GhostNet: The Chinese Espionage Network That Compromised 1,295 Computers in 103 Countries and Could Watch Through Your Webcam
In March 2009, a research team at the Citizen Lab at the University of Toronto published a report that changed how the world understood state-sponsored cyber espionage. Researchers had been investigating malware found on the computers of Tibetan government-in-exile offices at the request of the Dalai Lama's organization. What they found was not a targeted Tibetan campaign - it was the command-and-control infrastructure of a global espionage network that had compromised computers in 103 countries, including foreign ministries, embassies, the offices of the Dalai Lama, a NATO computer, and the computer networks of the Indian government.
The network was named GhostNet. The Citizen Lab researchers followed the malware to its C2 servers, which were predominantly hosted in China, and documented the network systematically. GhostNet gave its operators real-time access to infected computers - not just file theft but live remote desktop viewing, microphone activation, and camera activation. Foreign embassies and ministries were being watched in real time. Sensitive diplomatic communications were being read as they were written. And this had been operating, undetected, for years.
Discovery and Scope
The Citizen Lab investigation began when the Tibetan government-in-exile asked for help investigating suspected compromises of their computer systems in 2008. Researchers found a sophisticated RAT (Remote Access Trojan) on Tibetan networks that communicated with external C2 infrastructure. Following the C2 infrastructure led to a larger network than anyone had expected.
The GhostNet report documented 1,295 infected computers across 103 countries. Targets included foreign ministries of Iran, Bangladesh, Latvia, Indonesia, Philippines, Brunei, Barbados, and Bhutan; embassies of India, South Korea, Indonesia, Romania, Cyprus, Malta, Thailand, Taiwan, Portugal, Germany, and Pakistan; the ASEAN (Association of Southeast Asian Nations) Secretariat; SAARC (South Asian Association for Regional Cooperation); the Asian Development Bank; and numerous NGOs and Tibetan organizations. Approximately 30% of the infected computers were described as "high-value" targets.
Attribution and China
The Citizen Lab was careful in its attribution language. The report noted that C2 infrastructure was predominantly in China (with some servers on Hainan Island, the location of a major PLA signals intelligence facility) and that the targeting pattern was consistent with Chinese government intelligence interests - heavy focus on Tibetan organizations, the Dalai Lama's office, and diplomatic targets in countries with significant China policy relevance. The report did not formally attribute GhostNet to the Chinese government, noting that the evidence was circumstantial and that attribution of state-sponsored operations through purely technical analysis had inherent limitations.
Chinese government officials denied involvement. Independent security researchers who analyzed the GhostNet infrastructure and malware concluded the targeting pattern was consistent with Chinese state intelligence collection priorities. The general consensus in the security research community was that GhostNet represented either state-directed or state-tolerated collection on behalf of Chinese intelligence interests, even if the direct chain of command could not be established.
Shadow Network and Subsequent Research
Citizen Lab followed the GhostNet report with a 2010 investigation called "Shadows in the Cloud" that documented a separate but related espionage network - also using Chinese C2 infrastructure - that had compromised Indian government and military systems, the offices of the Dalai Lama, and computers belonging to United Nations, diplomatic corps, and business interests across South Asia. This network was stealing documents including classified Indian government documents and sensitive Dalai Lama correspondence.
The GhostNet and Shadow Network investigations established the Citizen Lab as the primary public research institution for documenting state-sponsored cyber espionage against civil society, a role it has continued through subsequent investigations of NSO Group's Pegasus spyware, Chinese operations against Uyghur communities, and numerous other campaigns where the targets were civil society organizations rather than government or military systems.