Showing posts with label Chinese Treachery. Show all posts
Showing posts with label Chinese Treachery. Show all posts

Saturday, 2 March 2013

Chinese trader accused of busting Iran missile embargo

Washington: A Chinese businessman indicted in the United States over sales of missile parts to Iran is still making millions of dollars from the trade, say security officials who monitor compliance with Western and U.N. sanctions.  These officials, speaking on condition of anonymity, said the businessman, Li Fangwei, has earned at least $10 million from illegal sales to Iran since his indictment by the New York County District Attorney in 2009. Trade sanctions are at the heart of international efforts to curb Iran’s nuclear programme for fear it is for military ends - a suspicion Iran rejects. Li’s alleged activities may point to Iran’s resourcefulness in circumventing those sanctions and turn a spotlight on China’s ability to police its own export restrictions.

It is hard to quantify the contribution of foreign firms and individuals to Iran’s nuclear and missile programmes, but analysts believe some vital components are all but impossible for Tehran to produce at home.  Contacted by Reuters on Feb 4, Li said he continued to get commercial inquiries from Iran but only for legitimate merchandise, such as steel products. Li said his company, LIMMT, had stopped selling to Iran once the United States began sanctioning it several years ago.

He dismissed allegations by the security officials that he had used deception, including changes of company names, to supply Iran with Chinese and foreign-made parts such as high-grade alloys that can be used to enrich uranium and guidance devices suitable for missiles. “Sure, we did business with Iran, but we did not export the goods they said we did, missiles or whatever,” Li said. “We still get inquiries from Iranian clients, but we don’t respond to them.”

A Chinese Foreign Ministry spokeswoman said Beijing was adhering to trade restrictions, including a U.N. ban on helping Iran build missiles that can deliver nuclear warheads. Officials from Iran, including at firms the security officials said were clients of Li and at the embassy in Beijing, did not respond to requests for comment. A Chinese bank which the security officials said Li used for Iranian business denied it had breached U.N. sanctions.

In 2006, the US Treasury barred Li from the US financial system for allegedly selling goods with potential military uses to Iran.

Three years later, the New York County District Attorney unsealed a fraud indictment against Li and his metals company LIMMT on suspicion they had used false names to process further payments for sales to Iran through several US banks. The US banks employed by Li were innocent of any wrongdoing because Li and other suspects had concealed their identities, the then District Attorney, Robert Morgenthau, said. On Feb 4, 2013, Li said that at the time of the indictment he had felt there was no point in saying anything because US courts and prosecutors “don’t listen to reason. It’s useless.”

Three weeks ago, on Feb. 11, the US State Department issued fresh sanctions against Li, saying he had “engaged in missile technology proliferation activities that require the imposition of missile sanctions”, and placing additional restrictions on any missile technology trade involving him.

A State Department official said Li had been sanctioned because of his “proliferation to Iran” since his 2009 indictment. Li did not respond to calls seeking comment on the Feb 11 action.

China reacted with irritation to the Feb. 11 measures. Foreign Ministry spokeswoman Hua Chunying said the US step “seriously violates the norms of international relations and harms China’s interests” and urged the United States to immediately revoke “these irrational sanctions”.

China has no extradition treaty with Washington.

The security officials allege that since the 2009 indictment Li, working in concert with the Iranian embassy in Beijing, had supplied parts to firms that make Iranian missiles, in particular the U.N.-blacklisted Shahid Bakeri Industrial group (SBIG). SBIG did not reply to faxes and emails sent by Reuters for comment.

The goods allegedly supplied included 15 tonnes of high-grade aluminium alloy, more than 20 tonnes of ultra-high strength steel, and 1,700 kg of graphite cylinders. agencies

Wednesday, 27 February 2013

Communist Party of China and Peoples Oppression Army supply FN-6 MANPAD of the Free Syria Army

One one side Communist Party of China and Peoples Oppression Army support Bashar Al-Assad, on another side Communist Party of China and Peoples Oppression Army supply Free Syrian Army with MANPADS ;)  Strange power China

China likes to play both sides for profit. Chinese external agency Ministry of State Security has become a bidder in the global arms black market.











Chinese Peoples Oppression Army cyber hacking attacks

Technology terrorism from Peoples liberation Army and Communist party of China



Thursday, 21 February 2013

China copies and reverse engineers Israel's Harpy UAV

Back in 2005, under pressure from the US, IAI returned the Chinese Harpy UAV without performing any upgrades.

http://www.defenseindustrydaily.com/a-harpy-compromise-0612/

PLA seems to have Shanzhai-ed the Harpy UAV


The actual IAI Harpy





Tuesday, 19 February 2013

BBC reporter detained investigating China's military secretive branch of Hacking

The Chinese want to know everything about others but do not want others to know anything about them.Selfish????




In a drab Shanghai office block, Unit 61398, China’s cyber rats

http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf 

New found wealth has got a lot of confidence to Communist Party of China. They officially lie and deny all these " allegations"

Chinese communist Party closes its own citizens from free information flow over the internet but uses it for hacking others networks.

Mandiant claims Unit 61398:
  • Employs hundreds, perhaps thousands of personnel
  • Requires personnel trained in computer security and computer network operations
  • Requires personnel proficient in the English language
  • Has large-scale infrastructure and facilities in the Pudong New Area of Shanghai
  • Was the beneficiary of special fibre optic communication infrastructure provided by state-owned enterprise China Telecom in the name of national defence.


This 12-story building on the outskirts of Shanghai is the headquarters of Unit 61398 of the People’s Liberation Army. China’s defense ministry has denied that it is responsible for initiating digital attacks



 


-->
An explosive security report has pinned the majority of China-based attacks against the US to an army of hackers working for the People's Liberation Army out of a nondescript building on the outskirts of Shanghai. The report, by security firm Mandian, claims P.L.A Unit 61398 operates out of the complex and is responsible for a deluge of hacking traffic originating in and around it.Members of an infamous group known in most instances as Comment Crew or Shanghai Group were allegedly tracked to the P.L.A unit and the building.
It said public accounts of data breaches against US security firms, critical infrastructure, and industrial control system and SCADA operators to a persistent and government-backed hacking outfit operating out of the white Shanghai apartment block. "We believe that organisations in all industries related to China’s strategic priorities are potential targets of APT1’s (the group) comprehensive cyber espionage campaign," ther report stated. "While we have certainly seen the group target some industries more heavily than others, our observations confirm that APT1 has targeted at least four of the seven strategic emerging industries that China identified in its 12th Five Year Plan."
Mandiant researchers correlated data IP addresses, toolsets and social engineering information to pin the attacks to the hacking group. Beijing deniedthe accusations to the New York Times, and reiterated its affirmation that it is not involved in hacking which it considers illegal.
Chinese hackers have left a trail of victims including SCADA software outfits Telvent and Digital Bond, and security firm Alient Vault which had links to sensitive information on the US' defensive preparedness against hacking, according to the report.Hackers were also involved in the Shady Rathacking campaign which was billed as a massive global espionage attack that hit some 75 organisations, the report said. APT1 is one of scores of such collectives researchers say operate out of China at the behest of Beijing. It started operating and first came to the public light in 2006 when Symantec's Japan office described a host which was operated by a hacker known as Ugly Gorilla, who was tracked in the research.
"APT1 has a well-defined attack methodology, honed over years and designed to steal massive quantities of intellectual property. They begin with aggressive spear phishing, proceed to deploy custom digital weapons, and end by exporting compressed bundles of files to China – before beginning the cycle again," the report stated.They employ good English — with acceptable slang — in their socially engineered emails. They have evolved their digital weapons for more than seven years, resulting in continual upgrades as part of their own software release cycle. Their ability to adapt to their environment and spread across systems makes them effective in enterprise environments with trust relationships."
APT1 typically established a foothold in organisations via a well-written spear phishing attempt containing malicious pdf files within a compressed zip. It also used custom backdoors, thought to be previously unknown, of which 42 families were detailed by Mandiant."We usually detect multiple families of APT1 backdoors scattered around a victim network when APT1 has been present for more than a few weeks," the report said. The group's average infiltration lasted 356 days, with the longest stretching to four years and 10 months. The most amount of data stolen from a single organisation was 6.5 terabytes, extracted over 10 months.
The group was also unique in that it utilised unique attack vectors including GETMAIL which helped to steal email. Once the attackers compromised a network they were difficult to detect, the report said, because they connected to shared resources and could execute commands on other systems using Microsoft's psexec tool or Windows Task Scheduler."These actions are hard to detect because legitimate system administrators also use these techniques to perform actions around the network."


Thursday, 14 February 2013

Profile of a Chinese Hacker working for the Chinese Military PLA and Chinese Communist Party

http://cyb3rsleuth.blogspot.com/2013/02/chinese-threat-actor-4.html

Currently they are on holiday for the Chinese new year and will be back in Chinese communist Party offices all over China.

US, Taiwan, Japan, Philippines, Vietnam, Mongolia, India, Lao, Burma, Russia, South Korea, Ukraine, Kyrgyzstan, Tajikistan, Kazakhstan, Tibetians in exile, Xingjiang all are being targeted

Profiled here is Zhang Changhe  who is a teacher at the PLA Information Engineering University is in Zhengzhou ;)

Kaixin001.com, a Chinese Facebook-style site, to a Zhang Changhe in Zhengzhou. Zhang’s profile image on Kaixin is of a blooming lotus, a traditional Buddhist symbol. Going back to the QQ account, Cyb3rsleuth found a blog linked to it, again with a Buddha-themed profile picture, whose user went by Changhe—the same pronunciation as the Kaixin user’s given name, though rendered in different characters. The blog contained musings on Buddhist faith, including this, from a post written in Chinese and titled “repentance”: “It’s Jan. 31, 2012 today, I’ve been a convert to Buddhism for almost five years. In the past five years, I broke all the Five Precepts—no killing living beings, no stealing, no sexual misconduct, no lies, and no alcohol, and I feel so repentant.” Amid his list of sins, from lack of sympathy to defensiveness to lying, is No. 4: “I continuously and shamelessly stole, hope I can stop in the future.”

Underlined is the confession

The papers identified Zhang as working at the PLA Information Engineering University. The institution is one of China’s principal centers for electronic intelligence, where professors train junior officers to serve in operations throughout China
It’s as if the U.S. National Security Agency had a university.


Gate to the PLA Information Engineering University:CHINESE HACKERS CRADLE
Central Plains Communications Digital City in Zhengzhou: It is from these obscure buildings that the Chinese hackers steal technological,government and defense secrets

So called "Tawnya Grilth" living in Sin Digoo(San Diego) claims to be a Buddhist who has never stolen on his home page
http://www.businessweek.com/articles/2013-02-14/a-chinese-hackers-identity-unmasked#r=rss

Joe Stewart’s day starts at 6:30 a.m. in Myrtle Beach, S.C., with a peanut butter sandwich, a sugar-free Red Bull, and 50,000 or so pieces of malware waiting in his e-mail in-box. Stewart, 42, is the director of malware research at Dell SecureWorks, a unit of Dell (DELL), and he spends his days hunting for Internet spies. Malware is the blanket term for malicious software that lets hackers take over your computer; clients and fellow researchers constantly send Stewart suspicious specimens harvested from networks under attack. His job is to sort through the toxic haul and isolate anything he hasn’t seen before: He looks for things like software that can let hackers break into databases, control security cameras, and monitor e-mail.
Within the industry, Stewart is well-known. In 2003 he unraveled one of the first spam botnets, which let hackers commandeer tens of thousands of computers at once and order them to stuff in-boxes with millions of unwanted e-mails. He spent a decade helping to keep online criminals from breaking into bank accounts and such. In 2011, Stewart turned his sights on China. “I thought I’d have this figured out in two months,” he says. Two years later, trying to identify Chinese malware and develop countermeasures is pretty much all he does.
Computer attacks from China occasionally cause a flurry of headlines, as did last month’s hack on the New York Times (NYT). An earlier wave of media attention crested in 2010, when Google (GOOG) and Intel (INTC) announced they’d been hacked. But these reports don’t convey the unrelenting nature of the attacks. It’s not a matter of isolated incidents; it’s a continuous invasion.

Malware from China has inundated the Internet, targeting Fortune 500 companies, tech startups, government agencies, news organizations, embassies, universities, law firms, and anything else with intellectual property to protect. A recently prepared secret intelligence assessment described this month in the Washington Post found that the U.S. is the target of a massive and prolonged computer espionage campaign from China that threatens the U.S. economy. With the possible exceptions of the U.S. Department of Defense and a handful of three-letter agencies, the victims are outmatched by an enemy with vast resources and a long head start.
Stewart says he meets more and more people in his trade focused on China, though few want that known publicly, either because their companies have access to classified data or fear repercussions from the mainland. What makes him unusual is his willingness to share his findings with other researchers. His motivation is part obsession with solving puzzles, part sense of fair play. “Seeing the U.S. economy go south, with high unemployment and all these great companies being hit by China … I just don’t like that,” he says. “If they did it fair and square, more power to them. But to cheat at it is wrong.”

 Stewart tracks about 24,000 Internet domains, which he says Chinese spies have rented or hacked for the purpose of espionage. They include a marketing company in Texas and a personal website belonging to a well-known political figure in Washington. He catalogs the malware he finds into categories, which usually correspond to particular hacking teams in China. He says around 10 teams have deployed 300 malware groups, double the count of 10 months ago. “There is a tremendous amount of manpower being thrown at this from their side,” he says.

Investigators at dozens of commercial security companies suspect many if not most of those hackers either are military or take their orders from some of China’s many intelligence or surveillance organizations. In general, they say the attacks are too organized and the scope too vast to be the work of freelancers. Secret diplomatic cables published by WikiLeaks connected the well-publicized hack of Google to Politburo officials, and the U.S. government has long had classified intelligence tracing some of the attacks to hackers linked to the People’s Liberation Army (PLA), according to former intelligence officials. None of that evidence is public, however, and China’s authorities have for years denied any involvement.
Up to now, private-sector researchers such as Stewart have had scant success putting faces to the hacks. There have been faint clues left behind—aliases used in domain registrations, old online profiles, or posts on discussion boards that give the odd glimpse of hackers at work—but rarely an identity. Occasionally, though, hackers mess up. Recently, one hacker’s mistakes led a reporter right to his door.

Stewart works in a dingy gray building surrounded by a barbed-wire fence. A small sign on a keycode-locked door identifies it as Dell SecureWorks. With one other researcher, Stewart runs a patchwork of more than 30 computers that fill his small office. As he examines malware samples, he shifts between data-filled screens and white boards scribbled with technical terms and notes on Chinese intelligence agencies.

The computers in his office mostly run programs he wrote himself to dissect and sort the malware and figure out whether he’s dealing with variations of old code or something entirely new. As the computers turn up code, Stewart looks for signature tricks that help him identify the work of an author or a team; software writers compare it with the unique slant and curlicues of individual handwriting. It’s a methodical, technical slog that would bore or baffle most people but suits Stewart. He clearly likes patterns. After work, he relaxes with a 15-minute session on his drum kit, playing the same phrase over and over.

A big part of Stewart’s task is figuring out how malware is built, which he does to an astonishing level of detail. He can tell the language of the computer on which it was coded—helping distinguish the malware deployed by Russian criminal syndicates from those used by Chinese spies. The most important thing he does, however, is figure out who or what the software is talking to. Once inside a computer, malware is set up to signal a server or several servers scattered across the globe, seeking further marching orders. This is known in the information security business as “phoning home.” Stewart and his fellow sleuths have found tens of thousands of such domains, known as command and control nodes, from which the hackers direct their attacks.
Discovery of a command node spurs a noticeable rise in pitch in Stewart’s voice, which is about as much excitement as he displays to visitors. If a company getting hacked knows the Internet Protocol (IP) address of a command node, it can shut down all communication with that address. “Our top objective is to find out about the tools and the techniques and the malware that they’re using, so we can block it,” Stewart says.

The Internet is like a map, and every point—every IP—on that map belongs to someone with a name and an address recorded in its registration. Spies, naturally, tend not to use their real names, and with most of the Internet addresses Stewart examines, the identifying details are patently fake. But there are ways to get to the truth.
In March 2011, Stewart was examining a piece of malware that looked different from the typical handiwork of Russian or Eastern European identity thieves. As he began to explore the command nodes connected to the suspicious code, Stewart noticed that since 2004, about a dozen had been registered under the same one or two names—Tawnya Grilth or Eric Charles—both listing the same Hotmail account and usually a city in California. Several were registered in the wonderfully misspelled city of Sin Digoo.

Some of the addresses had also figured in Chinese espionage campaigns documented by other researchers. They were part of a block of about 2,000 addresses belonging to China Unicom (CHU), one of the country’s largest Internet service providers. Trails of hacks had led Stewart to this cluster of addresses again and again, and he believes they are used by one of China’s top two digital spying teams, which he calls the Beijing Group. This is about as far as Stewart and his fellow detectives usually get—to a place and a probable group, but not to individual hackers. But he got a lucky break over the next few months.

Tawnya Grilth registered a command node using the URL dellpc.us. It was a little too close to the name of Stewart’s employer. So Stewart says he contacted Icann (the Internet Corporation for Assigned Names and Numbers), the organization that oversees Internet addresses and arbitrates disputes over names. Stewart argued that by using the word Dell, the hackers had violated his employer’s trademark. Grilth never responded, and Icann agreed with Stewart and handed over control of the domain. By November 2011 he could see hacked computers phoning home from all over the world—he was watching an active espionage campaign in progress.


He monitored the activity for about three months, slowly identifying victim computers. By January 2012, Stewart had mapped as many as 200 compromised machines across the globe. Many were within government ministries in Vietnam, Brunei, and Myanmar, as well as oil companies, a newspaper, a nuclear safety agency, and an embassy in mainland China. Stewart says he’d never seen such extensive targeting focused on these countries in Southeast Asia. He broadened his search of IP addresses registered either by Tawnya Grilth or “her” e-mail address, jeno_1980@hotmail.com, and found several more. One listed a contact with the handle xxgchappy. The new addresses led to even more links, including discussion board posts on malware techniques and the website rootkit.com, a malware repository where researchers study hacking techniques from all over the world.
Then Stewart discovered something much more unusual: One of the domains hosted an actual business—one that offered, for a fee, to generate positive posts and “likes” on social network sites such as Twitter and Facebook (FB). Stewart found a profile under the name Tawnya on the hacker forum BlackHatWorld promoting the site and a PayPal (EBAY) account that collected fees and funneled them to a Gmail account that incorporated the surname Zhang. Stewart was amazed that the hacker had exposed his or her personal life to such a degree.
In February 2012, Stewart published a 19-page report on SecureWorks’s website to coincide with the RSA Conference in San Francisco, one of the biggest security industry events of the year. He prefaced it with an epigraph from Sun Tzu’s The Art of War: “We cannot enter into informed alliances until we are acquainted with the designs of our neighbors and the plans of our adversaries.”


Stewart didn’t pursue Zhang. His job was done. He learned enough to protect his customers and moved on to the other countless bits of malware. But his report generated interest in the security world, because it’s so difficult to find any traces of a hacker’s identity. In particular, Stewart’s work intrigued another researcher who immediately took up the challenge of unmasking Tawnya Grilth. That researcher is a 33-year-old who blogs under the name Cyb3rsleuth, an identity he says he keeps separate from his job running an India-based computer intelligence company. He asked that his name not be used to avoid unwanted attention, including hacking attempts on his company.

Cyb3rsleuth says he’d already found a calling in outing the identities of Eastern European hackers and claims to have handed over information on two individuals to government authorities. Stewart’s work inspired him to post his findings publicly, and he says he hopes that unearthing more details on individual hackers will give governments the evidence to take action. The hackers are human and make mistakes, so the trick is finding the connection that leads to a real identity, Cyb3rsleuth says.
As Stewart’s new collaborator dug in, the window into Tawnya Grilth’s world expanded. There were posts on a car forum; an account on a Chinese hacker site; and personal photos, including one showing a man and a woman bundled up against the wind at what looked like a tourist site with a pagoda in the background.

Cyb3rsleuth followed the trail of the hacker’s efforts to drum up business for the social media promotion service through aliases and forums tied to the Hotmail account. He eventually stumbled on a second business, this one with a physical location. The company, Henan Mobile Network, was a mobile-phone wholesaler, according to business directories and online promotional posts. The shop’s website was registered using the Jeno Hotmail account and the Eric Charles pseudonym.

Cyb3rsleuth checked an online Chinese business directory for technology companies and turned up not only a telephone number for the company but also a contact name, Mr. Zhang, and an address in Zhengzhou, a city of more than 8 million in the central Chinese province of Henan. The directory listing gave three account numbers for the Chinese instant-messaging service called QQ. The service works along the lines of MSN Messenger, with each account designated by a unique number. One of those accounts used an alternate e-mail that incorporated the handle xxgchappy and listed the user’s occupation as “education.”

Putting that e-mail into Chinese search engines, Cyb3rsleuth found it was also registered on Kaixin001.com, a Chinese Facebook-style site, to a Zhang Changhe in Zhengzhou. Zhang’s profile image on Kaixin is of a blooming lotus, a traditional Buddhist symbol. Going back to the QQ account, Cyb3rsleuth found a blog linked to it, again with a Buddha-themed profile picture, whose user went by Changhe—the same pronunciation as the Kaixin user’s given name, though rendered in different characters. The blog contained musings on Buddhist faith, including this, from a post written in Chinese and titled “repentance”: “It’s Jan. 31, 2012 today, I’ve been a convert to Buddhism for almost five years. In the past five years, I broke all the Five Precepts—no killing living beings, no stealing, no sexual misconduct, no lies, and no alcohol, and I feel so repentant.” Amid his list of sins, from lack of sympathy to defensiveness to lying, is No. 4: “I continuously and shamelessly stole, hope I can stop in the future.”

The same QQ number appears on an auto forum called xCar, where the user is listed as belonging to a club for owners of the Dongfeng Peugeot 307—a sporty four-door popular among China’s emerging middle class—and where the user asked, circa 2007, about places to buy a special license-plate holder. In a photo taken in 2009, Zhang stands on a beach, squinting into the sun with his back to the waves, arm in arm with a woman the caption says is his wife—the same person as in the pagoda picture. His bushy hair is cut short over a young face.
In March, Cyb3rsleuth published what he found on his personal blog, hoping that someone—governments, the research community, or some of the many hacking victims—would act. He knows of no response so far. Still, he’s excited. He’d found the face of a ghost, he says.

The city of Zhengzhou sprawls near the Yellow River in Henan province. The municipal government website describes it as “an example of a remarkably fast-changing city in China (without minor tourism clutter).” Kung-fu fans pass through on their way to the Shaolin Temple, a center of Buddhism and martial arts, 56 miles to the southwest. The city mostly serves as a gigantic transit hub for people and goods moving by rail to other places all over China.

About a 500-meter walk south from the central railway station is a tan, seven-story building with a dirty facade and red characters that read Central Plains Communications Digital City. The building is full of tiny shops, many selling electronics. The address listed for Zhang’s mobile-phone business is on the fourth floor, room A420.

Under dim fluorescent lights, two young clerks tell a reporter that they don’t know Zhang Changhe or Henan Mobile Network. The commercial manager of the building, Wang Yan, says the previous tenant of A420 moved out three years ago; she says she has no idea what the business had been, except that the proprietors weren’t there very often and that the operation didn’t last long.
A Chinese-language search on Google turns up a link to several academic papers co-authored by a Zhang Changhe. One, from 2005, relates to computer espionage methods. He also contributed to research on a Windows rootkit, an advanced hacking technique, in 2007. In 2011, Zhang co-authored an analysis of the security flaws in a type of computer memory and the attack vectors for it. The papers identified Zhang as working at the PLA Information Engineering University. The institution is one of China’s principal centers for electronic intelligence, where professors train junior officers to serve in operations throughout China, says Mark Stokes of the Project 2049 Institute, a think tank in Washington. It’s as if the U.S. National Security Agency had a university.

The gated campus of the PLA Information Engineering University is in Zhengzhou, about four miles north of Zhang Changhe’s mobile shop. The main entrance is at the end of a tree-lined lane, and uniformed men and women come and go, with guards checking vehicles and identification cards. Reached on a cell-phone number listed on the QQ blog, Zhang confirms his identity as a teacher at the university, adding that he was away from Zhengzhou on a work trip. Asked if he still maintained the Henan Mobile telephone business, he says: “No longer, sorry.” About his links to hacking and the command node domains, Zhang says: “I’m not sure.” About what he teaches at the university: “It’s not convenient for me to talk about that.” He denies working for the government, says he won’t answer further questions about his job, and hangs up.

Stewart continues to uncover clues that point to Zhang’s involvement in computer network intrusions. A piece of malware SecureWorks discovered last year and dubbed Mirage infected more than 100 computers, mainly in Taiwan and the Philippines. Tawnya Grilth owned one of the command domains. Late last year, Stewart was looking at malware hitting Russian and Ukrainian government and defense targets. The only other sample of that kind of malware he could find in his database was one that phoned home to a command node at AlexaUp.info. The billing name used in the registration: Zhang Changhe. Stewart says Zhang is affiliated with the Beijing Group, which probably involves dozens of people, from programmers to those handling the infrastructure of command centers to those who translate stolen documents and data. As Stewart discusses this, his voice is flat. He’s realistic.

Outing one person involved in the hacking teams won’t stop computer intrusions from China. Zhang’s a cog in a much larger machine and, given how large China’s operations have become, finding more Zhangs may get easier. Show enough of this evidence, Stewart figures, and eventually the Chinese government can’t deny its role. “It might take several more years of piling on reports like that to make that weight of evidence so strong that it’s laughable, and they say, ‘Oh, it was us,’ ” says Stewart. “I don’t know that they’ll stop, but I would like to make it a lot harder for them to get away with it.”

Wednesday, 13 February 2013

Chinese Troop Movements Signal War? Taiwan, Japan and South Korea targets?





Surely Chinese cannot be moving tanks around during the period of the Chinese new year celebrations just like that for fireworks shows?

Tanks, one by one, moving along a main road in China’s coastal Fujian province. Driving up speculations that the Chinese military may be warming up for war. Local residents took these pictures between February 3 to February 6. At times, the line of tanks and artillery blocked traffic for several miles. And it wasn’t just in Fujian province. These military vehicles were spotted further up the coast, in neighboring Zhejiang province. According to dissident website, molihua.org, these tanks in Hubei province are being transported from a military base to the coast. The troop movements come after months of escalating tensions between China and Japan over the disputed territory of the Diaoyun, or Senkaku islands and they’re known in Japan. It’s caused international worries that the two countries may be on the cusp of war. Both sides have scrambled jets and warships in the region. In January, during naval exercise near the disputed waters, Chinese warships reportedly directed their targeting radar at a Japanese vessel. On February 7, State-run Global Times published this article saying there is a “serious possibility” a military conflict may flare up between China and Japan. It continues to say that fewer and fewer people are hopeful for a peaceful resolution to the Diaoyu Island crisis. Are we in a countdown to war between China and Japan? NTD will continue to keep you posted as the situation develops.


Friday, 8 February 2013

China's one-child policy creates wimpy military recruits, deserters

In March 2011, Xuexi Shibao (Study Times), the organ of the Central Party School that teaches party ideology, ran an article that said, "Soldiers from the one-child generation are wimps who have absolutely no fighting spirit." 

The one-child pampered children began quitting the military for all sorts of frivolous reasons. "I don't want to get a tan" and "I hate military quarters with no air conditioning" were among excuses cited.

Chinese soldiers engages in widespread gambling
http://ajw.asahi.com/article/asia/china/AJ201302060009 

The emergency notice issued by police in Jilin province gives a physical description of the four deserters as well as a warning that they may be ready to commit a crime


CAOSHI, China--While China's military prowess has long been a source of concern for other nations, there are signs that all is not well within the armed forces.
The posturing by China on the Senkaku Islands issue, for instance, suggests a state of readiness that could result in a call to arms at a moment's notice.
But an incident in late 2011 that was never publicly disclosed by China but uncovered by The Asahi Shimbun suggests the central leadership is being forced to re-evaluate recruitment to the People's Liberation Army/Navy.

The facts of the matter are this: Four soldiers deserted from their unit armed with automatic weapons and stolen ammo. A dragnet was set up and a fatal shootout followed. It emerged that the soldiers had racked up sizable gambling debts and armed themselves so they could rob a bank and become solvent again.

But as often happens in reporting on China, the gravity of the situation faced by security authorities at the time was not immediately apparent until long afterward.
On the morning of Nov. 9, 2011, police in Jilin province, northeastern China, issued an emergency notice to all financial institutions in the province.
It said, "Four soldiers armed with model 95 automatic rifles have stolen 795 rounds of ammunition and deserted their unit."

The soldiers, aged between 19 and 24, belonged to a unit based in Jilin city. Photos of the four men, along with their physical characteristics, were issued.
The notice went on to say, "Contact the police if you have any information."
The four deserted from their base early that morning and were trapped by police some eight hours later when they were stopped at an expressway toll booth in Caoshi town of Fushun city, about 200 kilometers from their base.
A booth worker, recalling that day, described the fast-moving events as "like a scene out of an action movie."

The four deserters approached the toll booth in a taxi. They fired at a police officer who tried to question them. They were quickly surrounded by dozens of members of a special police unit. Gunfire raged, and three of the deserters were killed. The fourth was taken into custody.
Neither the military nor the police ever made a public announcement about the incident, suggesting a deep level of shock took hold in the military establishment over deserters going on the run with stolen weapons.
According to a source who was involved in the joint investigation by the military and police, the four men smuggled a tablet computer to their base quarters and became heavily involved in an online gambling site. They were unable to pay off their losses with their monthly salaries of 2,000 yuan (about 30,000 yen, or $323) and began piling up debt.
Their gambling activities came to the attention of their superior officer only a few days before the incident, and they were severely chastised.

According to the source, the lone survivor who was taken into custody said, "We wanted to take revenge on our superior officer." He also revealed that the group had planned to rob a bank.
"The incident revealed some serious problems, including a low sense of morale among military personnel and the lax oversight structure," said the source.
At one time, a military career was considered the passport to a better life as it provided entry into becoming a Communist Party member or finding a job at a state-run company after completion of military service.
But that no longer appears to be the case for those born in 1979, when China implemented its one-child policy, and in the years that followed. According to several military sources, things changed when those born under that policy began joining the military.
The ratio among all military personnel of only children rose from about 20 percent in 1996 to more than 70 percent in 2006.
These pampered children began quitting the military for all sorts of frivolous reasons. "I don't want to get a tan" and "I hate military quarters with no air conditioning" were among excuses cited.
In March 2011, Xuexi Shibao (Study Times), the organ of the Central Party School that teaches party ideology, ran an article that said, "Soldiers from the one-child generation are wimps who have absolutely no fighting spirit."
According to a source at a military think tank, an internal study found that 26 percent of soldiers who are only children quit because they found military training too tough.
So now, the military is focusing on recruiting members with proven academic achievement. And that means college graduates, as many are having difficulty landing a job. In 2009, only 68 percent of college graduates found employment.

In the past, the military only recruited among junior and senior high school students. But it was flooded with applications when it expanded recruitment efforts to cover college students.
In Beijing city alone, about 120,000 college students applied for military service in 2009.
A high-ranking officer in the Beijing Military Region said, "Having more outstanding soldiers allows us to respond more effectively to information technology as well as advanced weapons."
However, it remains to be seen if recruiting college students will alleviate the problem of desertion.
In early 2011, nine members of a unit with about 400 members in Wuhan, Hubei province, deserted. Three refused to return to their unit, so commanders implemented an administrative measure that prohibited the three from finding work at a state-run company or leaving China.
A high-ranking officer with the Wuhan security district, which decided on the disciplinary measure, said, "We were prepared for criticism (that the measure was excessive). We had to set an example in order to secure adequate staffing levels."

Saturday, 2 February 2013

With Burma in mind, China quietly supports Wa rebels

China wants Myanmar to become a communist ruled failed satellite state like Nepal, North Korea.


Chinese external spy agency Ministry of State Security [MSS] involved so that Chinese government can maintain

While Burma’s military steps up battles against Kachin rebels along the border with China, security analysts say Beijing has been quietly selling advanced weapons to another insurgent group on its border, the United Wa State Army. The Wa are the largest militia in Burma and considered the biggest narcotics dealing organization in Southeast Asia.Burma’s military airstrikes and mortar attacks on Kachin rebels in recent weeks raised international concerns about the government’s peace efforts. The heavy fighting in Burma’s north is the worst since a 17-year cease-fire with the Kachin Independence Army broke down in 2011.
But while China calls for military restraint in Kachin state, security analysts say Beijing has been secretly arming another rebel group, the United Wa State Army.
In a December report, IHS Jane’s Intelligence Review says China last year provided the Wa with advanced weapons to build up their defenses. The transfers included surface to air missiles and, for the first time, at least 12 armored vehicles the report refers to as “tank destroyers.”
Thailand-based security analyst and author of the report, Anthony Davis, said Beijing is trying to balance historic camaraderie with the Wa and its relations with Burmese authorities.
“The Chinese cannot afford to ignore the ethnic forces along their border, nor at the same time can they afford to ignore the central government,” Davis said. “Is that to say that China is directly supplying that equipment? No, it’s not. Clearly the supplier of that equipment is known to senior elements in the government, but that is not to say that they are directly involved in financing. They need to maintain a degree of deniability here,” he said.
China’s Foreign Ministry declined to comment on the IHS Jane’s Intelligence Review report.
The Wa are Burma’s largest rebel group, estimated at up to 30,000 full and part-time fighters. Despite its professed policy of non-interference, military analysts say China has long been the largest supplier of weapons to the Wa, albeit unofficially.
The Wa were one of several ethnic militias that formed after the 1989 breakup of the Burmese Communist Party.
Beijing directly supported the communists and maintained relations with the newly formed rebel groups.
Yale University Ph. D. candidate Josh Gordon said China has been particularly close with the Wa, who speak Chinese. The Wa are more or less a proxy of China, said Gordon.

“You’ll use Chinese money, Chinese cell phones, Chinese electricity for in large part, where there is electricity in the urban areas, and have connection to the Chinese Internet,” he said.
Burma signed a cease-fire with the Wa in the 1990s and allowed them to govern their own territory in northeastern Shan state. They turned it into one of Asia’s largest methamphetamine production bases and are considered the region’s largest drug-dealing organization.

The U.S. Drug Enforcement Agency in 2011 put most-wanted pictures of Wa leader Wei Hsueh Kang in Thailand’s entertainment venues.

Despite the recent escalation in Chinese weapons transfers to the Wa, Davis said Beijing is not trying to destabilize the border area. Instead, China is sending a message to Burmese authorities not to even think about attempting in Wa territory what they are doing in Kachin state where local groups are fighting Burmese forces, he said.
“The Chinese are not stoking fires in Northern Burma. By reinforcing the Wa they are reinforcing a military deterrent. If you like, they are reinforcing peace and stability which has existed for the last 20 years in a manner that’s been favorable to China.”

During past decades of military rule and western sanctions, China held great sway over Burma and its natural resources. But since Burma’s reform-minded President Thein Sein took office, and sanctions were suspended, China’s influence is being thrown off balance.
Davis said the weapons tranfers to the Wa appear to be China responding to its political reversals.
Ye Htut, a spokesman for Burma’s president, declined to comment on the report by IHS Jane’s Intelligence Review.

“We don’t have any information on that,” he said. “But, every time the Chinese government assures us they will not interfere in our internal affairs. So we accept their assurance.”
China this month sent a high-level military delegation to Burma to discuss border security issues and the fighting in Kachin state. The official New Light of Myanmar newspaper said the Chinese agreed not to interfere with Burma’s internal problems.

Tuesday, 29 January 2013

China selling weapons to ethnic army in Shan State ?

Move comes after the Myitsone dam project was being developed jointly by Burma and China at the head of the Irrawaddy river in Burma's northern Kachin state was cancelled.

China has dismissed as “ill-founded” and “misguided” allegations it sold or delivered weapons to the about 30,000-strong United Wa State Army in Shan State.
"The Chinese government holds a clear and consistent policy of respecting the sovereignty and territorial integrity of Myanmar," its embassy here said in a statement issued on Sunday.
Reports alleging China had sold or transferred weapons to ethnic armed groups in Myanmar are misguided, it said. The media reports are based on an erroneous “report by a western defence think-tank” it said, referring to Janes Intelligence Review, which released a report last month alleging that China’s effort to arm the ethnic army was “unprecedented both in the quantity of munitions and the type of systems delivered”. The report described the alleged arms deal as “highly likely to have stemmed from a high-level decision made in Beijing”.
Weapons the Wa Army received included ground-to-air missiles and 12 tank destroyers, the report stated.
The embassy stressed that China had always given strong support to a peaceful solution to the conflict within Myanmar through dialogue and negotiation by both sides. “China in recent days repeatedly called for an immediate ceasefire and joint efforts to resume peace and stability along the border area,” it said.
“China has persistently played a constructive role in promoting peace and facilitating dialogue towards the resolution of the conflict. We will continue to do so,” the statement added.
The Janes Intelligence Review report alleges that a transfer of Chinese-made PTL02 Wheeled Tank Destroyers was made in the middle of last year. The report’s author, Thailand-based intelligence analyst Anthony Davis, described this as “a significant escalation in the equipment supply to the [Wa army]” from China.
Rising support for the ethnic army coincides with political developments in Myanmar that worry Beijing, primarily increased openness to diplomatic and military ties with the United States, the report said.

Sunday, 27 January 2013

Tada...Chinese copied version of C-17 Globemaster is here

Successfully first test flight for the new Chinese large military transport aircraft Xian Y-20

Cnrl+C  = C-17 Globemaster
Cnrl+V  = Xian Y-20

Check the landing gear, tail and other aircraft fuselage design minus the nose
 
 




China on Saturday, January 26, 2013, conducted a successful test flight of its new domestically made large military transport aircraft Y-20. The plane took off at around 2:00pm from an airport in Yanliang, northwest China's Shaanxi Province, according to CCTV News.

As a large and multi-role transport aircraft, the Y-20 can carry out long-range transportation missions even under complicated weather conditions. The Y-20 was developed by Xi’an Aircraft Industry, a subsidiary of China’s leading military aircraft maker, the Aviation Industry Corporation of China.

The successful test flight is a significant boost to China’s capabilities in national defense, rescue and relief work, and humanitarian aid. Reports say more tests are planned.

The Y-20 program is part of an effort to develop an indigenous long-range jet-powered heavy transport aircraft, a top priority in China's "Medium- and Long-Term National Science and Technology Development Program (2006-20)" (MLP).

Earlier reports said it's able to accommodate most large PLA combat and support vehicles, including the Type 99 series tanks, with a capacity to carry up to 66 tons of goods. 

Thursday, 27 December 2012

China says its plane harassed by Japanese military aircraft

We all along knew about the "peaceful" rise of China
 A government spokesman confirmed on Thursday that a Chinese maritime surveillance plane was harassed by Japanese military aircraft while patrolling airspace near the Diaoyu Islands.
Japan's action was meant to escalate the situation and it should bear the consequences, said Shi Qingfeng, spokesman for the State Oceanic Administration (SOA).
Shi said the Chinese plane was conducting a routine patrol in airspace over the East China Sea about 150 km away from the Diaoyu Islands.
Shi said the flight route used by the plane has been used by Chinese surveillance planes since 2007.
"The Japanese side's disturbance was intended to cause confusion and distort the truth," Shi said. ;)