In January 2010, Google announced that it had been the target of a "highly sophisticated and targeted attack on our corporate infrastructure originating from China." This was extraordinary: a major US technology company publicly attributing a breach to Chinese state-sponsored hackers. The announcement named at least twenty other large US companies as co-victims and disclosed that the attackers had accessed Gmail accounts of Chinese human rights activists. Google threatened to stop censoring search results in China and potentially leave the Chinese market entirely. The breach, named Operation Aurora by McAfee, fundamentally changed how the security industry understood Chinese cyber espionage.
Aurora was not the first Chinese cyber espionage campaign against US technology companies - Titan Rain (2003-2005) had targeted defense contractors, and Operation Shady RAT had been running for years. But Aurora was the first time a major US corporation publicly called out China by name, and the first time the public understood the scale of Chinese industrial espionage targeting Silicon Valley. The companies that Google listed as co-victims included Adobe, Juniper Networks, Rackspace, Yahoo, and Symantec. The actual list of victims, revealed in later investigations, was over 30 companies.
The Initial Compromise Vector
The attackers used a zero-day vulnerability in Internet Explorer 6 (CVE-2010-0249) to achieve initial access. The attack was delivered through a targeted spear-phishing email or instant message containing a link to a malicious website. When visited in IE6, the page exploited the vulnerability to install malware on the victim's machine without user interaction beyond clicking the link.
The IE6 vulnerability was a use-after-free in the browser's handling of certain HTML objects. Microsoft had not patched it at the time of the attacks - it was a genuine zero-day. Google's network traffic analysis found evidence that the attack had been running since mid-2009 before Google became aware of it.
The initial foothold malware connected to C2 infrastructure using SSL-encrypted communications, blending with normal HTTPS traffic. The C2 servers were hosted primarily in Taiwan and elsewhere in Asia. The malware - later named Hydraq by McAfee - established persistence, gathered system information, and provided a remote shell for the attackers.
What Was Stolen
At Google, the attackers accessed the source code repository - specifically, targeting the password management system Gaia, which controls access to Google's authentication infrastructure. The attackers were searching for information about specific named individuals: Chinese human rights activists whose Gmail accounts they had identified. The goal appears to have been identifying whether the Chinese government's surveillance of these individuals was being monitored or disrupted by Google, and gaining access to the activists' accounts and communications.
Google disclosed that it found evidence the attackers had accessed the Gmail accounts of approximately two dozen US, China, and Europe-based advocates of human rights in China. The access was primarily achieved through the social engineering of account holders rather than through direct exploitation of Google's infrastructure - phishing the individuals whose accounts were of intelligence interest.
At other companies, the targets were more clearly industrial espionage: source code, product roadmaps, customer lists, pricing data. The breadth of the campaign - 30+ companies across technology, defense, finance, and energy - was consistent with a state-sponsored systematic effort to acquire US intellectual property rather than a single targeted operation.
Attribution: APT1 and PLA Unit 61398
The Aurora attackers were attributed to a group that the security industry came to call APT1 - Advanced Persistent Threat 1. In February 2013, Mandiant published a landmark report ("APT1: Exposing One of China's Cyber Espionage Units") that attributed the group to PLA Unit 61398, a specific military unit of the People's Liberation Army based in Pudong, Shanghai.
The Mandiant report was the most detailed public attribution of a state cyber espionage group to that point. It included photographs of the unit's building, organizational details, and specific individual identifiers (handles, email addresses) for operators. The report documented APT1 activity from 2006-2013 across 141 companies in 20 industries.
The US Department of Justice followed the Mandiant report with the first-ever indictment of foreign government officials for cyber espionage in May 2014, charging five PLA officers by name with hacking US steel, solar, and nuclear power companies. China rejected the indictment as fabricated, suspended participation in a US-China cyber working group, and the named individuals remained in China beyond US legal reach. The indictments were largely symbolic but established a precedent that the US government was willing to name state actors publicly.
Google's Response: China Exit Threat
Google's public attribution and response to Aurora was unprecedented. The company disclosed that in addition to the corporate espionage, the attackers had targeted Chinese human rights activists' accounts - framing the attack not just as industrial espionage but as an attack on Google's users and on freedom of expression.
Google announced it would stop censoring search results for google.cn and would no longer operate a censored search engine in China. In March 2010, Google redirected all google.cn traffic to the uncensored google.com.hk, effectively abandoning the Chinese search market. The decision cost Google a significant market position - Baidu had around 60% market share in China, and Google was the primary competitor. Google chose its stated principles over market share.
The political and corporate response to Aurora established a pattern that subsequent Chinese cyber espionage incidents would follow: public attribution from private security firms, government naming of state actors, diplomatic friction, nominal consequences, and continued espionage. The specific activity attributed to APT1 decreased after the Mandiant report - not because China stopped, but because the group's infrastructure was burned and operations shifted to less attributable units.