German magazine reveals more information on elite NSA spy unit
January 1, 2014 Leave a comment
By JOSEPH FITSANAKIS | intelNews.org
Last June, we reported on the existence of an elite cyberatack unit within the United States National Security Agency (NSA), which operates under the Agency’s Office of Tailored Access Operations. Veteran NSA watcher Matthew M. Aid, who made the initial revelation, said at the time that the Office, known at NSA simply as TAO, maintains a substantial “hacker army” that works in close cooperation with the Central Intelligence Agency (CIA) and the Federal Bureau of Investigation (FBI). Now German newsmagazine Der Spiegel says it viewed internal documents that confirm the existence of TAO as the NSA’s elite operational unit. The publication describes TAO as “something like a squad of plumbers that can be called in when normal access to a target is blocked”. It adds that TAO operatives are routinely detailed to a host of American intelligence agencies to help conduct intelligence operations ranging from traditional espionage to counterterrorism and cyberwarfare. Furthermore, TAO’s personnel, which are allegedly far younger than the average NSA officer, are experts in exploiting the technical deficiencies of the information-technology industry. They have therefore been able to compromise communications hardware and software produced by some of the world’s biggest IT companies and service providers, including Huawei, Cisco and Microsoft. The Spiegel article claims that TAO was established in 1997, several years before the Internet became a prominent engine of economic and cultural activity around the world. Its personnel, which initially consisted of a few select technical experts, was housed at the NSA headquarters in Fort George Meade, Maryland, but “in a separate wing, set apart from the rest of the agency”. Notably, Der Spiegel cites a paper produced by a former TAO unit head, which states that the program has produced “some of the most significant intelligence our country has ever seen” and urges for its continued growth. Read more of this post







By TIMOTHY W. COLEMAN | intelNews.org |










The mysterious Chinese unit behind the cyberespionage charges
May 20, 2014 by Joseph Fitsanakis 2 Comments
On Monday, the United States government leveled for the first time charges against a group of identified Chinese military officers, allegedly for stealing American trade secrets through cyberespionage. The individuals named in the indictment are all members of a mysterious unit within the Chinese People’s Liberation Army (PLA) command structure, known as Unit 61398. It is estimated that the unit has targeted at least 1,000 private or public companies and organizations in the past 12 years. Western cybersecurity experts often refer to the group as “APT1”, which stands for “Advanced Persistent Threat 1”, or “Byzantine Candor”. It is believed to operate under the Second Bureau of the PLA’s General Staff Department, which is responsible for collecting foreign military intelligence. Many China military observers argue that Unit 61398 is staffed by several thousand operatives, who can be broadly categorized into two groups: one consisting of computer programmers and network operations experts, and the other consisting of English-language specialists, with the most talented members of the Unit combining both skills. Computer forensics experts have traced the Unit’s online activities to several large computer networks operating out of Shanghai’s Pudong New Area district, a heavily built neighborhood in China’s largest city, which serves as a symbol of the country’s rapid industrialization and urbanization. Among other things, Unit 61398 is generally accused of being behind Operation SHADY RAT, one of history’s most extensive known cyberespionage campaigns, which targeted nearly 100 companies, governments and international organizations, between 2006 and 2011. The operation is believed to be just one of numerous schemes devised by Unit 61398 in its effort to acquire trade secrets from nearly every country in the world during the past decade, say its detractors. American sources claim that the PLA Unit spends most of its time attacking private, rather than government-run, networks and servers. As the US Attorney General, Eric Holder, told reporters on Monday, Unit 61398 conducts hacking “for no reason other than to advantage state-owned companies and other interests in China, at the expense of businesses here in the United States”. But The Washington Post points out that the recent revelations by US intelligence defector Edward Snowden arguably make it “easier for China to dismiss” Washington’s charges, since they point to Read more of this post
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with Advanced Persistent Threat 1, Analysis, Byzantine Candor, China, Chinese People's Liberation Army, computer hacking, cyberespionage, economic espionage, News, operation SHADY RAT, Unit 61398