POST Online Media Lite Edition



 

Chinese intelligence conspired to steal sensitive aviation and technological data for years

Staff Writer |
Chinese intelligence officers and those working under their direction, which included hackers and co-opted company insiders, conducted or otherwise enabled repeated intrusions into private companies’ computer systems in the United States and abroad for over five years.<br><br>rnThe conspirators’ ultimate goal was to steal, among other data, intellectual property and confidential business information, including information related to a turbofan engine used in commercial airliners.<br><br>rnThe charged intelligence officers, Zha Rong and Chai Meng, and other co-conspirators, worked for the Jiangsu Province Ministry of State Security (“JSSD”), headquartered in Nanjing, which is a provincial foreign intelligence arm of the People’s Republic of China’s Ministry of State Security (“MSS”).<br><br>rnThe MSS, and by extension the JSSD, is primarily responsible for domestic counter-intelligence, non-military foreign intelligence, and aspects of political and domestic security.<br><br>rnFrom at least January 2010 to May 2015, JSSD intelligence officers and their team of hackers, including Zhang Zhang-Gui, Liu Chunliang, Gao Hong Kun, Zhuang Xiaowei, and Ma Zhiqi, focused on the theft of technology underlying a turbofan engine used in U.S. and European commercial airliners.<br><br>rnThis engine was being developed through a partnership between a French aerospace manufacturer with an office in Suzhou, Jiangsu province, China, and a company based in the United States.<br><br>rnMembers of the conspiracy, assisted and enabled by JSSD-recruited insiders Gu Gen and Tian Xi, hacked the French aerospace manufacturer.<br><br>rnThe hackers also conducted intrusions into other companies that manufactured parts for the turbofan jet engine, including aerospace companies based in Arizona, Massachusetts and Oregon.<br><br>rnAt the time of the intrusions, a Chinese state-owned aerospace company was working to develop a comparable engine for use in commercial aircraft manufactured in China and elsewhere.<br><br>rnDefendant Zhang Zhang-Gui is also charged, along with Chinese national Li Xiao, in a separate hacking conspiracy, which asserts that Zhang Zhang-Gui and Li Xiao leveraged the JSSD-directed conspiracy’s intrusions, including the hack of a San Diego-based technology company, for their own criminal ends.<br><br>rn“For the third time since only September, the National Security Division, with its US Attorney partners, has brought charges against Chinese intelligence officers from the JSSD and those working at their direction and control for stealing American intellectual property,” said John C. Demers, Assistant Attorney General for National Security.<br><br>rn“This is just the beginning.<br><br>rnTogether with our federal partners, we will redouble our efforts to safeguard America’s ingenuity and investment.”<br><br>rn“State-sponsored hacking is a direct threat to our national security.<br><br>rnThis action is yet another example of criminal efforts by the MSS to facilitate the theft of private data for China’s commercial gain,” said U.S.<br><br>rnAttorney Adam Braverman.<br><br>rn“The concerted effort to steal, rather than simply purchase, commercially available products should offend every company that invests talent, energy, and shareholder money into the development of products.”<br><br>rn“The threat posed by Chinese government-sponsored hacking activity is real and relentless,” said John Brown, FBI Special Agent in Charge of the San Diego Field Office.<br><br>rn“Today, the Federal Bureau of Investigation, with the assistance of our private sector, international and U.S.<br><br>rngovernment partners, is sending a strong message to the Chinese government and other foreign governments involved in hacking activities.<br><br>rnWe are working together to vigorously investigate and hold hackers accountable regardless of their attempts to hide their illicit activities and identities.”<br><br>rnOn October 10, the Department of Justice announced that a JSSD intelligence officer was extradited to the Southern District of Ohio, on charges that he attempted to steal trade secrets related to jet aircraft engines, and in September, in the Northern District of Illinois, a grand jury indicted a U.S.<br><br>rnArmy recruit who is accused of working as an agent of a JSSD intelligence officer, without notification to the Attorney General.rnrnAs the indictment in the Southern District of California describes in detail, China’s JSSD intelligence officers and hackers working at their direction masterminded a series of intrusions in order to facilitate intrusions and steal non-public commercial and other data.<br><br>rnThe hackers used a range of techniques, including spear phishing, sowing multiple different strains of malware into company computer systems, using the victim companies’ own websites as “watering holes” to compromise website visitors’ computers, and domain hijacking through the compromise of domain registrars.<br><br>rnThe first alleged hack began no later January 8, 2010, when members of the conspiracy infiltrated Capstone Turbine, a Los-Angeles-based gas turbine manufacturer, in order to steal data and use the Capstone Turbine website as a “watering hole.”<br><br>rnChina’s intelligence service also sought, repeatedly, to hack into a San Diego-based technology company from at least August 7, 2012 through January 15, 2014, in order to similarly steal commercial information and use its website as a “watering hole.”<br><br>rnChinese actors used not only hacking methods to conduct computer intrusions and steal commercial information, they also coopted victim company employees.<br><br>rnFrom at least November 2013 through February 2014, two Chinese nationals working at the direction of the JSSD, Tian Xi and Gu Gen, were employed in the French aerospace company’s Suzhou office.<br><br>rnOn January 25, 2014, after receiving malware from an identified JSSD officer acting as his handler, Tian infected one of the French company’s computers with malware at the JSSD officer’s direction.<br><br>rnOne month later, on February 26, 2014, Gu, the French company’s head of Information Technology and Security in Suzhou, warned the conspirators when foreign law enforcement notified the company of the existence of malware on company systems.<br><br>rnThat same day, leveraging that tip-off, conspirators Chai Meng and Liu Chunliang tried to minimize JSSD’s exposure by causing the deletion of the domain linking the malware to an account controlled by members of the conspiracy.<br><br>rnThe group’s hacking attempts continued through at least May of 2015, when an Oregon-based company, which, like many of the other targeted companies, built parts for the turbofan jet engine used in commercial airliners, identified and removed the conspiracy’s malware from its computer systems.<br><br>rnCount Two of the indictment charges a separate conspiracy to hack computers in which Zhang Zhang-Gui, a defendant charged in Count One, supplied his co-defendant and friend, Li Xiao, with variants of the malware that had been developed and deployed by hackers working at the direction of the JSSD on the hack into Capstone Turbine.<br><br>rnUsing malware supplied by Zhang, as well as other malware, Li launched repeated intrusions that targeted a San Diego-based computer technology company for more than a year and a half.<br><br>rnThese intrusions caused thousands of dollars of damage to protected computers.<br><br>rnCount Three of the indictment charges Zhang Zhang-Gui with the substantive offense of computer hacking a San Diego technology company, which was one of the targets of the conspiracies alleged in Counts One and Two.<br><br>rnThe charges contained in the indictment are merely accusations, and the defendants are presumed innocent unless and until proven guilty.<br><br>rnThe FBI, led by the San Diego Field Office, conducted the investigation that resulted in charges announced today.<br><br>rnThis case is being prosecuted by Alexandra Foster and Sabrina Fève of the United States Attorney’s Office for the Southern District of California and Jason McCullough of the National Security Division’s Counterintelligence and Export Control Section.<br><br>rnThe Criminal Division’s Office of International Affairs also provided assistance in this matter, and the Department appreciates the cooperation and assistance provided by France’s General Directorate for Internal Security (DGSI) and the

Article continues below




ttp://www.histerius.com/hs0818/officials.jpg" class="slikadesno" alt="officials" title="officials">Chinese intelligence officers and those working under their direction, which included hackers and co-opted company insiders, conducted or otherwise enabled repeated intrusions into private companies’ computer systems in the United States and abroad for over five years.

The conspirators’ ultimate goal was to steal, among other data, intellectual property and confidential business information, including information related to a turbofan engine used in commercial airliners.

The charged intelligence officers, Zha Rong and Chai Meng, and other co-conspirators, worked for the Jiangsu Province Ministry of State Security (“JSSD”), headquartered in Nanjing, which is a provincial foreign intelligence arm of the People’s Republic of China’s Ministry of State Security (“MSS”).

The MSS, and by extension the JSSD, is primarily responsible for domestic counter-intelligence, non-military foreign intelligence, and aspects of political and domestic security.

From at least January 2010 to May 2015, JSSD intelligence officers and their team of hackers, including Zhang Zhang-Gui, Liu Chunliang, Gao Hong Kun, Zhuang Xiaowei, and Ma Zhiqi, focused on the theft of technology underlying a turbofan engine used in U.S. and European commercial airliners.

This engine was being developed through a partnership between a French aerospace manufacturer with an office in Suzhou, Jiangsu province, China, and a company based in the United States.

Members of the conspiracy, assisted and enabled by JSSD-recruited insiders Gu Gen and Tian Xi, hacked the French aerospace manufacturer.

The hackers also conducted intrusions into other companies that manufactured parts for the turbofan jet engine, including aerospace companies based in Arizona, Massachusetts and Oregon.

At the time of the intrusions, a Chinese state-owned aerospace company was working to develop a comparable engine for use in commercial aircraft manufactured in China and elsewhere.

Defendant Zhang Zhang-Gui is also charged, along with Chinese national Li Xiao, in a separate hacking conspiracy, which asserts that Zhang Zhang-Gui and Li Xiao leveraged the JSSD-directed conspiracy’s intrusions, including the hack of a San Diego-based technology company, for their own criminal ends.

“For the third time since only September, the National Security Division, with its US Attorney partners, has brought charges against Chinese intelligence officers from the JSSD and those working at their direction and control for stealing American intellectual property,” said John C. Demers, Assistant Attorney General for National Security.

“This is just the beginning.

Together with our federal partners, we will redouble our efforts to safeguard America’s ingenuity and investment.”

“State-sponsored hacking is a direct threat to our national security.

This action is yet another example of criminal efforts by the MSS to facilitate the theft of private data for China’s commercial gain,” said U.S.

Attorney Adam Braverman.

“The concerted effort to steal, rather than simply purchase, commercially available products should offend every company that invests talent, energy, and shareholder money into the development of products.”

“The threat posed by Chinese government-sponsored hacking activity is real and relentless,” said John Brown, FBI Special Agent in Charge of the San Diego Field Office.

“Today, the Federal Bureau of Investigation, with the assistance of our private sector, international and U.S.

government partners, is sending a strong message to the Chinese government and other foreign governments involved in hacking activities.

We are working together to vigorously investigate and hold hackers accountable regardless of their attempts to hide their illicit activities and identities.”

On October 10, the Department of Justice announced that a JSSD intelligence officer was extradited to the Southern District of Ohio, on charges that he attempted to steal trade secrets related to jet aircraft engines, and in September, in the Northern District of Illinois, a grand jury indicted a U.S.

Army recruit who is accused of working as an agent of a JSSD intelligence officer, without notification to the Attorney General. As the indictment in the Southern District of California describes in detail, China’s JSSD intelligence officers and hackers working at their direction masterminded a series of intrusions in order to facilitate intrusions and steal non-public commercial and other data.

The hackers used a range of techniques, including spear phishing, sowing multiple different strains of malware into company computer systems, using the victim companies’ own websites as “watering holes” to compromise website visitors’ computers, and domain hijacking through the compromise of domain registrars.

The first alleged hack began no later January 8, 2010, when members of the conspiracy infiltrated Capstone Turbine, a Los-Angeles-based gas turbine manufacturer, in order to steal data and use the Capstone Turbine website as a “watering hole.”

China’s intelligence service also sought, repeatedly, to hack into a San Diego-based technology company from at least August 7, 2012 through January 15, 2014, in order to similarly steal commercial information and use its website as a “watering hole.”

Chinese actors used not only hacking methods to conduct computer intrusions and steal commercial information, they also coopted victim company employees.

From at least November 2013 through February 2014, two Chinese nationals working at the direction of the JSSD, Tian Xi and Gu Gen, were employed in the French aerospace company’s Suzhou office.

On January 25, 2014, after receiving malware from an identified JSSD officer acting as his handler, Tian infected one of the French company’s computers with malware at the JSSD officer’s direction.

One month later, on February 26, 2014, Gu, the French company’s head of Information Technology and Security in Suzhou, warned the conspirators when foreign law enforcement notified the company of the existence of malware on company systems.

That same day, leveraging that tip-off, conspirators Chai Meng and Liu Chunliang tried to minimize JSSD’s exposure by causing the deletion of the domain linking the malware to an account controlled by members of the conspiracy.

The group’s hacking attempts continued through at least May of 2015, when an Oregon-based company, which, like many of the other targeted companies, built parts for the turbofan jet engine used in commercial airliners, identified and removed the conspiracy’s malware from its computer systems.

Count Two of the indictment charges a separate conspiracy to hack computers in which Zhang Zhang-Gui, a defendant charged in Count One, supplied his co-defendant and friend, Li Xiao, with variants of the malware that had been developed and deployed by hackers working at the direction of the JSSD on the hack into Capstone Turbine.

Using malware supplied by Zhang, as well as other malware, Li launched repeated intrusions that targeted a San Diego-based computer technology company for more than a year and a half.

These intrusions caused thousands of dollars of damage to protected computers.

Count Three of the indictment charges Zhang Zhang-Gui with the substantive offense of computer hacking a San Diego technology company, which was one of the targets of the conspiracies alleged in Counts One and Two.

The charges contained in the indictment are merely accusations, and the defendants are presumed innocent unless and until proven guilty.

The FBI, led by the San Diego Field Office, conducted the investigation that resulted in charges announced today.

This case is being prosecuted by Alexandra Foster and Sabrina Fève of the United States Attorney’s Office for the Southern District of California and Jason McCullough of the National Security Division’s Counterintelligence and Export Control Section.

The Criminal Division’s Office of International Affairs also provided assistance in this matter, and the Department appreciates the cooperation and assistance provided by France’s General Directorate for Internal Security (DGSI) and the Cybercrime Section of the Paris Prosecutor’s Office during the investigation of this matter.


What to read next

Conspiring to export specialty metals to Iran
Chinese company Sinovel Wind Group convicted of theft of trade secrets
Executives charged with manipulating company’s accounting systems

U.S.: Areas of severe thunderstorms and heavy rain through the weekend

 
Upper-level ridging weakens from the Ohio Valley to the Southeast on Friday, resulting in a reduced area of Heat Advisories over the east.
 
 

Latest

Baker Hughes: U.S. oil rig count down by 6 to 432
Malaysia introduces new rules prohibiting all plastic waste imports from U.S.
Kazakh-German JV Skyhansa to build $500 mln airport near Chinese border
Ukrainian poultry products gained access to Oman market

NEWS

EPPO targets criminal organisation suspected of VAT fraud involving sales of diesel

U.S.: Severe thunderstorms in the Northern Plains and Upper Midwest
Former U.S. senator Bob Menendez begins serving 11-year bribery sentence
Russian-linked tanker crew accused in Finland-Estonia undersea cable sabotage probe
Croatia: Former minister sentenced to two years of imprisonment for abuse of office and authority
U.S.: Widespread showers across the eastern half, severe thunderstorms in Montana into the Plains
 

BUSINESS

Peru's mining exports jump 23 pct

Vietnam encourages private businesses to invest in railway sector
Baker Hughes: U.S. oil rig count down by 1 to 438
AfDB to provide $184.1 million for Africa’s largest solar energy and battery storage project
EIB supports Bay of Biscay electricity interconnection between Spain and France
U.S., UK, and Congolese officials inaugurate Kiswishi City Special Economic Zone
 

Trending Now

Peru's mining exports jump 23 pct

Fire in Egyptian hospital kills at least seven coronavirus patients

Egyptians start paying taxes on imported mobiles

Micron plans to invest $200 billion in semiconductor manufacturing and R&D


POLITICS

New York Power Authority directed to develop nuclear power plant

Cuban President begins official visit to Belarus
EU adopts new tariffs on Russian and Belarusian agricultural goods and fertilisers
EU proposes banning LNG gas imports from Russia by end of 2027
New York Governor announces Sullivan County broadband project
Zimbabwe to ban lithium concentrate exports
 

Today We Recommend

New York Power Authority directed to develop nuclear power plant


Highlights 

Micron plans to invest $200 billion in semiconductor manufacturing and R&D

750 new jobs coming to Michigan

WFS to open new multi-purpose terminal at Lyon Airport


COMPANIES

Micron plans to invest $200 billion in semiconductor manufacturing and R&D

750 new jobs coming to Michigan
LS Cable and unit join Korea-Japan submarine cable project
WFS to open new multi-purpose terminal at Lyon Airport
CEVA Logistics renews contract to transport aeronautics parts between France, Morocco, Tunisia
Malian government takes over Canadian-owned Barrick Gold mine
 

CAREERS

Bluecrux appoints four new partners

Isomorphic Labs appoints Ben Wolf as chief medical officer
Vodacom names new international markets CEO
David Andreadakis joins Loyalty Juggernaut as chief commercial officer
Tom Montali joins CSL as business development director
Concirrus appoints Steve O'Reilly as product manager
 

ECONOMY

EU-Mercosur trade up substantially in last decade

Russia's trade surplus falls 18.3% to $42.4 bln in January-April
U.S. economy in Q1 revised up to 0.2-pct contraction
Japan loses top creditor position for first time in 34 years
NZ exports to EU jump 28% in first year of trade deal
EU generated €39.2 billion surplus in trade in agricultural products
 

EARNINGS

Ericsson Q2 sales down but North America up

Lockton revenue $3.55 billion
Motorcar Parts of America Q4 sales $189.5 million
Limoneira Q2 revenue $44.6 million
Lululemon athletica Q1 revenue increased 10% to $2.2 billion
PVH Q1 GAAP EBIT $205 million
 

OP-ED

Micromanaging is the worst enemy of efficiency and teamwork

Niger set to monetize massive gas reserves through Saharan natural gas pipeline
Putting the brakes on EV folly that choked the market
Oil discovery in Kavango Basin may mean huge benefits for Namibians
Cape Town and Dubai battle over Africa's energy future
Is America going to lose its superpower status?
 

AGRIFISH

Ireland: Minister Donohoe removes broiler poultry farmers from VAT Flat Rate Addition scheme

FLI tests mobile One Health laboratory for diagnosing highly pathogenic pathogens
First vaccine against swine dysentery disease recommended for approval
USDA expands fruit pest quarantines in New York and California
Peru records 23.6% growth in agricultural export sales compared to 2024
China allows imports of rapeseed meal, soybean meal from Uruguay
 

LEADERSHIP

Study: Missing a deadline has a bigger impact than you might think

Employers prefer younger job candidates for AI roles although experienced workers perform same or better
Study finds workers misjudge wage markets
Some organizations may need to expand their hierarchical structures earlier than others
Study finds there's right way and wrong way to deliver negative feedback in workplace
Allyship is critical and its needs appreciation
 

CRIME

German court convicts four ex-Volkswagen managers of fraud in emissions scandal

EU fines carmakers €458 million for anti-recycling cartel
Commission fines Pierre Cardin and its licensee Ahlers €5.7 million for restricting cross-border sales of clothing
BHP, Vale agree to pay $30B damages for Brazil dam disaster
Commission fines České dráhy and Österreichische Bundesbahnen €48.7 million over collusion to exclude common compe
SEC charges Keurig with making inaccurate statements regarding recyclability of K-Cup beverage pod
 

Magazine

TRAVEL

Radisson Hotel Group debuts in the heart of Tunisia’s capital city, Tunis

Morocco’s first Radisson branded hotel opens in Casablanca
Buna channels, an unreal and beautiful part of Bosnia and Herzegovina
JW Marriott unveils Mindful Haven with opening of JW Marriott Hotel Nairobi
Sotheby's Sports Week returns with fantastic artifacts
Red Roof properties open in Michigan
 

SEA, LAND, AIR

Citroën C3 Aircross, the most affordable compact SUV with 7 seats

2025 Chevrolet Equinox stands apart with fresh looks and capability
Hill Helicopters HX50, luxury in the sky
Opel Movano becomes fully equipped camper van
Porsche Panamera, new hybrid variants
Dodge Charger, 670 horsepower of electric
 

DESIGN

Cold night, hot fire pit, cool entertainment

Embellish your home with PVC panels
You'll have to hurry if you want one of 20 new Louis Vuitton watches
Luxury duvet looks good, fells good and keeps you healthy
Vacheron Constantin, watches for life and more
Schüller kitchens, where functionality marries design
 

GADGETS

MESA/Boogie Celebrates 40-year partnership with John Petrucci

reMarkable 2, monochrome tablet for your thoughts and your eyes
OnePlus Ace 3V, first with Snapdragon 7 Plus Gen 3
ASUS Zenfone 11 Ultra, flagship with a reason
Samsung Galaxy S24 is photography powerhouse
Casette tapes are making a big comeback, and so are portable players
 

HEALTH

Bolivia declares national health emergency due to measles outbreak

Hong Kong researchers develop needle-free flu vaccine with broad protection
World's first vaccines that don't need refrigeration entered trials
First patient enrolled in Phase 1 clinical trial of Akiram’s cancer drug candidate
FDA grants marketing authorization of first home test for chlamydia, gonorrhea and trichomoniasis
Human cases of anthrax reported in western Mongolia
 

MEANTIME

Cost of keeping wind turbines out of sight

Mission to "weigh" all of Earth's forests from space launched
NASA's SPHEREx space telescope begins mapping entire sky
Russian academics, gas industry experts see undersea LNG transportation as feasible
India launches space docking experiment mission
World-first carbon-14 diamond battery made