Don’t do SECURITY. Do business SECURELY.

McAfee report details five-year ‘Operation Shady RAT’ espionage campaign

McAfee reported a five-year cyber espionage campaign, dubbed Operation Shady RAT, that it said had compromised at least 72 organisations.

Security firm McAfee published research on Operation Shady RAT, a cyber espionage campaign it said had compromised at least 72 organisations over around five years. Researcher Dmitri Alperovitch said the victims spanned governments, international bodies, and companies in 14 countries.

What happened

  • Victims reportedly included government agencies, defence contractors, technology companies, and international organisations.
  • Some intrusions lasted as long as 28 months, according to the report.
  • McAfee said it believed a single state actor was behind the campaign but did not name the country.
  • Some other security firms questioned whether the findings were new, noting that such targeted intrusions were already well known to specialists, and criticised the report’s dramatic framing.

Why it mattered

The report helped bring the scale of long-running espionage campaigns into public view and fed a wider political debate about state-sponsored hacking. McAfee described it as one of the largest transfers of wealth in terms of intellectual property.

Lessons for organisations

Plan on the basis that a determined attacker may already be inside your network; invest in logging, detection, and threat hunting as well as prevention. Protect sensitive intellectual property with access controls and monitoring.

Sources: MIT Technology Review, CSO Online

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights