News / Asia

US-China Cyber Spying Case Turns Spotlight on Shadowy Unit 61398

Part of the building of 'Unit 61398', a secretive Chinese military unit, is seen in the outskirts of Shanghai, Feb. 19, 2013.
Part of the building of 'Unit 61398', a secretive Chinese military unit, is seen in the outskirts of Shanghai, Feb. 19, 2013.
Reuters
— A tense stand-off between the United States and China over state-backed cyber espionage has dragged China's secretive hacking unit “61398” back into focus, after the military group was pinpointed last year for mounting cyber attacks on Western commercial targets.
 
U.S. authorities on Monday charged five Chinese military officers at the unit, accusing them of hacking into American nuclear, metal and solar firms to steal trade secrets. China on Tuesday summoned the U.S. ambassador in Beijing and warned it would retaliate if Washington followed through with the charges. It said the affair would damage “mutual trust.”
 
At the center of the argument is a nondescript tower block in the northern suburbs of China's financial capital Shanghai, home to Chinese People's Liberation Army (PLA) Unit 61398.
 
The 12-story block houses as many as several thousand staff, according to Mandiant, a U.S. cyber security firm recently acquired by global network security company FireEye Inc. Mandiant identified the location as the source of a large number of espionage operations in a 70-page report last year.
 
“This unit is one of the most prolific. The group is really active and very aggressive,” said Pierluigi Paganini, a cyber security expert and founder of Security Affairs, based in Italy.
 
Unit 61398's Shanghai base is kitted out with specialist fiber optic lines, while staff are trained in areas from English linguistics to covert communications, network security and cyber attack strategy, according to the Mandiant report.
 
The unit's operatives, working under code names such as “UglyGorilla”, “DOTA” and “SuperHard”, also have close research and recruitment ties with China's leading academic centers such as the prestigious Shanghai Jiaotong University.
 
Publicly available academic reports, school registers, recruitment notices and local online community notice boards show a web of social, educational and academic networks spreading out from the cyber spying unit. Military units in China are often organized in this way with schools, sports clubs and social events organized communally for unit members.
 
Tip of the iceberg

 
However, unit 61398 - more formally known as General Staff Department (GSD), Third Department, Second Bureau - is just one of dozens of similar groups based in China, and far from the foremost, said Mandiant analyst Jen Weedon.
 
“The unit is one of many and its tradecraft is not that great. They are one of the ones that doesn't seem to mind leaving traces behind,” she told Reuters.
 
The unit, which started operating in or before 2006, saw activity drop sharply in the wake of the 2013 Mandiant report, but has since returned to “business as usual” after it overhauled some of its hacking techniques, Weedon added.
 
The new allegations are that Chinese state-owned firms “hired” the unit, which used a range of cyber attack methods to illegally gather corporate information from mostly U.S. firms and help give Chinese companies a competitive edge.
 
The unit “stole sensitive, internal communications”, using tactics such as “spear phishing” emails to gain access to employees' computers, after which it was able to collect internal data, according to the indictment document, posted on the United States Department of Justice website.
 
Federal prosecutors said the suspects targeted companies including Alcoa Inc, Allegheny Technologies Inc., United States Steel Corp, Toshiba Corp unit Westinghouse Electric Co, the U.S. subsidiaries of SolarWorld AG , and a steel workers' union.
 
Unit 61398 - or at least one very much like it - also stole data from at least one U.S. government agency in a hacking campaign named 'Byzantine Candor', according to diplomatic cables released by Wikileaks.
 
“Hackers based in Shanghai and linked to the PRC's People's Liberation Army [PLA] Third Department” stole data from at least one U.S. government agency, according to a leaked 2008 cable.
 
Officials in Washington have argued for years that cyber espionage is a top national security concern, and the battle is heating up. Both sides have ramped up public and private confrontation, including at a summit last year between U.S. President Barack Obama and Chinese President Xi Jinping.
 
China has denied the unit is involved in cyber espionage, and insists the country is more a victim than a perpetrator of cyber attacks.
 
Paganini said he was not surprised at the latest turn of events, which he described as just the “tip of the iceberg”.
 
“I believe there's an ongoing battle in the cyberspace. These countries are investing large amounts in cyber units that are able to create specific malware and have the ability to get into foreign networks and computers to steal trade secrets and intellectual properties,” he said.

You May Like

Mali's Female Basketball Players Rebound After Islamist Occupation

Islamist extremists ruled northern Mali for most of 2012, imposing strict Sharia law, and now some 18 months later, the region is slowly getting back on its feet More

Video Vietnamese Staging Chinese Product Boycott After Oil Rig Spat

Many Chinese-made products go unsold, for now, with numerous Vietnamese consumers still angry over recent dispute More

Koreas Mark 61st Anniversary of War Armistice

Muted observances on both sides of heavily-armed Demilitarized Zone that separates two decades-long enemies More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Students in Business for Themselvesi
X
Mike O'Sullivan
July 26, 2014 11:04 AM
They're only high school students, but they are making accessories for shoes, fabricating backpacks and doing product photography - all through their own businesses. It's the result of a partnership between a non-profit organization that teaches entrepreneurship and their schools. VOA's Mike O'Sullivan and Deyane Moses met the budding entrepreneurs near Los Angeles.
Video

Video Students in Business for Themselves

They're only high school students, but they are making accessories for shoes, fabricating backpacks and doing product photography - all through their own businesses. It's the result of a partnership between a non-profit organization that teaches entrepreneurship and their schools. VOA's Mike O'Sullivan and Deyane Moses met the budding entrepreneurs near Los Angeles.
Video

Video Astronauts Train in Underwater Lab

In the world’s only underwater laboratory, four U.S. astronauts train for a planned visit to an asteroid. The lab - called Aquarius- is located five kilometers off Key Largo, in southern Florida. Living in close quarters and making excursions only into the surrounding ocean, they try to simulate the daily routine of a crew that will someday travel to collect samples of a rock orbiting far away from earth. VOA’s George Putic has more.
Video

Video Not Even Monks Spared From Thailand’s Junta-Backed Morality Push

With Thailand’s military government firmly in control after May’s bloodless coup, authorities are carrying out plans they say are aimed at restoring discipline, morality and patriotism to all Thais. The measures include a crackdown on illegal gambling, education reforms to promote students’ moral development, and a new 24-hour phone hotline for citizens to report misbehaving monks. Steve Sandford reports from Bangkok.
Video

Video Virtual Program Teaches Farming Skills

In a fast-changing world beset by unpredictable climate conditions, farmers cannot afford to ignore new technology. Researchers in Australia are developing an online virtual world program to share information about climate change and more sustainable farming techniques for sugar cane growers. As VOA's Zlatica Hoke reports, the idea is to create a wider support network for farmers.
Video

Video Airline Expert: Missile will Show Signature on Debris

The debris field from Malaysia Airlines Flight 17 is spread over a 21-kilometer radius in eastern Ukraine. It is expected to take investigators months to sort through the airplane pieces to learn about the missile that brought down the jetliner and who fired it. VOAs Carolyn Presutti explains how this work will be done.
Video

Video Treatment for Childhood Epilepsy Heats up Medical Marijuana Debate

In the United States, marijuana is classed as an illegal drug by the federal government. But nearly half the states have legalized it, to some degree. Proponents say some strains of marijuana might have exceptional health benefits, for treating pain or inflammation in chronic conditions such as cancer, multiple sclerosis and epilepsy. Shelley Schlender reports on a strain of medical marijuana developed in Colorado that is reputed to reduce seizures in childhood epilepsy
Video

Video Airbus Adds Metal 3D Printed Parts to New Jets

By the end of this year, European aircraft manufacturing consortium Airbus plans to deliver the first of its new, extra-wide-body passenger jets, the A350-XWB. Among other technological innovations, the new plane will also incorporate metal parts made in a 3-D printer. VOA's George Putic has more.
Video

Video AIDS Conference Welcomes Exciting Developments in HIV Treatment, Prevention

Significant strides have been made in recent years toward the treatment and prevention of HIV, the virus that causes AIDS. This year, at the International AIDS Conference, the AIDS community welcomed progress on a new pill that may prevent transmission of the deadly virus. VOA’s Anita Powell reports from Melbourne, Australia.
Video

Video IAEA: Iran Turns its Enriched Uranium Into Less Harmful Form

Iran has converted its stockpiles of enriched uranium into a less dangerous form that is more difficult to use for nuclear weapons, according to the United Nations’ Atomic Energy Agency. The move complies with an interim deal reached with Western powers on Iran's nuclear program last year, in exchange for easing of sanctions. Henry Ridgwell reports for VOA from London.

AppleAndroid