Menu
Second Chinese army unit linked to corporate cyber-espionage

Second Chinese army unit linked to corporate cyber-espionage

Internet postings link a Chinese hacking group to a military unit

A Chinese hacking group that has attacked U.S. and European aerospace and communications companies is almost certainly linked to the Chinese military, a U.S. Internet security company said Monday.

"Putter Panda" has been active for several years, and a trail of Internet postings and domain registrations by one of its members points to it being part of Unit 61486 of China's People's Liberation Army, said Irvine, California-based CrowdStrike in a 62-page report.

The unit is different from the one recently named by the U.S. Department of Justice in a series of indictments of Chinese citizens.

CrowdStrike said the link between the attacks and the Chinese army was established through a number of Internet postings, photo uploads and domain registrations made by one of the group's members.

The same name, Chen Ping, or associated email addresses and aliases were used to register a number of domain names that were used to host malware or control hacking tools. Some contain the names of major Japanese gaming companies, such as Konami and Namco, while others mention Kyocera, BMW and Nestle. There's also one named "Windows Updote," an easily missed incorrect spelling of Microsoft's Windows Update.

Accounts on websites and blogs pointed to Chen living in Shanghai and having an interest in Internet security. In one photo uploaded after a drinking session with friends, two PLA officers' peaked caps can be seen in the background.

Another picture posted by Chen from "the office" shows several large satellite dishes on the grounds of the building's compound. The dishes have been located at a Shanghai building known to house a PLA signals intelligence unit. As if to make the link clearer, Chen at one point registered one of his domain names to the building's address.

"When you look at operational security of some of the folks involved in this high-profile cyber-espionage, you would think they would be a little more careful about how they operate," said George Kurtz, president and CEO of CrowdStrike.

But despite its poor operational security, Unit 61486 is a determined adversary, the report said.

"They are roughly equivalent to the other actors we've seen coming out of China," said Adam Meyers, CrowdStrike's vice president of intelligence. "They've got a whole bunch of custom stuff they have built, a lot of different tools, and they have some degree of capability."

In late May, the U.S. Department of Justice indicted five Chinese nationals on charges of hacking U.S. companies to obtain trade secrets. It was the first time the U.S. had formally indicted state-sponsored hackers.

The Chinese government denied the claims and called them "fabricated," and in a subsequent report the government said it was a victim of U.S. cyberattacks.

That response was part of the motivation for CrowdStrike's new report, Kurtz said.

"We see a lot on the ground, where we see first hand the intellectual property theft taking place," he said. "We really wanted to put this story out there to say it isn't a one-off in terms of the U.S. government's indictments. It's a sustained, coordinated and systematic campaign against companies around the globe."

Martyn Williams covers mobile telecoms, Silicon Valley and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn's e-mail address is martyn_williams@idg.com


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securityspywareintrusionCrowdStrike

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments