On January 12, 2010, Google published a blog post that changed the geopolitics of the internet. Titled "A New Approach to China," it announced that Google had detected "a highly sophisticated and targeted attack on our corporate infrastructure originating from China." The company disclosed that at least twenty other major companies had been targeted in the same campaign. The attacks, researchers later named "Operation Aurora," introduced the world to the concept of the Advanced Persistent Threat - and to the reality that nation-state actors were systematically targeting the most valuable intellectual property on the planet.

Discovery

Google's security team first detected the intrusion in December 2009, when they noticed unusual exfiltration of source code from internal repositories. The initial investigation revealed the attackers had compromised a small number of employee accounts and from there navigated to intellectual property storage systems. When Google broadened the investigation, they found something more alarming: the surveillance systems the company had built to comply with US lawful intercept requirements had been accessed. The court order compliance system - the mechanism through which Google received and responded to legal demands from law enforcement - had been breached.

The implication was significant. Anyone with access to that system could see which Gmail accounts were under active surveillance by US intelligence services. If those accounts included Chinese dissidents, human rights workers, or government officials, the attackers now had a list of individuals the United States was watching - valuable counterintelligence and potentially a way to identify intelligence sources.

[WARNING]
Google's discovery that its lawful intercept compliance infrastructure had been targeted directly contributed to years of debate about the risks of CALEA-style surveillance backdoors. The argument: any access mechanism built for authorized parties is also a target for unauthorized ones. Salt Typhoon's 2024 breach of US telecom carriers via CALEA infrastructure confirmed this concern was not hypothetical.

The Vulnerability: IE 6 and CVE-2010-0249

The initial infection vector was CVE-2010-0249, a use-after-free vulnerability in Internet Explorer's handling of HTML objects. The exploit worked on Internet Explorer 6, 7, and 8, though the most reliable exploitation was against IE 6 - still approximately 22% of the browser market at the time of discovery.

The attack chain was a spear phishing campaign of unusual sophistication. Targets received email or instant messages crafted to exploit existing relationships - in some cases, messages that appeared to come from trusted colleagues. The messages contained links to websites controlled by the attackers. Visiting the site in IE triggered the exploit, which dropped a dropper disguised as a JPEG file containing shellcode that decoded and executed a custom backdoor. The backdoor - later named "Hydraq" or "Aurora RAT" by different vendors - connected to command and control infrastructure hosted in Taiwan using SSL to encrypt the traffic.

The name "Aurora" came from the malware itself: investigators found references to a filepath containing the string "Aurora" in the malware samples, suggesting it was the internal project name used by the attackers.

[TECHNICAL NOTE]
The Aurora backdoor was notable for its evasion techniques. It used a custom binary protocol over SSL on port 443 to blend with legitimate HTTPS traffic, performed minimal filesystem writes (most activity was in-memory), and used a compressed, XOR-obfuscated PE payload. For 2009, this represented a meaningfully more sophisticated approach than commodity RATs in use at the time.

Scope: Twenty Companies and Beyond

Google's disclosure acknowledged at least twenty targeted organizations in the same campaign. Companies that publicly confirmed they were targeted or compromised include: Adobe, Juniper Networks, Rackspace, Symantec, Northrop Grumman, Dow Chemical, and Morgan Stanley. Several companies declined to comment or confirm, and the full list has never been made public. Estimates from investigators who worked the cases put the number of affected organizations considerably higher than twenty.

The targeting was not random. Adobe was targeted for its source code - widely deployed PDF and Flash software represented valuable access to supply chain compromise possibilities. Juniper's network equipment source code would be valuable for developing exploits against the network infrastructure of anyone using their products. Defense contractor Northrop Grumman represented direct access to weapons systems research. The pattern was consistent with state-sponsored intellectual property theft and pre-positioning for future operations.

Attribution and the APT Framework

The US Air Force had coined the term "Advanced Persistent Threat" internally before Aurora, but the public use of the phrase to describe a specific type of threat actor emerged from the Aurora investigation. The characteristics that defined the category: advanced technical capabilities (custom malware, zero-day exploits), persistence (long dwell times, maintained access over months), and threat in the strategic sense (targeting determined by nation-state intelligence objectives).

Attribution to China was publicly stated by Google and confirmed by US government assessments. The technical evidence included server infrastructure in China, malware compilation artifacts with Chinese language settings, targeting patterns consistent with Chinese intelligence priorities, and code reuse with tools previously associated with Chinese actors. The diplomatic cable released by WikiLeaks later that year included an assessment attributing the attacks to the Politburo Standing Committee, identifying the operation as part of China's ongoing effort to monitor dissidents and steal Western technology.

The specific threat actor group behind Aurora is believed to be what Mandiant later designated APT17 (or DEPUTY DOG), distinct from the more famous APT1 (Comment Crew) exposed in the 2013 Mandiant report. Some assessments attributed portions of the campaign to APT10. The Chinese intelligence structure uses multiple units with overlapping targets, making clean attribution to a single organizational entity difficult.

Google's Ultimatum

The most extraordinary aspect of Google's response was not the disclosure - it was the ultimatum embedded in it. Google announced that as a result of the attack and the "attempts over the past year to further limit free speech on the web," the company was "no longer willing to continue censoring our results on Google.cn." If Google could not reach an agreement with the Chinese government to operate an unfiltered search engine, it would close its China operations entirely.

Google had launched Google.cn in 2006 under significant internal controversy, agreeing to self-censor search results for politically sensitive queries as a condition of operating in China. The Aurora attacks - and specifically the discovery that the surveillance system had been compromised, potentially to identify Chinese dissidents who used Gmail - appears to have been the decisive factor in the company's position change.

Negotiations with the Chinese government proceeded for several months. In March 2010, Google stopped censoring Google.cn and began redirecting Chinese users to Google.com.hk, operating from Hong Kong which is technically under different legal jurisdiction from mainland China. The Chinese government responded by blocking Google services intermittently and then increasingly completely. By 2012, Google's market share in China had fallen to below 5%. Baidu, which had agreed to censorship requirements, benefited directly.

[INFO]
The "A New Approach to China" post was drafted with significant involvement from Google co-founder Sergey Brin, whose family had emigrated from the Soviet Union and who opposed censorship on principle. Internal accounts describe Brin as the driving force behind the decision to go public and deliver the ultimatum rather than quietly absorb the breach and continue China operations.

The 2013 Mandiant Report and APT1

While Aurora was attributed to Chinese actors, the full picture of systematic Chinese cyber espionage didn't become public until February 2013, when Mandiant published "APT1: Exposing One of China's Cyber Espionage Units." The report documented in extraordinary detail the operations of a unit Mandiant designated APT1, attributing it with high confidence to the People's Liberation Army's 3rd Department, 2nd Bureau - Unit 61398, operating from a specific building in Pudong, Shanghai.

The report documented 20 industries targeted over seven years, terabytes of stolen data, and identified specific individuals by their online handles and linked them to real names and locations. It was the most detailed public attribution of a nation-state hacking operation ever published at the time. The Chinese government denied the allegations entirely.

The Mandiant report directly enabled the 2014 DOJ indictment of five PLA officers - Wang Dong (UglyGorilla), Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui - for computer fraud and economic espionage. None of them were extradited; the indictments stood as a statement of attribution and a precedent for future actions, including the 2020 indictments of MSS officers for APT41 activity.

Legacy: The Era of State-Sponsored Hacking

Operation Aurora marked the moment when corporate security teams had to account for an adversary category that had previously been considered government-only: nation-states with dedicated, well-resourced, long-horizon intrusion capabilities targeting private companies for intellectual property and strategic intelligence.

The pre-Aurora threat model assumed the primary attackers were financially motivated criminals (credit card theft, fraud) and opportunistic hackers. The post-Aurora model required companies - especially those in defense, aerospace, technology, pharmaceuticals, and energy - to consider that government intelligence services were specifically targeting their intellectual property, with no financial motive, willing to maintain persistent access for years.

The terminology Aurora created - APT, threat actor groups, nation-state hacking - became the dominant framework for the field. The Mandiant APT numbering system (APT1, APT28, APT29) became the standard. Every major intelligence vendor now publishes threat intelligence reports using APT-derived frameworks. The entire sector of threat intelligence - as a commercial product sold to enterprises - exists largely because Operation Aurora demonstrated there was a market for it.

What Google discovered in December 2009 was not an isolated incident. Aurora was the moment the rest of the world caught up to what the intelligence community had known for years: the most capable attackers on the internet were not in it for the money.