News / Asia

US-China Cyber Spying Case Turns Spotlight on Shadowy Unit 61398

Part of the building of 'Unit 61398', a secretive Chinese military unit, is seen in the outskirts of Shanghai, Feb. 19, 2013.
Part of the building of 'Unit 61398', a secretive Chinese military unit, is seen in the outskirts of Shanghai, Feb. 19, 2013.
Reuters
— A tense stand-off between the United States and China over state-backed cyber espionage has dragged China's secretive hacking unit “61398” back into focus, after the military group was pinpointed last year for mounting cyber attacks on Western commercial targets.
 
U.S. authorities on Monday charged five Chinese military officers at the unit, accusing them of hacking into American nuclear, metal and solar firms to steal trade secrets. China on Tuesday summoned the U.S. ambassador in Beijing and warned it would retaliate if Washington followed through with the charges. It said the affair would damage “mutual trust.”
 
At the center of the argument is a nondescript tower block in the northern suburbs of China's financial capital Shanghai, home to Chinese People's Liberation Army (PLA) Unit 61398.
 
The 12-story block houses as many as several thousand staff, according to Mandiant, a U.S. cyber security firm recently acquired by global network security company FireEye Inc. Mandiant identified the location as the source of a large number of espionage operations in a 70-page report last year.
 
“This unit is one of the most prolific. The group is really active and very aggressive,” said Pierluigi Paganini, a cyber security expert and founder of Security Affairs, based in Italy.
 
Unit 61398's Shanghai base is kitted out with specialist fiber optic lines, while staff are trained in areas from English linguistics to covert communications, network security and cyber attack strategy, according to the Mandiant report.
 
The unit's operatives, working under code names such as “UglyGorilla”, “DOTA” and “SuperHard”, also have close research and recruitment ties with China's leading academic centers such as the prestigious Shanghai Jiaotong University.
 
Publicly available academic reports, school registers, recruitment notices and local online community notice boards show a web of social, educational and academic networks spreading out from the cyber spying unit. Military units in China are often organized in this way with schools, sports clubs and social events organized communally for unit members.
 
Tip of the iceberg

 
However, unit 61398 - more formally known as General Staff Department (GSD), Third Department, Second Bureau - is just one of dozens of similar groups based in China, and far from the foremost, said Mandiant analyst Jen Weedon.
 
“The unit is one of many and its tradecraft is not that great. They are one of the ones that doesn't seem to mind leaving traces behind,” she told Reuters.
 
The unit, which started operating in or before 2006, saw activity drop sharply in the wake of the 2013 Mandiant report, but has since returned to “business as usual” after it overhauled some of its hacking techniques, Weedon added.
 
The new allegations are that Chinese state-owned firms “hired” the unit, which used a range of cyber attack methods to illegally gather corporate information from mostly U.S. firms and help give Chinese companies a competitive edge.
 
The unit “stole sensitive, internal communications”, using tactics such as “spear phishing” emails to gain access to employees' computers, after which it was able to collect internal data, according to the indictment document, posted on the United States Department of Justice website.
 
Federal prosecutors said the suspects targeted companies including Alcoa Inc, Allegheny Technologies Inc., United States Steel Corp, Toshiba Corp unit Westinghouse Electric Co, the U.S. subsidiaries of SolarWorld AG , and a steel workers' union.
 
Unit 61398 - or at least one very much like it - also stole data from at least one U.S. government agency in a hacking campaign named 'Byzantine Candor', according to diplomatic cables released by Wikileaks.
 
“Hackers based in Shanghai and linked to the PRC's People's Liberation Army [PLA] Third Department” stole data from at least one U.S. government agency, according to a leaked 2008 cable.
 
Officials in Washington have argued for years that cyber espionage is a top national security concern, and the battle is heating up. Both sides have ramped up public and private confrontation, including at a summit last year between U.S. President Barack Obama and Chinese President Xi Jinping.
 
China has denied the unit is involved in cyber espionage, and insists the country is more a victim than a perpetrator of cyber attacks.
 
Paganini said he was not surprised at the latest turn of events, which he described as just the “tip of the iceberg”.
 
“I believe there's an ongoing battle in the cyberspace. These countries are investing large amounts in cyber units that are able to create specific malware and have the ability to get into foreign networks and computers to steal trade secrets and intellectual properties,” he said.

You May Like

China Investigates Former Powerful Security Chief

Former security chief and member of Politburo Standing Committee, Zhou Yongkang, under investigation for suspected 'serious disciplinary violation' More

India, US Look to Reset Ties During Kerry Visit

This week's talks will be first high level interaction between two countries since Prime Minister Narendra Modi took charge More

Video Young African Leadership Program Renamed to Honor Mandela

YALI program, launched by President Obama in 2010, aims to build skills in business, entrepreneurship, public management and civic leadership More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Vietnamese Staging Chinese Product Boycott After Oil Rig Spati
X
Reasey Poch
July 28, 2014 7:18 PM
China recently pulled an oil rig from an area of the disputed South China Sea that Vietnam also claims. Despite the action, the incident has had a lingering effect on consumers in Vietnam. VOA's Reasey Poch reports from Hanoi on an effort to boycott Chinese products.
Video

Video Vietnamese Staging Chinese Product Boycott After Oil Rig Spat

China recently pulled an oil rig from an area of the disputed South China Sea that Vietnam also claims. Despite the action, the incident has had a lingering effect on consumers in Vietnam. VOA's Reasey Poch reports from Hanoi on an effort to boycott Chinese products.
Video

Video ESA Spacecraft to Land on a Comet

After a long flight through deep space, a European Space Agency probe is finally approaching its target -- a comet millions of kilometers away from earth. Scientists say the mission may lead to some startling discoveries about the origins of the water on earth. VOA’s George Putic has more.
Video

Video Young Africans Arrive in US for Leadership Program

President Barack Obama's Young African Leadership Initiative has brought hundreds of young Africans to the United States for a six-week program aimed at building their knowledge and skills in fields such as public administration and business. Out of the 50,000 young Africans who applied for the program, just one percent was accepted. VOA's Laurel Bowman caught up with some of those who made the cut and has this report.
Video

Video In Honduras, Amnesty Rumors Fuel US Migration Surges

False rumors in Central America are fueling the current surge of undocumented young people being apprehended at the U.S. border. The inaccurate claims suggest the U.S. will give amnesty to young migrants from the region. As VOA's Brian Padden reports from Honduras, these rumors trace back to President Obama's 2012 executive order to halt deportations for some young undocumented immigrants already living in the United States.
Video

Video Students in Business for Themselves

They're only high school students, but they are making accessories for shoes, fabricating backpacks and doing product photography - all through their own businesses. It's the result of a partnership between a non-profit organization that teaches entrepreneurship and their schools. VOA's Mike O'Sullivan and Deyane Moses met the budding entrepreneurs near Los Angeles.
Video

Video Astronauts Train in Underwater Lab

In the world’s only underwater laboratory, four U.S. astronauts train for a planned visit to an asteroid. The lab - called Aquarius- is located five kilometers off Key Largo, in southern Florida. Living in close quarters and making excursions only into the surrounding ocean, they try to simulate the daily routine of a crew that will someday travel to collect samples of a rock orbiting far away from earth. VOA’s George Putic has more.

AppleAndroid