CASE FILE
INC-20100112-AURORA
MID-2009 – JAN 2010
TLP:CLEAR
// Cyber Incident Case File — Nation-State Cyber Espionage / Zero-Day Intrusion Campaign

OPERATION AURORA

COMPILED: 2026-08-29  |  INCIDENT DATE: MID-2009 (initial intrusions) to 2010-01-12 (public disclosure)  |  SOURCES: Google Official Blog · McAfee Labs · Symantec · MITRE ATT&CK (G0066) · Dark Reading · Wired · The New York Times · CFR Cyber Operations Tracker · Wikipedia · SecurityWeek · Security Affairs · CVE/NVD records
Incident Type: Nation-State Cyber Espionage — Zero-Day Intrusion Campaign
Attribution: ELDERWOOD GROUP (CHINA-NEXUS) [MEDIUM]
Severity: CRITICAL (Historical)
Era: Pre-ATT&CK / Early Public-Attribution Era
ATT&CK Framework: Enterprise (Retrospective)
34+
Organizations Reportedly Targeted Across Tech, Defense & Chemical Sectors
CVE-2010-0249
Zero-Day Internet Explorer Use-After-Free Exploited As Entry Vector
~6 Months
Estimated Attacker Presence In Google's Network Prior To Detection
2010
Year Google Withdrew Censored Search From Mainland China
00
Case File Overview
Attributed Actor → No companion actor card on file — tracked as MITRE ATT&CK G0066 "Elderwood"; attribution confidence MEDIUM, has not reached indictment-level certainty
Incident NameOperation Aurora
Date RangeMid-2009 (initial intrusions) – 2010-01-12 (Google's public disclosure)
Incident TypeNation-State Cyber Espionage / Zero-Day Intrusion Campaign
Primary ActorElderwood Group (aka Beijing Group, Elderwood Gang, Sneaky Panda) — assessed China-nexus
Attribution ConfidenceMEDIUM — compelling circumstantial and technical evidence; never reached indictment-level certainty
Primary TargetGoogle Inc. corporate infrastructure (source code, Gaia SSO system, Gmail activist accounts); 30+ additional companies
Victim Count20 confirmed in Google's initial disclosure; subsequent reporting places the total at 30–34+ organizations
Initial DiscoveryMid-December 2009 (approx. Dec 14) — anomalous access detected on Google's internal network
Discovered ByGoogle's internal security team; McAfee Labs engaged during incident response and named the campaign
Dwell TimeEstimated several months — activity reportedly began mid-2009, undetected until December
Primary ImpactTheft of intellectual property/source code; attempted compromise of Gmail accounts of Chinese human-rights activists; Google's exit from mainland Chinese search
ATT&CK FrameworkEnterprise (Retrospective) — predates ATT&CK's 2013 introduction
MITRE Campaign IDNot catalogued as a distinct Campaign — tracked at group level only (G0066, Elderwood)
Historical IOCsC2 infrastructure and file hashes from 2009–2010 are long defunct; retained for research/retrospective value only
01
Situation Overview

On January 12, 2010, Google took an extraordinary step for the era: it published a blog post stating that it — along with at least 20 other major companies — had been the target of "a highly sophisticated and targeted attack on our corporate infrastructure originating from China" (Google Official Blog, Jan 2010). The intrusion, later dubbed "Operation Aurora" by McAfee Labs after a file-path string ("Aurora") found embedded in the attackers' binaries (McAfee Labs, Jan 2010), had begun months earlier and gone undetected until Google's internal security team noticed anomalous access to corporate systems in mid-December 2009.

The attackers' objectives were twofold and, in retrospect, unusually candid about intent: steal intellectual property, and gain access to the Gmail accounts of Chinese human-rights activists. Google stated that source code had been accessed and that at least two Gmail accounts saw unauthorized access limited to header and account-creation-date metadata rather than message content (Google Official Blog, Jan 2010). Reporting later indicated that among the systems reached was Gaia, Google's single sign-on authentication infrastructure — a target whose compromise would have carried implications well beyond one company's stolen code.

Operation Aurora is remembered less for technical novelty — a spear-phish/instant-message lure delivering an Internet Explorer zero-day (CVE-2010-0249) was sophisticated for its time but not unprecedented — than for what its disclosure broke open. It was one of the first instances of a major U.S. technology company publicly and directly attributing an intrusion to China rather than quietly remediating, and it used that disclosure to justify a consequential business decision: ending censorship of search results on google.cn and, in effect, withdrawing from operating a censored search engine on the mainland.

The campaign is attributed with medium confidence to a persistent China-based espionage cluster later named "Elderwood" by Symantec (from a source-code variable it used), and independently tracked as the "Beijing Group" by Dell SecureWorks and "Sneaky Panda" by CrowdStrike — now catalogued by MITRE ATT&CK as G0066. That same infrastructure and tradecraft reportedly persisted for years afterward, targeting defense contractors, NGOs, and supply-chain software vendors, meaning Aurora was not an isolated event but the first publicly visible instance of an operation that continued long after Google made it famous.

02
Background & Context

Google's censored Chinese search engine, google.cn, had operated since 2006 under an arrangement with Beijing that drew sustained criticism from free-speech and human-rights advocates in the U.S. Congress and abroad. That tension was already live for Google well before December 2009; the discovery that the same intrusion had targeted Gmail accounts belonging to Chinese human-rights activists gave the company both a security rationale and a values-based one to revisit the arrangement (Google Official Blog, Jan 2010).

Internet Explorer 6 remained the dominant enterprise browser in 2009–2010 despite being eight years old and carrying substantial accumulated legacy vulnerabilities, and "advanced persistent threat" was a term barely a few years into public use (popularized by U.S. Air Force officials around 2006). The notion that a nation-state might run a sustained, multi-victim espionage campaign against private industry — rather than against government or military targets — was still met with public skepticism ahead of Google's disclosure. Commercial antivirus of the era was overwhelmingly signature-based and had no meaningful visibility into a novel zero-day payload like Hydraq.

Retrospective research published by Symantec in 2012 ("The Elderwood Project") found forensic evidence tying the same toolset and delivery infrastructure used in Aurora to intrusions predating the Google case by as much as three years, indicating the cluster later blamed for Aurora had likely been operating against other, undisclosed victims well before it became famous. None of that earlier activity had been publicly connected until Google's disclosure prompted retrospective threat-hunting across other victim organizations' logs.

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Targeted Lure Delivery BLIND
Attackers approached at least one employee at a targeted organization through Microsoft Messenger instant-chat software, sending a link framed to appear as though it came from a trusted contact. Similar targeted emails and IM-based lures were used across the wider victim set, tailored per organization rather than mass-distributed (McAfee Labs, Jan 2010).
Because the lure arrived through a channel largely outside the email security controls of the time, most victim organizations had no logging or detection capability covering the initial contact.
Zero-Day Exploitation (CVE-2010-0249) BLIND
Clicking the link directed the victim's browser — running an unpatched Internet Explorer 6, 7, or 8 — to a server hosting JavaScript that triggered a use-after-free memory-corruption flaw in IE's layout engine (mshtml.dll), achieving arbitrary code execution with no further user action required. The exploit had genuine zero-day status: no patch existed anywhere until Microsoft's out-of-band update on January 21, 2010 (Microsoft MS10-002; CVE-2010-0249).
Because this was a true zero-day, no signature- or patch-based defense could have stopped exploitation at this stage — a gap common to Elderwood's later campaigns as well, per Symantec's follow-on research.
Hydraq Backdoor Deployment & Persistence BLIND
Successful exploitation dropped and executed Trojan.Hydraq (also referred to as the "Aurora" backdoor), a data-theft trojan that established persistence by riding on the Windows svchost.exe service process, and downloaded additional components including a VNC-based module capable of streaming a live view of the victim's desktop to the attackers (Symantec, 2010). Command-and-control traffic was styled to resemble ordinary HTTP/HTTPS web traffic to blend into normal network flows.
Hydraq's persistence and evasion techniques were individually unremarkable but combined to defeat the endpoint and network monitoring typical of large enterprises at the time.
Internal Reconnaissance & Lateral Movement BLIND
Once inside, operators used harvested credentials and internal access to move toward higher-value targets — engineers and systems tied to source-code repositories. At Google specifically, reporting indicates the intrusion reached systems associated with Gaia, the company's single sign-on/password-authentication infrastructure, as well as broader source-code repositories (Wired, 2010; New York Times, 2010).
The multi-month dwell time before detection indicates lateral movement went uncaught by contemporaneous internal monitoring — Google, like most victims, discovered the intrusion after the theft had already occurred, not during it.
Exfiltration & Gmail Access Attempts BLIND
Attackers exfiltrated portions of source code from at least some victims, and separately attempted to access the Gmail accounts of Chinese human-rights activists. Google stated the Gmail-related access was limited — for two accounts, attackers appeared to have accessed only account-creation-date and subject-line metadata rather than message content (Google Official Blog, Jan 2010) — but the intent was unambiguous given the political sensitivity of the target list.
Neither the source-code theft nor the Gmail access attempts were detected as they happened; both were reconstructed after the fact during Google's investigation.
Detection & Public Disclosure DETECTED
In mid-December 2009, Google's internal security team detected anomalous activity on its corporate network and opened an investigation that, over the following weeks, uncovered the wider campaign against dozens of other companies. On January 12, 2010, Google published its findings on its official blog — an unusually direct public attribution to China for a major U.S. company at the time — and announced it would stop censoring search results on google.cn. McAfee Labs, brought in during the response, named the campaign "Operation Aurora" after a string found in the attackers' file paths.
04
TTPs — MITRE ATT&CK Mapping Pre-ATT&CK incident (2009–2010); all techniques are retrospective mappings
[RETROSPECTIVE]
Reconnaissance
T1591
Gather Victim Org Information
[MEDIUM] Identified specific employees at each target organization with access to source-code repositories or sensitive systems, enabling per-victim tailored lures rather than mass phishing.
[RETROSPECTIVE]
Initial Access
T1566.002
Phishing: Spearphishing Link
[HIGH] Delivered a malicious link via Microsoft Messenger IM (and email at other victims), framed to appear as coming from a trusted contact.
[RETROSPECTIVE]
Initial Access
T1189
Drive-by Compromise
[MEDIUM] Victims were redirected to an attacker-controlled site hosting the CVE-2010-0249 exploit chain, requiring only a page visit to trigger.
[RETROSPECTIVE]
Execution
T1203
Exploitation for Client Execution
[HIGH] Use-after-free vulnerability in Internet Explorer's mshtml.dll layout engine (CVE-2010-0249) achieved arbitrary code execution with no patch available at time of use.
[RETROSPECTIVE]
Persistence
T1543.003
Create or Modify System Process: Windows Service
[HIGH] Trojan.Hydraq installed itself dependent on the svchost.exe service host process to survive reboots and blend with legitimate Windows services.
[RETROSPECTIVE]
Defense Evasion
T1027
Obfuscated Files or Information
[MEDIUM] Packed and encrypted the Hydraq payload and its configuration/communications to hinder static analysis and signature detection.
[RETROSPECTIVE]
Lateral Movement
T1078
Valid Accounts
[MEDIUM] Used credentials and internal access harvested post-compromise to reach source-code systems and, per reporting, components of Google's Gaia SSO infrastructure.
[RETROSPECTIVE]
Command & Control
T1071.001
Application Layer Protocol: Web Protocols
[HIGH] C2 traffic was styled to resemble ordinary HTTP/HTTPS web traffic to blend into normal enterprise network flows.
[RETROSPECTIVE]
Collection
T1114
Email Collection
[LOW] Attempted access to Gmail accounts of Chinese human-rights activists; Google reported access limited to account metadata for the accounts it could confirm, not message content.
[RETROSPECTIVE]
Exfiltration
T1041
Exfiltration Over C2 Channel
[MEDIUM] Source code and related intellectual property were removed from victim networks over the same channel used for command and control.
05
Defender Post-Mortem What was missed, when, and why
INITIAL ACCESS &
EXPLOITATION
MISSED
No victim organization detected the IM-based lure or the CVE-2010-0249 exploitation at the point of compromise. No patch or reliable signature existed until Microsoft's out-of-band fix (MS10-002) shipped on January 21, 2010 — over a month after Google's public disclosure of the campaign.
LATERAL MOVEMENT &
EXFILTRATION
PARTIALLY DETECTED
Google's security team identified the intrusion only after attackers had already operated inside the network for months and reached source-code systems. Detection came from retrospective anomaly review of internal access logs, not a real-time alert tied to the exploit, the Hydraq backdoor, or the exfiltration itself.
POST-INCIDENT
LESSON ADOPTED
The incident directly catalyzed Google's multi-year shift toward what became the BeyondCorp zero-trust architecture, broader industry adoption of default two-factor authentication, and the later creation of Google's Project Zero vulnerability-research team.
INDUSTRY-WIDE
LESSON ADOPTED
Symantec's and McAfee's public technical write-ups on Hydraq and the wider Elderwood cluster produced one of the earliest widely shared, cross-vendor case studies of a nation-state intrusion, accelerating the adoption of formal indicator-of-compromise sharing as a standard threat-intelligence practice.
06
Technical Artifacts Malware, tools, CVEs, IOCs
Trojan.Hydraq (aka "Aurora" Backdoor)
RAT / Backdoor [HISTORICAL — Limited detection utility]
Windows backdoor delivered via the CVE-2010-0249 exploit chain; persisted as a service riding on svchost.exe, encrypted its configuration, and communicated over HTTP/HTTPS-styled C2 channels designed to blend with legitimate traffic. Downloaded secondary modules including a VNC-based remote-desktop-streaming component. Later Hydraq variants were observed years after Aurora in unrelated China-nexus campaigns, tracked by MITRE ATT&CK as Software S0203 (Symantec, 2010; MITRE ATT&CK).
CVE-2010-0249 — Internet Explorer Use-After-Free
Zero-Day Exploit [HISTORICAL — Patched since 2010]
Use-after-free vulnerability in Internet Explorer's mshtml.dll layout engine affecting IE 6, 6 SP1, 7, and 8 on Windows 2000 through Windows 7; exploited by manipulating object references during page rendering to achieve arbitrary code execution. Patched out-of-band by Microsoft in security bulletin MS10-002, released January 21, 2010 (CVE-2010-0249; Microsoft MSRC).
Elderwood Exploit-Delivery Platform
Exploit Framework [HISTORICAL — Infrastructure retired]
Symantec's 2012 "Elderwood Project" research described a shared exploit-delivery platform reused across multiple zero-days (Flash, Internet Explorer, PDF readers) by the same actor cluster over several years, indicating sustained access to a pipeline of unpatched vulnerabilities rather than one-off tool development — a hallmark used to distinguish well-resourced state-linked operators from typical criminal groups (Symantec, 2012; Security Affairs).
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling.
⚠ HISTORICAL IOCs — These artifacts are archival. Infrastructure has long since rotated. Use for research and retrospective analysis only.
TypeValue / DescriptionSourceDate
CVECVE-2010-0249 (MS10-002) — IE mshtml.dll use-after-freeMicrosoft MSRC / NVD2010-01-21
MALWARETrojan.Hydraq / "Aurora" backdoor sample familySymantec2010-01
BUILD ARTIFACT"Aurora" string embedded in attacker build-path metadata (origin of the campaign name)McAfee Labs2010-01-14
NOTENo consistently corroborated public list of C2 domains or IP addresses specific to Operation Aurora was identified in open-source reporting for this card. Later-generation Elderwood infrastructure (2010–2012) is catalogued in Symantec's "Elderwood Project" whitepaper; consult that source directly rather than treating any domain as an Aurora-specific IOC.
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
Directly triggered Google's decision to stop censoring search results on google.cn and redirect mainland Chinese users to the uncensored google.hk site — a rare instance of a major U.S. company taking a public, human-rights-driven stance against Beijing. On January 21, 2010, U.S. Secretary of State Hillary Clinton delivered an "Internet Freedom" speech directly referencing the intrusion and calling on China to investigate, elevating a corporate security incident to inter-state diplomatic friction.
⬡ Technical / Capability
Accelerated Google's internal work that became the BeyondCorp zero-trust architecture, treating internal network location as untrusted and shifting toward identity- and device-based access control. Widely credited, alongside subsequent incidents, as a catalyst for Google's later creation of Project Zero and for the broader industry's move toward default two-factor authentication.
⬡ Legal / Regulatory
No indictments were filed in connection with Operation Aurora specifically — attribution never reached the evidentiary standard needed to support criminal charges, unlike later cases (e.g., the 2014 U.S. indictment of PLA Unit 61398 members). The incident nonetheless fed into a broader U.S. policy and congressional focus on Chinese state-linked economic cyber-espionage that shaped later, more formal responses.
08
Attribution
ATTRIBUTION CONFIDENCE: MEDIUM
Attributed ToElderwood Group (aka Elderwood Gang, Beijing Group [Dell SecureWorks], Sneaky Panda [CrowdStrike]) — MITRE ATT&CK G0066
SponsorAssessed ties to the Chinese People's Liberation Army; not officially confirmed via indictment
Formal AttributionNo formal U.S. government attribution or indictment specific to this campaign; Google's January 2010 disclosure named China as point of origin without naming a specific group or state entity
IndictmentsNone filed in connection with this specific campaign
Companion Actor CardNone on file — Elderwood / G0066 not yet profiled separately in this library
Primary EvidenceMalware code-reuse and infrastructure overlap linking Hydraq/Aurora tooling to later Elderwood campaigns (Symantec's 2012 Elderwood Project research); New York Times reporting citing investigators who traced attack traffic to Shanghai Jiaotong University and the Lanxiang Vocational School
Competing HypothesesBoth named Chinese schools publicly and vigorously denied involvement; the Lanxiang school's dean disputed that its students had the technical sophistication attributed to them, and some researchers have noted it would be operationally unusual for a state-directed campaign to launch visibly from institutions with traceable government ties — raising an alternative possibility of compromised or staging infrastructure at those institutions rather than direct involvement
What Would Change AssessmentA formal indictment (as later occurred for APT1/PLA Unit 61398) naming specific individuals or a PLA unit tied to the Aurora-era Hydraq toolset and infrastructure would raise confidence to HIGH; verifiable evidence that the Jiaotong/Lanxiang traffic was itself compromised third-party infrastructure rather than direct involvement would lower it further

Attribution confidence for Operation Aurora sits at MEDIUM. The forensic case for a coherent, persistent China-based actor cluster is strong: Symantec's follow-on "Elderwood Project" research traced shared malware code, exploit-delivery infrastructure, and targeting logic across years of intrusions before and after Aurora. The case for direct Chinese state sponsorship, while widely assumed at the time and since, never reached the indictment-level evidentiary standard later applied to cases such as the 2014 PLA Unit 61398 charges. The New York Times' contemporaneous reporting connecting the intrusion to two China-based schools added a specific, disputed data point rather than definitive proof — both institutions denied involvement, and the claim has never been independently corroborated in public record. The defensible characterization is "China-nexus, assessed state-tied"; treating this as attribution to a specific PLA unit or named individuals is not supported by public evidence.

09
Historical Significance

Operation Aurora is widely credited as one of the first publicly disclosed, high-profile nation-state cyber-espionage campaigns against Western private industry, and the first in which a major technology company chose public attribution and transparency over quiet remediation. That choice — made by Google in January 2010 — reset the norm: within a few years, public attribution of state-linked intrusions by both companies and governments became a standard part of the incident-response and policy toolkit rather than a rare exception.

It also produced one of the earliest well-documented "APT ecosystems" in open-source reporting. The Elderwood cluster's multi-year reuse of a shared zero-day delivery platform, first connected to Aurora and later mapped across dozens of additional intrusions by Symantec's 2012 research, demonstrated that a single actor could sustain access to a pipeline of unpatched vulnerabilities — a capability signature analysts still use today to distinguish well-resourced state-linked groups from opportunistic criminal actors.

Finally, Aurora is a foundational case study in how a single security incident can reshape corporate strategy and international relations simultaneously: it drove Google's exit from mainland Chinese search, informed the design of the BeyondCorp zero-trust model, and prompted a sitting U.S. Secretary of State to give a major policy speech naming a specific corporate intrusion. Few incidents before or since have connected a browser use-after-free bug this directly to geopolitics, which is why it remains a mandatory case study in CTI, incident-response, and cyber-policy curricula alike.

10
References URLs are NOT defanged — navigate directly
Wikipedia
Accessed: 2026-08-29
MITRE ATT&CK
Accessed: 2026-08-29
McAfee Labs
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2010-01
McAfee Labs
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2010-01
Dark Reading
Accessed: 2026-08-29
Dark Reading
Accessed: 2026-08-29
NVD / CVE Details
Accessed: 2026-08-29
NBC News
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2010-01
Wikipedia
Accessed: 2026-08-29
Google (Keyword Blog)
Accessed: 2026-08-29