No menu items!

COSTA RICA'S LEADING ENGLISH LANGUAGE NEWSPAPER

HomeChinaResearchers identify sophisticated Chinese cyberespionage group

Researchers identify sophisticated Chinese cyberespionage group

WASHINGTON, D. C. — A coalition of security researchers has identified a Chinese cyberespionage group that appears to be the most sophisticated of any publicly known Chinese hacker unit and targets not only U.S. and Western government agencies but dissidents inside and outside China.

News of the state-sponsored hacker group dubbed Axiom comes a week before U.S. Secretary of State John Kerry and two weeks before U.S. President Barack Obama are due to arrive in Beijing for a series of high-level talks, including on the issue of cybersecurity.

In a report to be issued Tuesday, the researchers said Axiom is going after intelligence benefiting Chinese domestic and international policies — an across-the-waterfront approach that combines commercial cyberespionage, foreign intelligence and counterintelligence with the monitoring of dissidents.

Axiom’s work, the FBI said in an industry alert this month, is more sophisticated than that of Unit 61398, a People’s Liberation Army hacker unit that was highlighted in a report last year. Five of the unit’s members were indicted earlier this year by a U.S. grand jury. The researchers concur with the FBI’s conclusion, noting that, unlike Unit 61398, Axiom is focused on spying on dissidents as well as on industrial espionage and theft of intellectual property.

“Axiom’s activities appear to be supported by a nation state to steal trade secrets and to target dissidents, pro-democracy organizations and governments,” said Peter LaMontagne, chief executive of Novetta Solutions, a Northern Virginia cybersecurity firm that heads the coalition. “These are the most sophisticated cyberespionage tactics we’ve seen out of China.”

Chinese Embassy spokesman Geng Shuang said in an email that “judging from past experience, these kinds of reports or allegations are usually fictitious.” He repeated Beijing’s position that Chinese law prohibits cybercrime and that the government “has done whatever it can to combat such activities.”

Senior Obama administration officials have over the past year and a half publicly called on China to halt its practice of stealing U.S. commercial secrets to benefit its own industries. China, especially in the wake of disclosures last year of widespread U.S. government surveillance by former National Security Agency contractor Edward Snowden, has pushed back, arguing that it is the United States that needs reining in.

Geng said in his email: “China is a victim of these kinds of attacks, according to the Snowden revelations.” Following the PLA indictments in May, Beijing pulled out of bilateral talks aimed at easing tensions in cyberspace.

In recent weeks, the research consortium has detected Axiom malicious software on at least 43,000 computers around the world belonging to law enforcement and other government agencies, journalists, telecommunication and energy firms, as well as human rights and pro-democracy groups.

The group said there also are indications that Axiom may be behind a high-profile cyberattack on Google, announced in 2010, which compromised the tech giant’s source code and targeted Chinese dissidents using Gmail.

At least one Chinese language computer in the United States was targeted, the report said, without specifying to whom the computer belonged.

Novetta senior technical director Andre Ludwig also said Axiom is seeking to hack personnel management agencies to obtain the personal data of people who have access to classified information that it can use for future targeting.

Axiom has been active for at least six years and employs techniques that make it stand out from other hacker groups, the researchers said. For one thing, it is highly skilled at burying malware within legitimate computer traffic so that a company or agency analyst who is studying traffic logs cannot detect it, Ludwig said.

The malware, called Hikit, can create multiple points of presence — what Ludwig called “breadcrumbs” inside the network to help Axiom move around and steal data, all without arousing suspicion.

Axiom also appears to have a “maintenance cycle” in which it periodically switches out malware, Ludwig said. “They have an advanced playbook,” he said.

Unlike the security firm Mandiant, which reported on Unit 61398, the researchers were unable to identify the locations in China where Axiom operates from or identify its members. Axiom’s members, Ludwig said, are better at covering their tracks than Unit 61398. They did not, for example, keep email accounts or have an online presence that could be traced back to them.

China military expert Mark Stokes said it was “not surprising” to find that Unit 61398 was not as sophisticated as Axiom. That unit is part of the second bureau of the PLA’s Third Department, which is the rough equivalent of the NSA. “Cyber seems a really small part of second bureau’s broader mission, which is signals intelligence,” said Stokes, executive director of Project 2049 Institute, an Arlington, Va., think tank. “There are other parts of 3 PLA that reasonably could be expected to have a much more dedicated cyber mission.”

The research coalition is made up of at least a dozen companies, including Microsoft, whose Windows operating system is on more than 1 billion computers around the world, enabling the firm to detect infections on a wide swath of machines. Microsoft has loaded special software on its malicious software removal tool that automatically detects the presence of Axiom malware and removes it, while allowing the company to track the results.

Some security experts said the report carries valuable remediation advice not often seen in such reports. The researchers created custom “signatures,” ways to detect Axiom malware in users’ computers. This is the sort of data more traditionally exchanged in private intelligence sharing groups, the experts said.

“This is the beginning of what will hopefully be a long line of industry-coordinated efforts to expose these threat groups, and to do so without having to use law enforcement, to help corporations and governments around the world combat” hackers, said Stephen Ward, senior director of iSight Partners, another coalition member. “This is a big first step.”

Other coalition members include Bit9, Cisco, FireEye,F-Secure, Symantec, Tenable, ThreatConnect, ThreatTrack Security, Volexity and threat researchers who did not wish to be identified.

© 2014, The Washington Post

Trending Now

Why Daniel Ortega Is Moving to Eliminate Nicaragua’s Opposition

"They will have no choice but to bark," Nicaraguan President Daniel Ortega shot back in response to the wave of international condemnation sparked by...

Costa Rica Faces Months of Drought as El Niño Intensifies

Costa Rica doesn't take direct hurricane hits often, but this year's El Niño is playing out with the same shape as one, tracked for...

Former Herediano Executive Pleads Guilty in U.S. Gambling Case

Michael Lawrence Brannon, a U.S. businessman who previously held an ownership stake and board position in the group that managed Club Sport Herediano, has...

Pesticide Runoff Is Quietly Draining Costa Rica’s Caribbean Tourism Economy

Decades of banana and pineapple chemistry have left a documented trail through Limón's rivers. The cost lands on the reefs, fisheries and certifications the Caribbean coast needs to compete.

Costa Rica’s Romería Closes With Zero Deaths and 1,772 Medical Cases

Costa Rica's Romería closed without a single reported death, ending a nine-day emergency operation in which the Costa Rican Red Cross treated 1,772 people...

Gunmen Storm Costa Rica Hospital and Kill Patient in Nicoya

Two masked gunmen forced their way into a public hospital in Guanacaste early Saturday and shot a patient to death as he lay on...

Costa Rica Opens Consular Line in Colombia as Earthquake Toll Climbs Past 70

Costa Rica's embassy has opened consular lines in Colombia after Monday's magnitude 7.4 earthquake. Seven airports are shut, Bogotá is still operating, and Avianca and LATAM are waiving change fees.

Costa Rica Orders AyA to Compensate Customers Over Excess Water Charges

An audit put improper water, sewer and hydrant charges at roughly ₡65.4 billion and gave AyA and Aresep until June 2027 to define how customers will be paid back.

Costa Rica Proposes Major Overhaul of Courts and State Oversight

Lawmakers from Costa Rica's governing party filed a package of constitutional reform bills on Tuesday that would end the Comptroller General's power to block...
🌴 The Weekly Pura Vida

Costa Rica, Once a Week

The week's top stories, weather & insider tips — delivered every Sunday. One email, zero clutter.

🔒 Free. No spam. Unsubscribe anytime.

Loading…

Latest News from Costa Rica

Costa Rica Coffee Maker Chorreador
Costa Rica Car Rentals
Costa Rica Travel Insurance
Costa Rica Travel