战略与国际研究中心-Cyber-Incidents-Attributed-to-China_15页_329kb
报告摘要
Cyber Incidents Attributed to China: Summary
Core Content
This document compiles a range of reports and analyses from various security and intelligence organizations, detailing cyber incidents attributed to China. It focuses on both specific and general attributions, highlighting the involvement of Chinese government entities, particularly the People's Liberation Army (PLA), in cyber espionage and hacking campaigns. The reports emphasize the strategic and economic motivations behind these attacks, as well as the sophisticated infrastructure and techniques employed.
Main Points
- Government Involvement: Multiple reports indicate that cyber incidents are often state-sponsored, with the Chinese government directly or indirectly supporting hacking activities.
- PLA's Role: The PLA, particularly its General Staff Department's 3rd Department (Unit 61398), is frequently linked to cyber operations.
- Targeted Industries: The attacks target a wide range of sectors including defense, energy, aerospace, IT, and financial services, often with strategic implications.
- Hacker Recruitment: Chinese universities and military-affiliated institutions are involved in recruiting and training hackers for cyber operations.
- Evidence of Attribution: Logs, IP addresses, malware, and codebases are used to trace attacks back to China, suggesting a coordinated and sustained effort.
- Global Impact: The cyber campaigns have affected multiple countries, including the United States, Japan, India, and others, with potential military and economic consequences.
Key Information
Specific Attribution to China
- Wang (Rocy Bird): A PLA-linked hacker who blogged about his experiences in a hacking unit, active between 2006 and 2009. His writings and activities are linked to Mandiant's APT1 report.
- APT1 (Unit 61398): Identified as a PLA unit responsible for numerous cyber espionage attacks, targeting over 140 organizations across various industries.
- Zhang Changhe: A PLA Information Engineering University teacher linked to attacks on Vietnamese government ministries and other targets.
- Gu Kaiyuan: A former student at Sichuan University, associated with the 'Byzantine Hades' campaign, traced back to China.
- Javaphile: A Chinese hacker group with a formal connection to the Shanghai Public Security Bureau.
- NCPH Group: Located in Sichuan Province, linked to attacks on the U.S. Defense Department.
- Titan Rain: A series of cyber espionage attacks on U.S. government and military networks, traced to Guangdong province.
- Unit 61539 (BNCC): A PLA unit identified as one of the most capable in cyber operations, with senior officials listed.
- Honker Union: A group suspected of being a proxy for the Chinese government, with attacks traced back to mainland China.
General Attribution to China
- Operation Aurora (Elderwood): A large-scale cyberattack campaign traced to China, with evidence pointing to state sponsorship.
- Shady RAT: A long-term cyber espionage campaign targeting over 70 organizations, attributed to a state actor, likely China.
- GhostNet: A cyber espionage network linked to Chinese military and intelligence activities, with targets in South and Southeast Asia.
- Chinese Cyber Warfare Strategy: The PLA emphasizes information warfare, aiming for information superiority through network-centric operations.
- University Involvement: Chinese universities are involved in training and supporting cyber operations, with recruitment efforts targeting students.
- Economic Espionage: China is noted as the most aggressive country in economic espionage, using both state and non-state actors to steal intellectual property.
- International Targets: Attacks have targeted not only U.S. entities but also companies in Europe, such as EADS and ThyssenKrupp, and organizations in Japan and India.
- Cyber Infrastructure: China has a well-developed cyber infrastructure, including training facilities and hacking groups, that support its cyber operations.
Conclusion
The document provides substantial evidence of China's involvement in cyber espionage and hacking, with a focus on the PLA's role in orchestrating and supporting these activities. The attribution is based on a combination of technical evidence, such as malware and IP addresses, and strategic analysis of the targets and methods used. These findings underscore the growing concern over China's cyber capabilities and their potential impact on global security and economic interests.
试读结束,高清完整版pdf/doc/ppt,请点下载