News / Asia

China's Cyber Espionage Case a Guide to Hacking

Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
Part of the building of 'Unit 61398', a secretive Chinese military unit accused of cyber espionage in Shanghai
The alleged hacking of U.S. corporate computers by elements of China’s military wasn’t in and of itself all that unique.
As cyber attacks go, it was moderately sophisticated in technique.
But that raises a more troubling question.
How could major international corporations — such as U.S. Steel, Alcoa and others with millions of dollars of intellectual property — get robbed by a small, low-cost group of hackers working from China?
The answer: It’s surprising it doesn’t happen more often.
Over its 48 pages and 31 counts of criminal misconduct, the U.S. Justice Department’s indictment details how five Chinese army officers, with Internet identities such as “Ugly Gorilla”, “Kandygoo” and “WinXYHappy,” went about infiltrating computer networks of six large U.S. corporations.
Sections of the indictment are so detailed that they read like a primer, a virtual "how-to manual" for anyone interested in how hackers do what they do.
Social engineering
While some of the terms such as “spearphishing,” “beacon” or “hop-points” may need a little technical explaining, it’s clear from the indictment that the defendants generally employed something security analysts call social engineering.
In essence, social engineering is a tactic where hackers pretend to be somebody else to try and trick the target into trusting them.
The aim is getting them to reveal information directly (such as a password) or infect their computers by clicking on malicious links and attachments. Social engineering, in the end, is just a fancy label for little more than a con job.
There are many different tricks a hacker might employ to earn their target’s trust.

But once they have it, it’s relatively easy to fool unsuspecting targets into releasing sensitive information.
A common example: if someone you believe is a trusted co-worker sends you an email urgently asking for a password they’ve forgotten, you’re probably much more likely to send it to them without thinking twice than someone you don’t know, analysts say.
“Given that these types of attacks can be attempted with very little consequence if they don't succeed,” said Mike Auty, senior security researcher at the firm MWR Infosecurity,

“It allows the attacker to launch a number of attacks, over a long period of time, and the chances are high that there will be a mistake, and someone will grant them access,” he said.
Which, as the indictment details, is  what the Chinese are alleged to have done.
One particular social engineering trick allegedly used by the defendants was “spearphishing” — sending links or attachments via email that, if clicked, would infect the target’s computer system without them knowing.
Once infected, the malware would create what’s called a “back door” or secret entrance into the system that could likely go undetected for prolonged periods.
In the recent indictment papers, U.S. prosecutors say that, defendant “SUN” — short for Sun Kailiang — “sent spearphishing e-mails purporting to be from two U.S. Steel e-mail accounts to approximately eight U.S. Steel employees, including U.S. Steel’s Chief Executive Officer.
“The e-mails had the subject line “US Steel Industry Outlook” and contained a link to malware that, once clicked, would surreptitiously install malware on the recipients’ computers, allowing the co-conspirators backdoor access to the company’s computers,” the indictment said.

“ unidentified co-conspirator sent approximately 49 spearphishing e-mails to U.S. Steel employees with the same subject, “US Steel Industry Outlook,” according to the indictment.
But it didn’t stop with basic spearphishing.
Researcher Auty said successful social engineering hacks often require more than just bad emails.
And the indictment lays out another, more sophisticated attack strategy that required much greater planning, research and patience.
Persistence over technology
Throughout the document, the Justice Department describes how the defendants would first try to gain lists of current and former employees at each of the six targeted companies and then went about researching who they were.
The defendants then went about purchasing a variety of web site domain names, such as ‘’ or ‘’ (readers are advised NOT to visit these sites) and populating them both with content that appeared legitimate, but also contained hidden Trojan-horse malware.
These websites both served to create an appearance of trust and also to serve as “hop-points” between the infected computers and the main attack servers in China to coordinate and control all the malware-infected computers in the U.S.
In the indictment, attorneys detail how these hop-points could surreptitiously allow the hackers to grab documents and “exfiltrate” — a computer term that basically means stealing — the data back to China.
As the indictment put it: “Between intrusions, the co-conspirators used the domain accounts to reassign the malicious domain names to non-routable or innocuous IP addresses, (e.g., IP addresses for popular webmail services, like Gmail or Yahoo), which would obscure any beacons their malware sent during that period.”
“Bad guys want my stuff”
Technologically speaking, it wasn’t anywhere near the sophistication of something like the Stuxnet virus.

But for sheer persistence and imagination, it was quite a clever operation.
“People need to realize: the bad guys are persistent, they’re organized,” said Stephen Cobb, a senior security researcher at the cyber security firm ESET North America. “Maybe this would help: it’s not an individual who’s trying to break into your web server every five seconds.”
“Let’s face it: every company today has information on their computers that they need to protect,” Cobb said. “If you’ve got a website, there’s an attempt to break into it every five, six seconds. It’s automated programs.

"So people from all around the world who want to get into somebody else’s computer are running automated script looking for holes," he said. "There’s a constant probing of systems.”
Still, it’s hard for most people to understand cyber security, analysts say.
“If you work for a bank, you should be fairly aware that people might want to rob you, that’s where the money is,” Cobb said. “But if you’re a doctor, or an engineer designing a product, you’re not necessarily thinking ‘there are bad guys who want my stuff.’‘”
But security expert Auty said that’s not a cause to lose hope.
“People will always be a weak element, but given that organizations have learnt to harden their perimeter, the next area of improvement required within the industry is ensuring internal visibility and appropriate segregation,” he said.
For both Auty and Cobb, the segregation of data into specific areas with different levels of security is key.
“You can’t protect what you don’t know about,” Cobb told VOA. “One of the very first things on my list for remediation or security programs for small business or big business is know what you’ve got.”

Doug Bernard

Doug Bernard covers cyber-issues for VOA, focusing on Internet privacy, security and censorship circumvention. Previously he edited VOA’s “Digital Frontiers” blog, produced the “Daily Download” webcast and hosted “Talk to America”, for which he won the International Presenter of the Year award from the Association for International Broadcasting. He began his career at Michigan Public Radio, and has contributed to "The New York Times," the "Christian Science Monitor," SPIN and NPR, among others. You can follow him @dfrontiers.

You May Like

Video Americans, Tourists, Reflect on Meaning of Thanksgiving

VOA garnered opinions from several people soon after November 13 Paris attacks, which colored many of their thoughts

Video Thais Send Security Concerns Down the River

In northern Thailand, the annual tradition of constructing floating baskets to carry away the year’s bad spirits highlights the Loy Krathong festival

Video Tree Houses - A Branch of American Dream

Workshops aimed at teaching people how to build tree houses have become widely popular in America in recent years

This forum has been closed.
Comment Sorting
by: TheSaucyMugwump from:
May 25, 2014 6:23 PM
Corporations are being hacked by both Chinese and Russians, with the former doing it for corporate espionage and the latter doing it for personal loot. Corporations today are only concerned with reducing costs and maximizing the salaries of CEOs and other corporate officers. Target and eBay outsourced a large part of their IT function and got burned.

There is a preventative measure for phishing: before clicking on links in emails, hover the mouse over the link (but don't click on it) and read the URL in the bottom-left corner of the screen. If the URL is not what you expect, report the email as spam. It is amazing how few articles mention this simple trick.

by: Anonymot from: Boston
May 25, 2014 11:13 AM
Wow! Sic 'em. They're doing what NSA & CIA are doing and we are supposed to have a global monopoly on hacking for governmental usage, both commercial for American corporate use as well "intelligence".

It makes no sense to allow these dangerous , skilled competitors wander freely around our electronic fairs. Perhaps we should bar ALL Chinese from entering and expel those who are here who may know too much - and Japanese, too (& Indians, Pakistanis, etc.) We don't really need any other smart people in the world. We suffice.

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Islamic State Unfazed by Losses in Iraq, Syriai
November 26, 2015 5:21 AM
Progress in the U.S.-led effort to beat Islamic State on its home turf in Iraq and Syria has led some to speculate the terror group may be growing desperate. But counterterror officials say that is not the case, and warn the recent spate of terror attacks is merely part of the group’s evolution. VOA National Security correspondent Jeff Seldin has more.

Video Islamic State Unfazed by Losses in Iraq, Syria

Progress in the U.S.-led effort to beat Islamic State on its home turf in Iraq and Syria has led some to speculate the terror group may be growing desperate. But counterterror officials say that is not the case, and warn the recent spate of terror attacks is merely part of the group’s evolution. VOA National Security correspondent Jeff Seldin has more.

Video Taiwan Looks for Role in South China Sea Dispute

The Taiwanese government is one of several that claims territory in the hotly contested South China Sea, but Taipei has long been sidelined in the dispute, overshadowed by China. Now, as the Philippines challenges Beijing’s claims in an international court at The Hague, Taipei is looking to publicly assert its claims. VOA’s Bill Ide has more from Beijing.

Video Syrian Refugees in US Express Concern for Those Left Behind

Syrian immigrants in the United States are concerned about the negative tide of public opinion and the politicians who want to block a U.S. plan to accept 10,000 Syrian refugees. Zlatica Hoke reports many Americans are fighting to dispel suspicions linking refugees to terrorists.

Video After Paris Attacks, France Steps Up Fight Against IS

The November 13 Paris attacks have drawn increased attention to Syria, where many of the suspected perpetrators are said to have received training. French President Francois Hollande is working to build a broad international coalition to defeat Islamic State in Syria and in Iraq. Zlatica Hoke reports.

Video US, Cambodian Navies Pair Up in Gulf of Thailand

The U.S. Navy has deployed one of its newest and most advanced ships to Cambodia to conduct joint training drills in the Gulf of Thailand. Riding hull-to-hull with Cambodian ships, the seamen of the USS Fort Worth are executing joint-training drills that will help build relations in Southeast Asia. David Boyle reports for VOA from Preah Sihanouk province.

Video Americans Sharpen Focus on Terrorism

Washington will be quieter than usual this week due to the Thanksgiving holiday, even as Americans across the nation register heightened concerns over possible terrorist threats. VOA’s Michael Bowman reports new polling data from ABC News and the Washington Post newspaper show an electorate increasingly focused on security issues after the deadly Islamic State attacks in Paris.

Video World Leaders Head to Paris for Climate Deal

Heads of state from nearly 80 countries are heading to Paris (November 30-December 11) to craft a global climate change agreement. The new accord will replace the Kyoto Protocol on Climate Change that expired in 2012.

Video Uncertain Future for Syrian Refugee Resettlement in Illinois

For the trickle of Syrian refugees finding new homes in the Midwest city of Chicago, the call to end resettlement in many U.S. states is adding another dimension to their long journey fleeing war. Organizations working to help them integrate say the backlash since the Paris attacks is both harming and helping their efforts to provide refugees sanctuary. VOA's Kane Farabaugh reports.

Video Creating Physical Virtual Reality With Tiny Drones

As many computer gamers know, virtual reality is a three-dimensional picture, projected inside special googles. It can fool your brain into thinking the computer world is the real world. But If you try to touch it, it’s not there. Now Canadian researchers say it may be possible to create a physical virtual reality using tiny drones. VOA’s George Putic reports.

Video New American Indian Village Takes Visitors Back in Time

There is precious little opportunity to experience what life was like in the United States before its colonization by European settlers. Now, an American Indian village built in a park outside Washington is taking visitors back in time to experience the way of life of America's indigenous people. Carol Pearson narrates this report from VOA's June Soh.

Video Even With Hometown Liberated, Yazidi Refugees Fear Return

While the northern Iraqi town of Sinjar has been liberated from Islamic State forces, it's not clear whether Yazidi residents who fled the militants will now return home. VOA’s Mahmut Bozarslan talked with Yazidis, a religious and ethnic minority, at a Turkish refugee camp in Diyarbakır. Robert Raffaele narrates his report.

Video Nairobi Tailors Make Pope Francis’ Vestments

To ensure the pope is properly attired during his visit, the Kenya Conference of Catholic Bishops asked the Dolly Craft Sewing Project in the Nairobi slum of Kangemi to make the pope's vestments, the garments he will wear during the various ceremonies. Jill Craig reports.

Video Cross-Border Terrorism Puts Europe’s Passport-Free Travel in Doubt

The fallout from the Islamic State terror attacks in Paris has put the future of Europe’s passport-free travel area, known as the "Schengen Zone," in doubt. Several of the perpetrators were known to intelligence agencies, but were not intercepted. Henry Ridgwell reports from London European ministers are to hold an emergency meeting Friday in Brussels to look at ways of improving security.

Video El Niño Brings Unexpected Fish From Mexico to California

Fish in an unexpected spectrum of sizes, shapes and colors are moving north, through El Niño's warm currents from Mexican waters to the Pacific Ocean off California’s coast. El Nino is the periodic warming of the eastern and central Pacific Ocean. As Faiza Elmasry tells us, this phenomenon thrills scientists and gives anglers the chance of a once-in-a-lifetime big catch. Faith Lapidus narrates.

Video Terrorism in Many Forms Continues to Plague Africa

While the world's attention is on Paris in the wake of Friday night's deadly attacks, terrorism from various sides remains a looming threat in many African countries. Nigerian cities have been targeted this week by attacks many believe were staged by the violent Islamist group Boko Haram. In addition, residents in many regions are forced to flee their homes as they are terrorized by armed militias. Zlatica Hoke reports.

Video Study: Underage Marriage Rate Higher for Females in Pakistan

While attitudes about the societal role of females in Pakistan are evolving, research by child advocacy group Plan International suggests that underage marriage of girls remains a particularly big issue in the country. VOA’s Ayesha Tanzeem reports how such marriages leads to further social problems.

VOA Blogs