U.S. hacker in military uniform showing cyber espionage on research university in China

China Accuses NSA of Cyber Espionage in Repeated Breaches of Xi’an Research University

The Chinese government claims that the National Security Agency (NSA) is behind repeated attacks on Northwestern Polytechnical University, an aerospace and space research university funded by Beijing. The claim comes as the US government has issued warnings about China’s state-supported advanced persistent threat (APT) groups “ransacking” companies for proprietary information that can be used to steal and copy intellectual property.

China claims that the NSA’s Office of Tailored Access Operations (TAO) is responsible for tens of thousands of “vicious” cyberattacks and has stolen over 140GB of data from the country in recent years as part of cyber espionage operations. China’s National Computer Virus Emergency Response Center (NCVERC) claims to have conducted an investigation with Qihoo 360 (a Chinese internet security company) that yielded evidence of TAO involvement.

China, US engage in back-and-forth claims of cyber espionage

For decades now the US has been quick to finger China’s APT hacking groups when it believes there is evidence, but China has generally just denied or ignored these claims without counter-accusations. But Beijing has recently become more aggressive in naming US government agencies in cyber espionage incidents, as the US becomes more vocal about China’s activity in IP theft from Western organizations.

The US government has conceded that it sometimes engages in cyber espionage actions for national security purposes, but draws a distinction between that and what it calls “ransacking” of research institutions and private companies by China’s state-backed hackers. In February, China pointed the finger at another alleged state-sponsored US hacking group; a team called “Equation” that has been linked to the NSA, which it claimed had breached various IT systems and planted malware.

China’s recent accusations have also included cyber espionage by US agencies against the domestic population of the country via intercepted text messages, something the wide-ranging Snowden leaks of 2013 included. While residing in Hong Kong as controversy over his initial claims raged, Snowden presented authorities with documents detailing a program that involved NSA mass hacking of Chinese phone companies to indiscriminately gather SMS messages. The current claims also mirror Snowden’s accusations that the NSA had hacked Tsinghua University, which hosted a digital hub that would allow access to the personal data of millions of Chinese citizens.

In the case of the attack on the research university, the Chinese government claims that TAO targeted network management and core technologies with 41 different attack tools. The authorities did not specify what the alleged hackers were after, but the research university is known for developing missile technology and drones. It is also on an “entity list” forbidding US citizens from doing business with it after a Chinese national living in Massachusetts was caught illegally exporting parts used in submarine detection to it.

Qihoo 360 has previously claimed that the CIA can be linked to cyber espionage operations in the country via code that Wikileaks has published, and that these operations date back to at least 2008. In the case of the attack on the research university, China claims that the NSA exploited a previously unseen “zero day” method to gain initial access.

Claims of attacks on research university could have multiple motivations

It is essentially an open secret that a research university can expect to be targeted by multiple foreign nations (and sometimes even allies), and that the US is as much a part of this international cyber espionage as anyone else. China’s claims do appear to be in direct response to recent US rhetoric, but also may have included Qihoo 360 as a means of indirectly advertising their services to other countries that China is establishing an economic foothold in.

NCVERC has followed the research university incident up by claiming that the NSA has tools capable of breaking into x86 and Sun Solaris environments that use SPARC silicon and has been actively using them for some time. Claims like this may also be meant to sow doubt among other nations.

Josh Lospinoso, CEO and Co-Founder of Shift5, sees all of this as just another piece of an ongoing game between the two nations: “China has pointed fingers at the United States for years in response to our intelligence community outing Chinese threat actors for numerous attacks, such as last year’s against Microsoft Exchange. Publicly accusing NSA’s TAO of hacking the Beijing-funded aviation university is certainly a strategic move for China in an attempt to diminish opinions of the U.S. in neighboring countries like Japan and South Korea – especially in light of heightened tensions following Nancy Pelosi’s visit to Taiwan. This type of rhetoric ramping up isn’t far off from what we saw from Russia ahead of the Ukraine invasion and I’m interested to see if China leans on this as a softening technique for their targets.”

Some observers have also noted that the timing of these cyber espionage accusations is a little suspicious, given that they come just ahead of the country’s annual Cybersecurity Week. This event is held in early October and is meant to generate publicity under the auspices of raising public awareness of cybersecurity issues and active defenses. China has been on a recent campaign to partner with South Pacific nations on cybersecurity defenses, engaging 10 of them in talks earlier this year. The “Digital Silk Road” is also a key part of the country’s ongoing Belt & Road Initiative, seeking to plant infrastructure in a broad variety of countries that it maintains at least some degree of access to.