawsuits

  • Various private lawsuits related to IP theft and data breach damages (unspecified)

14Aftermath

Policy changes

  • Increased focus on supply chain security and third-party vendor risk management.
  • Development of national cyber defense strategies (e.g., US CISA advisories).

Regulatory changes

  • Increased scrutiny of cross-border data flows and data localization requirements (e.g., GDPR influence).

Security improvements

  • Mandatory multi-factor authentication (MFA) adoption across critical infrastructure.
  • Enhanced network segmentation and zero-trust architecture implementation.

15Significance and legacy

Significance

Operation Aurora is historically significant because it provided concrete, high-profile evidence of state-sponsored cyber espionage targeting commercial and political interests. It shifted the global conversation about cyber threats from theoretical risk to documented, geopolitical reality, forcing major corporations and governments to treat cyber defense as a matter of national security.

Legacy

The incident accelerated the commercialization of cybersecurity services and research. It established a precedent for using cyberattacks as a tool of foreign policy, influencing subsequent geopolitical tensions and the development of international cyber norms.

16Disclosure and media

Authentication
Technical forensic analysis and source corroboration

Media partners

  • The New York Times
  • The Guardian
  • BBC News

Publishing organisations

  • Google
  • The New York Times

17Related files

Related events

  • Stuxnet Attack

Went on to inspire

  • Sony Pictures Hack (2014)
  • Equifax Breach (2017)

18Field notes

  1. 01The attack was one of the first times the public was given a clear, detailed look at a nation-state's cyber espionage capabilities.
  2. 02The targeting of human rights activists' accounts was a key factor in the subsequent geopolitical fallout, influencing Google's business decisions in China.

19Resolution

The incident was publicly disclosed and attributed to a nation-state, leading to corporate and geopolitical policy shifts, but the perpetrators were never captured or legally prosecuted.

20Sources

Official documents

  • Google Security Blog Posts (2010)
  • US Department of Commerce Reports (Post-2010)

References

  1. [1]Google Security Blog
  2. [2]The New York Times Investigative Reports
  3. [3]Academic Cybersecurity Journals
Fact sheetEL-0057

Dates

Event
12 Jan 2010
Started
1 Dec 2009
Ended
12 Jan 2010
Duration
42 days
Discovered
12 Jan 2010
Disclosed
12 Jan 2010
Ongoing
No

Target

Organisation
Google LLC
Type
Technology Company
Sector
Internet Services/Technology
Country
United States

Actor

Name
Elderwood Group
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
People's Liberation Army (PLA)
Motivation
Intellectual property theft, espionage, and surveillance of political dissidents.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (High volume of source code and documents)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.