Unit 61398: Chinese cyberspies
The Associated Press
Posted: Feb 20, 2013 8:37 AM ET
Last Updated: Feb 20, 2013 8:36 AM ET
Part of the building of Unit 61398, a secretive Chinese military unit, is seen in the outskirts of Shanghai. (Reuters)
Related
Related Stories
Unit 61398 of the People's Liberation Army has been recruiting computer experts for at least a decade. It has made no secret of details of community life such as badminton matches and kindergarten, but its apparent purpose became clear only when a U.S. internet security firm accused it of conducting a massive hacking campaign against North American targets.
Hackers with the Chinese unit have been active for years, using online handles such as "UglyGorilla," Virginia-based firm Mandiant said in a report released Tuesday as the U.S. prepared to crack down on countries responsible for cyberespionage. The Mandiant report plus details collected by The Associated Press depict a highly specialized community of internet warriors working from a blocky white building in Shanghai:
Recruiting the spies: Unit 61398, alleged to be one of several hacking operations run by China's military, recruits directly from universities. It favours high computer expertise and English language skills. A notice dated 2003 on the Chinese internet said the unit was seeking master's degree students from Zhejiang University's College of Computer Science and Technology. It offered a scholarship, conditional on the student reporting for work at Unit 61398 after graduation.
Cyberspy workplace: Mandiant says it traced scores of cyberattacks on U.S. defence and infrastructure companies to a neighbourhood in Shanghai's Pudong district that includes the 12-story building where Unit 61398 is known to be housed. The building has office space for up to 2,000 people. Mandiant estimates the number of personnel in the unit to be anywhere from hundreds to several thousand. The surrounding neighbourhood is filled with apartment buildings, tea houses, shops and karaoke bars.
The Unit 61398 community: While the building's activities may be top secret, Unit 61398's status in the community as a military division is not. It turns up in numerous Chinese internet references to community events, including a 2010 accord with the local government to set up a joint outreach centre on family planning. Other articles describe mass weddings for officers, badminton matches and even discussion of the merits of the "Unit 61398 Kindergarten." Other support facilities include a clinic, car pool, and guesthouse — all standard for the military's often self-contained communities across China.
The pipeline: The Mandiant report describes a special arrangement made with China Telecom for a fibre optic communication infrastructure in the Unit 61398 neighbourhood, pointing to its need for bandwidth and its elite status. The contract between the two refers to Unit 61398 as belonging to the General Staff Department 3rd Department, 2nd Bureau, and says China Telecom agreed to the military's suggested price due to "national defence construction" concerns.
Modus Operandus: The cyberspies typically enter targeted computer networks through "spearfishing" attacks, in which a company official receives a creatively disguised email and is tricked into clicking on a link or attachment that then opens a secret door for the hackers, Mandiant says. The cyberspies would steal and retransmit data for an average of just under a year, but in some cases more than four years. Information technology companies were their favourite targets, followed by aerospace firms, pointing to a key area of interest as China seeks to develop its own cutting-edge civilian and military aircraft.
Online handles: Mandiant identifies three of the unit's hackers by their screen names. It says one of them, "UglyGorilla," was first detected in a 2004 online forum posing a question to a cybersecurity expert about whether China needed a dedicated force to square off against an online cohort being mustered by the United States. The user of another screen name, "Dota," appears to be a fan of Harry Potter; Mandiant said references to the book and movie character appear as answers to his computer security questions.
Unit 61398 hackers were sometimes identified as the "Comment Crew" by security companies due to their practice of inserting secret backdoors into systems by using code embedded in comments on websites.
Revealing tweets: And what helped Mandiant track down the source of hacking into more than 140 companies and organizations from the U.S. and elsewhere? Facebook and Twitter.
China's "Great Firewall" of internet filtering blocks those U.S.-based social networks, but Unit 61398 operators got around that by accessing them directly from the unit's system. Mandiant was able to see that Facebook and Twitter accounts were being accessed from internet protocol addresses connected to the unit. It's not clear whether those accounts aided in hacking or were simply for the hackers' personal use.
"These actors have made poor operational security choices, facilitating our research and allowing us to track their activities," the report says.
Share Tools
Top News Headlines
- Search for Oklahoma tornado survivors nearly complete
- Rescue workers raced to complete the search for survivors and the dead in the Oklahoma City suburb where a mammoth tornado destroyed countless homes, cleared lots down to bare red earth and claimed 24 lives, including those of nine children.
more »
- Video forensics: How easy would it be to fake a Rob Ford video?
- A Toronto newspaper reported last week that it has seen a cellphone video of Mayor Rob Ford allegedly smoking crack, a claim that has gone global. If a video does surface, how easy would it be to determine its authenticity? CBC News asked video forensic analyst David McKay. more »
- Senate sends Duffy expense audit for 2nd internal review
- The Senate decided to send Senator Mike Duffy's audit report back to its internal committee for a second review, despite objections from the Liberal Senate leader, who argued the RCMP should be tasked with the job. more »
- How the weather info that storm chasers use can keep you safe
- Radar imagery and a stream of weather information are readily available to the public when severe weather bears down. more »
- What is 'Tornado Alley'?
- A tornado that generated winds as strong as 320 km/h and killed more than 20 people in Moore, Okla., on Monday fell in a geographical area of the U.S. generally known as 'Tornado Alley.' Here's a closer look at this storm-plagued region — and its counterparts in Canada. more »
Must Watch
Latest World News Headlines
- Jodi Arias gives jailhouse interviews as jury mulls execution
- In a surprise jailhouse interview just hours after a jury began deliberating her fate, Jodi Arias spoke out Tuesday about her murder trial, her many fights with her legal team and her belief that she 'deserves a second chance at freedom someday.' more »
- How the weather info that storm chasers use can keep you safe
- Radar imagery and a stream of weather information are readily available to the public when severe weather bears down. more »
- Search for Oklahoma tornado survivors nearly complete
- Rescue workers raced to complete the search for survivors and the dead in the Oklahoma City suburb where a mammoth tornado destroyed countless homes, cleared lots down to bare red earth and claimed 24 lives, including those of nine children. more »
- Guatemala overturns ex-dictator's 'historic' genocide conviction
- Guatemala's top court has overturned a conviction against former dictator Efrain Rios Montt, which just days ago was being hailed as a milestone decision. Earlier this month, the court made history by finding Rios Montt guilty of genocide and crimes against humanity. more »
- What is 'Tornado Alley'?
- A tornado that generated winds as strong as 320 km/h and killed more than 20 people in Moore, Okla., on Monday fell in a geographical area of the U.S. generally known as 'Tornado Alley.' Here's a closer look at this storm-plagued region — and its counterparts in Canada. more »
The National
The Current
- The morning after the Oklahoma tornado May. 21, 2013 4:17 PM The rescue efforts and aftermath of yesterday's devastating tornado in Moore, Oklahoma.
- Microsoft unveils Xbox One
- Deadly Oklahoma tornado confirmed as most powerful type
- Only 1 set of human remains found at Millard farm, police say
- Rob Ford faces more calls to address crack allegations
- Cloverdale Rodeo 'racist attack' investigated
- Kids from levelled Oklahoma schools recount deadly tornado
- One dead as floatplane overturns in Bute Inlet
- Yukon couple hold record for longest marriage in country
- Aboriginal woman settles lawsuit over 3½ years solitary confinement

