Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Cyber Spies Targeting U.S. Defense, Tech Firms Linked to China’s PLA: Report

A sophisticated cyber espionage group apparently tied to a Chinese military unit has been targeting organizations in the United States government, research, defense and technology sectors, a new report from CrowdStrike has revealed.

A sophisticated cyber espionage group apparently tied to a Chinese military unit has been targeting organizations in the United States government, research, defense and technology sectors, a new report from CrowdStrike has revealed.

Dubbed “Putter Panda” by the security firm, the threat actors are said to be operating from Shanghai apparently on behalf of Unit 61486 of the People’s Liberation Army (PLA). The group is reportedly linked to the PLA’s 3rd General Staff Department, China’s primary SIGINT collection and analysis agency, and it mainly targets space and aerospace industries not only in the US, but in Europe and Japan as well.

China Cyber Espionage

“This particular unit is believed to hack into victim companies throughout the world in order to steal corporate trade secrets, primarily relating to the satellite, aerospace and communication industries. With revenues totaling $189.2 billion in 2013, the satellite industry is a prime target for espionage campaigns that result in the theft of high-stakes intellectual property,” explained George Kurtz, CEO and co-founder of CrowdStrike.

“While the gains from electronic theft are hard to quantify, stolen information undoubtedly results in an improved competitive edge, reduced research and development timetables, and insight into strategy and vulnerabilities of the targeted organization,” Kurtz added.

The group has been operational since at least 2007, with most of their attacks relying on custom malware deployed through exploits for popular applications like Adobe Reader and the Microsoft Office suite, CrowdStrike noted in its report.

The company also believes that it has identified one of the individuals allegedly involved with the operation. 35-year-old Chen Ping, also known as CPYY, is believed to be responsible for the procurement of the domains used to control Putter Panda malware. The domains have been registered to an address that corresponds to the physical location of Unit 61486 headquarters in Shanghai, the report said.

Unit 61486 is not the only PLA unit accused of conducting cyber espionage operations. In February 2013, Mandiant published a report detailing the activities of Unit 61398, five officers of which were charged with economic espionage against the United States in May 2014.

The Chinese government has denied the accusations on numerous occasions and has asked for more evidence in support of the United States’ claims. CrowdStrike has found evidence that Putter Panda has shared infrastructure with Unit 61398, also known as Comment Panda, and that actors with ties to both groups have interacted.

Advertisement. Scroll to continue reading.

“Targeted economic espionage campaigns compromise technological advantage, diminish global competition, and ultimately have no geographic borders,” CrowdStrike said. “We believe the U.S. Government indictments and global acknowledgment and awareness are important steps in the right direction. In support of these efforts, we are making this report available to the public to continue the dialog around this ever-present threat.”

The complete 62-page intelligence report on Putter Panda is available online.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.