Sleuths Trace New Zero-Day Attacks to Hackers Who Hit Google
It's been more than two years since Google broke corporate protocol by revealing that it had been the victim of a persistent and sophisticated hack, traced to intruders in China that the company all but said were working for the government.
Context & Ripple Effects
The story closes a loop opened in January 2010, when Google used its 'new approach to China' post to disclose a persistent, sophisticated intrusion it implied was state-backed — breaking with the corporate norm of silent remediation. A month later, the detailed report on hacks targeting Google and others showed the operation had swept in dozens of companies, making the Google case the reference point for advanced persistent threats.
What is new on September 8, 2012 is continuity: researchers have tied fresh zero-day attacks to the same crew responsible for the original Google breach, meaning the group stayed active for more than two years after its highest-profile target went public. The pickup across eight outlets — Ars Technica, CNET, The Verge, Computerworld, eWeek and others — shows how much attention attribution stories now command. It lands one day after Google confirmed its acquisition of VirusTotal, putting the company deeper into the threat-intelligence business even as its own adversaries resurface.
First-order effects
- Organizations hit by the new zero-days gain actionable attribution: their attacker is the same group that breached Google in 2010, letting defenders prioritize against a known, long-running operator rather than an unknown one.
- Google's 2010 decision to name its intruders is vindicated as an investigative asset — the public record of tactics from that breach is what allows researchers to connect the new attacks at all.
Second-order effects
- Other companies targeted by the same group face mounting pressure to follow Google's disclosure playbook, since silence now leaves them as unreported data points in someone else's attribution work.
- Security vendors and the nascent threat-intel market get a demand signal: multi-year actor tracking across zero-day campaigns is the product customers will pay for, a space Google just entered via VirusTotal.
Third-order effects
- If attribution keeps sticking years after the fact, state-linked hacking stops being an episodic incident and becomes a named, persistent adversary that boards and regulators must plan around — eroding the assumption that a breach ends when the intruders leave.
- Google's path from victim to discloser to intelligence collector sketches a structural shift: private companies, not governments, becoming the primary public identifiers of nation-state cyber operations.
The trend: State-backed hacking groups are operating as continuous multi-year campaigns, and private-sector attribution — pioneered by Google's 2010 disclosure — is hardening into standard practice.