Network security firm FireEye revealed that Chinese hackers breached the computer systems of five European foreign ministries before the latest G20 summit.
The cyberattack was accomplished by sending a spam email containing a malicious file titled “US_military_options_in_Syria.” When the recipient opened the file, it infected their computer.
The company said it had control of the main command and control (C&C) server used by the hackers in late August. However, researchers lost access after the hackers moved to another server before the start of the G20 summit.
FireEye believes the hackers carried out the attack to steal data from these computers.
Based on the evidence, especially the language used on the hacker's server and the computers used for malware testing, researchers concluded that the attack originated in China.
