Trump administration considering mass expulsions of alleged Chinese spies

United States ChinaThe administration of United States President Donald Trump is considering the possibility of expelling from the country dozens of Chinese diplomats, journalists, and others, who are believed to be undercover spies. The expulsions relate to a spiraling information war between Washington and Beijing, which has erupted in recent weeks as a result of the COVID-19 pandemic.

Earlier this month, the Chinese government announced that it would expel 13 American journalists from three major newspapers, The Wall Street Journal, The New York Times and The Washington Post. Beijing also stipulated that all American news organizations operating in China had to provide its government with detailed information about their financial assets, employee structure and other organizational information. The journalists claimed that they were expelled for trying to report about the status of the COVID-19 pandemic inside China.

Around the same time, President Trump and senior members of his administration, including Secretary of State Mike Pompeo, began referring to the severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2, known as novel coronavirus) as “the Chinese virus” or “the Wuhan virus”. The term refers to the Chinese province where the virus is believed to have originated. President Trump claims that he decided to use the term “Chinese virus” in response to unsubstantiated claims by government officials in Beijing that the novel coronavirus was brought to China by members of the US military.

On Thursday The New York Times reported that the Trump administration was considering expelling from the US a large number of Chinese citizens who work as diplomats or journalists. In some cases, the White House is reportedly considering shutting down the bureaus of some Chinese media outlets in the US. According to a number of administration officials, many Chinese journalists based in the US are in reality undercover intelligence officers, who regularly report to the Ministry of State Security —China’s primary external intelligence agency. Some of these alleged undercover intelligence officers —known in the world of intelligence as ‘non-official cover’— are allegedly embedded with China Global Television Network, the foreign-language arm of the state-owned China Central Television (CCTV), according to some American officials.

On March 2, the Trump administration abruptly imposed quotas on the number of foreign citizens who are permitted to work for Chinese media organizations in the US. The Chinese media groups complied with the new directive in a timely manner, by recalling over 60 of their staff members to China. However, the White House now believes that a significant number of the 100 Chinese journalists who continue to operate in the US are undercover intelligence officers.

Meanwhile, on March 25, China’s English-language government-owned newspaper The Global Times raised eyebrows by repeating allegations that the novel coronavirus was brought to China by an American cyclist, who visited Wuhan in October of last year to compete in the Military World Games. Such allegations, which propagate the view that the novel coronavirus originated in the US, are quickly growing in popularity in Chinese social media platforms.

► Author: Joseph Fitsanakis | Date: 27 March 2020 | Permalink

Militaries around the world scramble to contain impact of COVID-19

COVID-19 ChinaMilitary forces around the world are scrambling to contain the impact of COVID-19 on military readiness, as the virus continues to infect troops and commanders at an alarming rate. On Tuesday, the Polish government announced that General Jaroslaw Mika, who serves as general commander of Branches of the Armed Forces, had tested positive for the coronavirus. General Mika is believed to have contracted the virus during a military conference that took place in the German city of Wiesbaden, where North Atlantic Treaty Organization commanders gathered to plan an American-led military exercise.

Also on Tuesday, the United States Department of Defense said that the commander of the US Army in Europe, Lieutenant General Christopher Cavoli, participated at the Wiesbaden conference, along with several other US Army staff members. They are currently being tested for exposure to COVID-19. Meanwhile the Reuters news agency reported that the US Pentagon acknowledged that “the US military’s official tally of servicemembers and related personnel who have been infected by the coronavirus likely undercounts the actual total”. Sources told the news agency that the low age and good health of American troops was “a mixed blessing of sorts”, since it allows US servicemembers to survive the virus but at the same time reduces their symptoms that would normally trigger testing for COVID-19.

The government of Taiwan said on Tuesday that over 400 members of its armed forces had entered self-imposed quarantine in order to prevent a possible COVID-19 outbreak among military personnel. This brings the total number of Taiwanese servicemembers who are currently in quarantine to over 2,000, which includes two generals. The country’s Minister of Defense, Yen De-fa, insisted on Tuesday that the virus had not impacted Taiwan’s military readiness.

Chinese officials have not provided information about the effect of the coronavirus on the country’s military. The Chinese-language website of The Epoch Times said last week that, according to unnamed insiders, the Chinese People’s Liberation Army had “forcibly isolated” tens of thousands of servicemembers this month. There are no reports of specific numbers in the Chinese media or non-Chinese news outlets.

Finally, according to Daily NK, a South Korean website that specializes on news from North Korea, approximately 180 North Korean soldiers have died as a result of contracting COVID-19 in the past month. The website cited “a source inside the North Korean military”, who said that Pyongyang had forcibly quarantined at around 3,700 soldiers of all ranks to prevent the spread of COVID-19 in the country’s military.

► Author: Joseph Fitsanakis | Date: 10 March 2020 | Permalink

Chinese cybersecurity firm accuses CIA of 11-year cyberespionage campaign

CIA headquartersA leading Chinese cybersecurity firm has accused the United States Central Intelligence Agency of using sophisticated malicious software to hack into computers belonging to the Chinese government and private sector for over a decade.

The accusation against the CIA comes from Qihoo 360, a prominent cybersecurity firm headquartered in Beijing. On Monday, company published a report of its investigation on its website, written in both Chinese and English. The report identifies the hackers as “the CIA Hacking Group (APT-C-39)”, and says that the group has carried out activities against “China’s critical industries” for at least 11 years.

The report claims that APT-C-39 targets included China’s energy and civilian aviation sectors, Internet service providers, scientific research universities and organizations, and various government agencies —which it does not name. The majority of the hacker group’s targets were located in Beijing, and also in China’s Zhejiang and Guangdong provinces.

According to Qihoo 360, APT-C-39 must be a “state-level hacking organization”, judging by the hacking tools that it used. These tools, such malware named by forensics experts as Grasshopper and Fluxwire, are believed to have been designed by the CIA. They were leaked in 2017 by the international whistleblower website WikiLeaks. American authorities have charged a former CIA programmer, Joshua Schulte, with leaking the malware. Schulte denies the charges.

The Qihoo 360 report also claims that the hours during which APT-C-39 hackers appear to be active correspond to the working hours of the East Coast of the United States. It also suggests that one goal behind the hacking operations against airline industry targets was to access the travel itineraries of senior figures in China’s political and industrial circles.

► Author: Ian Allen | Date: 04 March 2020 | Permalink

US threatens to de-fund Africa disease control program over Chinese influence

African UnionThe United States has threatened to pull its funding for an Africa-wide disease control program if the African Union decides to accept an offer from China to build the program’s new headquarters. The dispute accentuates a growing competition between Washington and Beijing to exert political control in Africa and places the African Union at the center of a difficult dilemma.

The quarrel concerns the Africa Centers for Disease Control and Prevention, or Africa CDC, a network of five biomedical research hubs that are located in Zambia, Kenya, Gabon, Nigeria and Egypt. The network was established in 2017 in response to the outbreak of the Ebola epidemic in western Africa. Its mission is to gather data that can help monitor and contain disease outbreaks and other health crises throughout the continent. The network’s central hub is located at the headquarters of the African Union in Addis Ababa, Ethiopia.

Africa CDC is an initiative of the African Union, but it is partly funded by outside countries and bodies, including China, the United States, and the World Bank. Washington supported the establishment of Africa CDC with a donation of $14 million, and an offer to pay the project director’s salary, as well as assign scientists to work there from the US CDC. But the United States has expressed concerns about a recent offer by China to double its funding of Africa CDC and to build a the organization’s new headquarters, at the cost of $80 million. Foreign affairs ministers from the African Union’s 55 states began discussing Beijing’s offer on Thursday during a meeting in Ethiopia.

There are some among them who question China’s intentions. They refer to news reports that surfaced in the French press in 2018, according to which the Chinese-built headquarters of the African Union was comprehensively ‘bugged’ by Beijing. According to the reports, the $200 million, 19-storey skyscraper in the Ethiopian capital was hardwired with computer servers that secretly communicate with Chinese government computers, without the consent of African Union network managers.

On Thursday The Wall Street Journal quoted an anonymous United States government official, who said that “if the Chinese build the headquarters [of Africa CDC], the US will have nothing to do with” the organization. The African Union has not commented on The Journal’s article.

► Author: Joseph Fitsanakis | Date: 07 February 2020 | Permalink

 

US expels Chinese diplomats for the first time since 1987

Chinese embassy in the United StatesThe United States quietly expelled two Chinese diplomats in October of this year, a move that neither Washington nor Beijing chose to make public, according to a report published on Sunday. If true, the incident would signify the first known expulsions of Chinese diplomatic personnel from the US since 1987.

The incident was reported by The New York Times, which cited “six people with knowledge of the expulsions”. It said that the expulsions were triggered by an incident that took place in September in the US state of Virginia. It involved at least two Chinese diplomats stationed in Washington, who allegedly attempted to enter “a sensitive installation” near the city of Norfolk. The paper did not name the installation, but said that it belongs to the US Armed Forces and is also used by members of Special Operations forces.

According to the American side, a car carrying the Chinese diplomats and their spouses drove up to one of the checkpoints of the military installation. Upon realizing that the car’s passengers did not have permission to enter the base, the guard at the checkpoint asked the driver to proceed through the gated entry and immediately turn around, thus exiting the base. But the car allegedly drove straight into the base and did not slow down after military personnel pursued it. It came to a stop only after several fire trucks blocked its way.

Once apprehended, the car’s passengers claimed that their knowledge of English was limited and had thus misunderstood the instructions given to them by the guard at the entrance to the base. The New York Times reported that this explanation was echoed by associates of the Chinese diplomats, who said that they were on “a sightseeing tour when they accidentally drove onto the base”.

But US officials told The Times they are skeptical of that explanation, and suspect the Chinese diplomats were trying to assess the physical security of the installation. Moreover, at least one of the Chinese diplomats was allegedly an intelligence officer operating under diplomatic cover —a clue that heightened the skepticism of American officials.

Interestingly, although it complained about the expulsions of its diplomats following the incident in Virginia, Beijing did not retaliate, as is customary in such cases. Therefore, no American diplomats or intelligence officers have been expelled from China in response to Washington’s move. The last time the US expelled Chinese diplomats from its soil was in 1987, when two employees of the Chinese embassy in Washington —almost certainly intelligence officers operating under diplomatic cover— were declared personae non gratae.

► Author: Joseph Fitsanakis | Date: 16 December 2019 | Permalink

Belgian university shuts down Chinese-funded institute due to espionage claims

Xinning SongOne of Belgium’s leading universities has decided to shut down a research institute funded by the Chinese government, after the Belgian intelligence service accused its director of spying on behalf of Beijing. The news was announced on Wednesday by the Vrije Universiteit Brussel (VUB), one of Belgium’s leading higher-education institutions. The Confucius Institute has been operated at VUB since 2006. But the university’s board of directors now says that it will not be renewing its contact with the Institute in 2020.

The Confucius Institute at VUB is one of more than 500 such research bodies that the government of China has funded around the world since 2004. Their mission is to promote the language and culture of China to the world. However, numerous academic institutions in Japan, Canada, and a number of European countries, have recently shut down Confucius Institute branches, following allegations that their staff members carried out espionage tasks, or tried to stifle academic research critical of China. In Europe alone, the University of Lyon in France, Stockholm University in Sweden, and Holland’s University of Leiden have all recently terminated their cooperation with the Confucius Institute.

In October of this year, Belgium’s State Security Service (VSSE) concluded that the VUB Confucius Institute director, Dr. Song Xinning, carried out espionage tasks on behalf of the Chinese government. As a result, the Belgian government refused to renew the work visa of Dr. Song, who had lived in Belgium for over a decade. Additionally, the Chinese academic was barred from entering the European Union’s Schengen Area —which comprises 26 European countries— for eight years.

Dr. Song alleges that his work visa was revoked after he refused to cooperate with an American diplomat stationed in Brussels. He also denies that he was ever in the service of Chinese intelligence or the Chinese state. But the VUB appears to have sided with the Belgian government in this dispute. The university annulled its contract with Dr. Song and, as of January, will be terminating its relationship with the Confucius Institute. In a press statement published online, VUB Rector Caroline Pauwels said that the work of the Confucius Institute did not meet the “current policy objectives” of the university.

► Author: Ian Allen | Date: 12 December 2019 | Permalink

As Australia launches probe, skeptics cast doubts on Chinese defector’s spy claims

Wang LiqiangAs the Australian government has launched an official investigation into the claims made by a self-styled Chinese intelligence defector, some skeptics have begun to cast doubts about his revelations. The claims of Wang “William” Liqiang have dominated news headlines in Australia for over a week. The 26-year-old from China’s eastern Fujian province reportedly defected to Australia in October, while visiting his wife and newborn son in Sydney. He is currently reported to be in a safe house belonging to the Australian Security Intelligence Organization (ASIO).

The Australian spy agency confirmed last week that Mr. Wang had provided a 17-page sworn statement, in which he detailed his work as an undercover intelligence officer for Chinese military intelligence. He is also said to have shared the identities of senior Chinese intelligence officers in Taiwan and Hong Kong, and to have explained how they plan to carry out espionage operations on behalf of Bejing. Some media reports claimed that Mr. Wang had shared details about deep-cover Chinese intelligence networks in Australia. The Australian government said on Tuesday that an official investigation had been launched into Mr. Wang’s claims.

But some skeptics in Australia and elsewhere have begun to raise doubts about the Chinese defector’s claims, suggesting that he has given little —if any information— that is genuinely new. Some argue that Mr. Wang is much too young to have been entrusted with senior-level responsibilities in the intelligence agency of a country that rarely promotes twenty-somethings in high-ranking positions. Additionally, Mr. Wang appears to have no military background —he claims to have been recruited while studying fine art— which is not typical of a Chinese military intelligence operative.

Furthermore, Mr. Wang episode interviewers from Australian television’s 60 Minutes program that he began feeling tormented by moral dilemmas when his staff officers supplied him with a fake passport bearing a different name, in preparation for an operation in Taiwan. However, by his own admission, Mr. Wang had been supplied with fake passports for previous operations, so it is not clear why he lost his nerve at the time he did. In fact, case officers usually covet the opportunity to go undercover and feel a sense of exhilaration when they receive fake identification documents for an undercover mission.

Is Mr. Wang not sharing the entire background to his decision to defect to Australia? Or could he be deliberately amplifying his role in Chinese intelligence, in an effort to appear useful to the Australian government and thus secure political protection by Canberra? In the words of Alex Joske, an analyst at the  International Cyber Policy Centre of the Australian Strategic Policy Institute, the details in some of Mr. Wang’s claims mean that “government investigations should uncover the facts eventually. But we don’t know the full story and we probably never will”.

► Author: Joseph Fitsanakis | Date: 26 September 2019 | Permalink

Chinese defector reveals identities of Chinese undercover spies in Asia and Australia

Wang LiqiangA Chinese intelligence defector has reportedly given the Australian government information about entire networks of Chinese undercover spies in Hong Kong, Taiwan and Australia, according to reports. The story of Wang “William” Liqiang, made headlines all over Australia during the weekend, culminating in an entire episode of 60 Minutes Australia about him airing on Sunday. The 26-year-old from China’s eastern Fujian province reportedly defected to Australia in October, while visiting his wife and newborn son, who live in Sydney. He is currently reported to be in a safe house belonging to the Australian Security Intelligence Organization (ASIO).

Police in the Chinese city of Shanghai claim that Mr. Wang is a small-time criminal who has been found guilty of using fraudulent documents and has a 15-month suspended prison sentence on his record. In a statement issued on Sunday, China’s embassy in Canberra described Mr. Wang as a “convicted fraudster” who was “wanted by police after fleeing [China] on a fake passport”. But according to reports in the Australian media, Mr. Wang has provided the ASIO with a 17-page sworn statement, in which he details his work as an undercover intelligence officer. He is also said to have shared the identities of senior Chinese intelligence officers in Taiwan and Hong Kong, and to have explained how they organize and implement espionage operations on behalf of Bejing.

In a leading article published on Saturday, The Sydney Morning Herald referred to Mr. Wang as “the first Chinese operative to ever blow his cover” and claimed that he had given the ASIO “a trove of unprecedented inside intelligence” about Chinese espionage operations in Southeast Asia. The newspaper said that the defector had revealed details about entire networks of Chinese intelligence operatives in Taiwan and Hong Kong. He also reportedly provided identifying information about deep-cover Chinese intelligence networks in Australia.

Meanwhile, in an unrelated development, Australian media said yesterday that the ASIO was examining allegations that a Chinese espionage ring tried to recruit an Australian businessman of Chinese background and convince him to run for parliament. According to reports, the spy ring approached Nick Zhao, a successful luxury car dealer, and offered to fund his political campaign with nearly $700,000 (AUS$1 million) if he run as a candidate for the Liberal Party of Australia. Zhao reportedly told the ASIO about the incident last year, shortly before he was found dead in a Melbourne hotel room. His death remains under investigation.

► Author: Joseph Fitsanakis | Date: 25 November 2019 | Permalink

FBI files espionage charges against California man who allegedly spied for China

Xuehua Edward PengThe United States has pressed espionage charges against a naturalized American citizen who operated as a courier for Chinese intelligence while working as a tour operator in California. On Monday federal prosecutors in San Francisco filed espionage charges against Xuehua “Edward” Peng, a 56-year-old Chinese-born American citizen. Peng, a trained mechanical engineer, reportedly entered the United States in June 2001 on a temporary visa. In 2012 he became a naturalized American citizen. By that time he was working for US Tour and Travel, an independent tour operator in California.

On Friday, officers with the Federal Bureau of Investigation arrested Peng at his home in Hayward, California, and charged him with spying on behalf of the Ministry of State Security (MSS), which is China’s primary external intelligence agency. At a press conference held on Monday, David Anderson, US Attorney for the Northern District of California, said that Peng began working for the MSS in June 2015 and continued to do so until June of 2018. Throughout that time, Peng participated in at least six dead drops on behalf of the MSS, said the FBI. But he was unaware that the agent on the other end of the dead drop was in fact an FBI informant, who had lured Peng and the MSS into an elaborate sting operation. The informant is referred to in the indictment as “the source”. The FBI said it paid the informant nearly $200,000 to facilitate the sting operation.

Most of the dead drops took place at a hotel in Newark, California. Peng would book a room in the hotel using a popular online booking service. He would check in and go to his hotel room, where he would hide envelopes containing as much as $20,000 in cash. He would then leave the room key at the front desk for his contact to pick up. The contact (the FBI informant) would pick up the key and the cash, and leave memory sticks with classified US government information for Peng to pick up. Peng would then travel to China to deliver the classified information to the MSS.

Unbeknownst to Peng, the FBI was monitoring him all along, and managed to secretly tape his alleged espionage activities. The surveillance footage is now part of the federal affidavit that was unsealed on Monday. Moreover, the FBI appears to have given Peng classified information that was approved for the purposes of the counterespionage operation against him. It is not known whether the classified information was real, deceptive, or a mixture of the two. It is worth noting that Peng is not a foreign diplomat and is therefore not subject to the rules of diplomatic immunity. He now faces a maximum of 10 years in prison and a fine of up to $250,000 if convicted.

► Author: Joseph Fitsanakis | Date: 01 October 2019 | Permalink

In unprecedented move, US plans to block undersea cable linking US with China

undersea telecommunications cableIn a move observers describe as unprecedented, a United States government regulator is preparing to recommend blocking the construction of an 8,000-mile long undersea cable linking America with China, allegedly due to national security concerns. Washington has never before halted the construction of undersea cables, which form the global backbone of the Internet by facilitating nearly 100% of Internet traffic. Much of the undersea cable network is in the process of being replaced by modern optical cables that can facilitate faster Internet-based communications than ever before.

One such scheme is the Pacific Light Cable Network (PLCN), an 8,000-mile undersea cable construction project funded by Google, Facebook and Dr. Peng Telecom & Media Group Co., one of China’s largest telecommunications-hardware manufacturers. The PLCN’s completion will produce the first-ever direct Internet link between Los Angeles and Hong Kong, and is expected to increase Internet speeds in both China and the United States. Most of the PLCN has been laid and its completion is projected for this year.

But now an American regulatory panel plans to recommend blocking the PLCN’s final construction phase. According to The Wall Street Journal, the panel fears that the $300 million undersea cable project may facilitate Chinese espionage. The Justice Department-led panel is known as Team Telecom and consists of officials from several American government agencies, said the paper, citing “individuals involved in the discussion” about PLCN.

Never before has the US blocked the construction of an undersea cable, reported The Journal. National security concerns have been raised with reference to past undersea cable projects, some of whom were partially funded by Chinese-owned companies. But the projects eventually went ahead after the manufacturers were able to demonstrate that the design of the undersea cables forbade the installation of wiretaps. If the PLCN project is blocked, therefore, it will be the first such case in the history of the Internet in America.

The paper said that supporters of the PLCN argue that it would give American government regulators more control over the security of Internet traffic before it even reaches US territory. Additionally, PLCN investors claim that the completion of the project will provide American companies with broader access to consumers in Asia. Google, Facebook, Dr. Peng Telecom and the US government declined to comment on the news report.

► Author: Joseph Fitsanakis | Date: 29 August 2019 | Permalink

Swiss to extradite brother of ‘leading biochemist’ who spied for Chinese firm

GlaxoSmithKlineA Swiss court has ordered the extradition to the United States of the brother of one of the world’s leading biochemists, who spied on a British pharmaceutical firm to help a Chinese startup. The extradition is part of a large corporate espionage case centered on Yu Xue, a Chinese scientist described by US federal prosecutors as “one of the world’s top protein biochemists”. Yu specializes in drug research for cancer and other serious terminal illnesses. From 2006 until 2016 he worked in the US for GlaxoSmithKline (GSK), a leading British pharmaceutical group.

In 2018, Yu was arrested by US authorities for stealing trade secrets from a GSK research facility in the US state of Pennsylvania, and giving them to a Chinese startup pharmaceutical company called Renopharma. He eventually pleaded guilty to stealing proprietary data from GSK, in a case that the US Department of Justice described as a textbook example of Chinese “economic warfare” against America. US government prosecutors also claim that Renopharma is almost wholly funded the Chinese government. The three co-founders of the Chinese firm have also been charged with corporate espionage targeting a US firm.

On May 28 Yu’s brother, Gongda Xue, was arrested in Basel, Switzerland. According to the US government, Gongda used GSK data stolen by his brother to carry out drug experimentation at the Friedrich Miescher Institute for Biomedical Research, where he worked as a post-doctoral trainee between 2008 and 2014. On Tuesday, the Swiss Federal Office of Justice (FOJ), ruled in favor of a request by the US government to extradite Gongda so he can be tried in Pennsylvaia. According to the FOJ, the Chinese scientist will be extradited as soon as his 30-day appeal period expires.

► Author: Ian Allen | Date: 17 July 2019 | Permalink

Poland frees on bail former intelligence officer arrested for spying for China

Orange PolskaThe Polish government has authorized the release on bail of a former counterintelligence officer who was charged in January of this year with spying for China. The man has been identified in media reports as Piotr Durbajlo and is believed to have served as deputy director of the Internal Security Agency, Poland’s domestic counterintelligence service. A cyber security expert, Durbajlo also served in Poland’s Office of Electronic Communications with a top security clearance and unrestricted access to classified systems of Poland and the North Atlantic Treaty Organization, of which Poland is a member.

However, at the time of his arrest on January 10, Durbajlo had left government service and was a mid-level executive at Orange Polska. The company operates as the Polish branch of a French multinational telecommunications carrier with sister companies in several European Union countries. Along with Durbajlo, Polish authorities arrested Wang Weijing, a Chinese national who worked for the Chinese telecommunications manufacturer Huawei. Orange Polska is Huawei’s main domestic partner in Poland. Wang reportedly learned Polish at the Beijing Foreign Studies University. In 2006 he was posted by the Chinese Ministry of Foreign Affairs at the Chinese consulate in Gdansk, Poland’s largest Baltic Sea port. In 2011 he left the Foreign Service and joined the Polish office of Huawei. Following his arrest on January 10, he was charged with espionage. Huawei denied it had any role in espionage against the Polish state, but fired Wang nonetheless. Both Wang and Durbajlo have been in pretrial detention since their arrest in January.

On Friday, July 5, Durbajlo’s legal team announced that he would be set free on July 7, on a $31,500 bail that must be paid within 30 days to secure his release. His lawyers explained that the charges against him had not been dropped, but did not explain why he was being released. It is worth noting that Durbajlo’s release on bail was announced during a visit to Poland by a high-level Chinese delegation, aimed at discussing economic and political ties between Warsaw and Beijing. Late on Tuesday it was announced that Wang would remain in pretrial detention for at least three more months.

► Author: Joseph Fitsanakis | Date: 10 July 2019 | Permalink

Attack by Chinese hacker group targeted high-profile individuals around the world

Operation SOFTCELLA hacker attack of impressive magnitude targeted specific individuals of interest to the Chinese government as they moved around the world, in what appears to be the first such operation in the history of cyberespionage. The attack was revealed late last month by Cybereason, an American cybersecurity firm based in Boston, Massachusetts. Company experts described the scope and length of the attack, dubbed Operation SOFTCELL, as a new phenomenon in state-sponsored cyberespionage. Cybereason said SOFTCELL has been in operation since at least 2017, and identified the culprit as APT10, a hacker group that is believed to operate on behalf of China’s Ministry of State Security.

The operation is thought to have compromised close to a dozen major global telecommunications carriers in four continents —the Middle East, Europe, Asia and Africa. According to Cybereason, the hackers launched persistent multi-wave attacks on their targets, which gave them “complete takeover” of the networks. However, they did not appear to be interested in financial gain, but instead focused their attention on the call detail records (CDRs) of just 20 network users. With the help of the CDRs, the hackers were able to track their targets’ movements around the world and map their contacts based on their telephone activity. According to The Wall Street Journal, which reported on Cybereason’s findings, the 20 targets consisted of senior business executives and government officials. Others were Chinese dissidents, military leaders, as well as law enforcement and intelligence officials.

An especially impressive feature of SOFTCELL was that the hackers attacked new telecommunications carriers as their targets moved around the world and made use of new service providers. The attacks thus followed the movements of specific targets around the world. Although this is not a new phenomenon in the world of cyberespionage, the geographical scope and persistence of the attacks are unprecedented, said The Wall Street Journal. Speaking last week at the 9th Annual International Cybersecurity Conference in Tel Aviv, Israel, Lior Div, Cybereason’s chief executive officer and co-founder, said SOFTCELL attacks occurred in waves over the course of several months. The hackers used a collection of techniques that are commonly associated with identified Chinese hacker groups. If detected and repelled, the hackers would retreat for a few weeks or months before returning and employing new methods. The Cybereason security experts said that they were unable to name the targeted telecommunications carriers and users “due to multiple and various limitations”.

► Author: Joseph Fitsanakis | Date: 09 July 2019 | Permalink

Despite spying allegations, African Union deepens ties with Chinese telecoms firm

African UnionDespite allegations in the French press that China has been spying for years on the internal communications of the African Union, the organization appears to be deepening its ties with a leading Chinese telecommunications firm. The allegations surfaced in January of last year in the Paris-based Le Monde Afrique newspaper. The paper claimed in a leading article that African Union technical staff found that the computer servers housed in the organization’s headquarters in Addis Ababa, Ethiopia, were secretly communicating with a server facility in Shanghai, China. The secret communications reportedly took place at the same time every night, namely between midnight and 2 in the morning. According to Le Monde Afrique, the African Union servers forwarded data to the servers in Shanghai from 2012, when the building opened its doors, until early 2017.

Beijing donated $200 million toward the project and hired the state-owned China State Construction Engineering Corporation to build the tower, which was completed in 2012. Since then, the impressive 330 feet, 19-storey skyscraper, with its reflective glass and brown stone exterior, has become the most recognizable feature of Addis Ababa’s skyline. The majority of the building material used to construct the tower was brought to Ethiopia from China. Beijing even paid for the cost of the furniture used in the impressive-looking building. The paper noted that, even though the organization was allegedly notified about the breach by its technical staff in January of 2017, there was no public reaction on record. However, according to Le Monde Afrique, African Union officials took immediate steps to terminate the breach. These included replacing the Chinese-made servers with new servers purchased with African Union funds, without Beijing’s mediation. Additionally, new encryption was installed on the servers, and a service contract with Ethio Telecom, Ethiopia’s state-owned telecommunications service provider, which uses Chinese hardware, has been terminated.

Last week, however, the African Union deepened its ties with Huawei Technologies, the Chinese telecommunications firm that provided all the hardware, as well as much of the software, used in the organization’s headquarters. Last week, at a meeting in the Ethiopian capital, Thomas Kwesi Quartey, deputy chair of the African Union’s Commission signed a memorandum of understanding with Philippe Wang, Huawei’s vice president for North Africa. According to the memorandum, Huawei will increase its provision of hardware and services to the African Union “on a range of technologies”. These range from broadband telecommunications to cloud computing, as well as 5G telecommunications capabilities and artificial intelligence systems. The Chinese firm will also continue to train African Union information technology and telecommunications technicians. Both the African Union and the government of China have denied the Le Monde Afrique allegations.

► Author: Joseph Fitsanakis | Date: 07 June 2019 | Permalink

German spies dismiss US warnings about Huawei threat to 5G network

Huawei 2German intelligence officials appear to be dismissing Washington’s warning that it will limit security cooperation with Berlin if China’s Huawei Telecommunications is allowed to build Germany’s 5G network. The company, Huawei Technologies, is a private Chinese venture and one of the world’s leading telecommunications hardware manufacturers. In recent years, however, it has come under scrutiny by some Western intelligence agencies, who view it as being too close to the Communist Party of China. More recently, Washington has intensified an international campaign to limit Huawei’s ability to build the infrastructure for 5G, the world’s next-generation wireless network. Along with Britain, Australia and Canada, the US is concerned that the Chinese telecommunications giant may facilitate global wiretapping on behalf of Beijing’s spy agencies.

In the past several months the United States has repeatedly warned Germany that intelligence sharing between the two countries will be threatened if the Chinese telecommunications giant is awarded a 5G contract by the German government. In March, Washington informed German officials that intelligence cooperation between the two allies would be severely impacted if Chinese telecommunications manufacturers were given the green light to build Germany’s 5G infrastructure. The warning was allegedly included in a letter to Peter Altmaier, Germany’s Minister of Economic Affairs and Energy, written by Ambassador Richard Grenell, America’s top diplomat in Germany. The letter urged the German government to consider rival bids by companies belonging to American allies, such as the Swedish telecommunications equipment manufacturer Ericsson, Finland’s Nokia Corporation, or the South Korean Samsung Corporation.

But a report by Bloomberg on Wednesday said that German authorities were not convinced by Grenell’s argument. Citing “four people with knowledge on the matter”, the news agency said that Germany’s intelligence community see Washington’s warnings as “political grandstanding”. The US and Germany “need each other’s resources to tackle global conflicts” and “rely on each other too much to risk jeopardizing crucial data sharing”, said the report. The anonymous officials told Bloomberg that Germany does benefit from America’s “vast array” of intelligence. However, German spy agencies also provide their American counterparts with crucial intelligence from several regions of the world, they said. The US Department of State did not comment on the Bloomberg report. The Chinese government has repeatedly dismissed allegations that Huawei poses an espionage threat to Western nations.

► Author: Ian Allen | Date: 18 April 2019 | Permalink