Chinese hackers struck US again in 2001 after a Chinese fighter plane collided with a US reconnaissance aircraft. The midair collision killed the Chinese pilot and led to the forced landing and detention of American crew. Both Chinese and American hackers responded with disruptive cyberattacks, with the Chinese hackers defacing thousands of US websites, including the White House site.
What is important about this is what happened next. The People's Daily, China's Communist Party newspaper, issued an editorial decrying the attack against the White House. They called it "web terrorism" and "unforgivable acts violating the law."The government asked Chinese hackers to forgo further attacks against US-based sites. They complied.
That was the last big cyberattack from Chinese patriotic hackers against the US. While Russia seems to condone, if not outright encourage or even sponsor, patriotic hackers, China has taken a stance against that sort of activity, at least with respect to US-based sites. In addition to reining in patriotic hackers, China has refrained from conducting cyberattacks that cause damage to critical infrastructure in other countries, like Russia did to Ukraine's power grid. However, it has used disruptive cyberattacks to help enforce censorship policies within its own borders.
The Chinese government's "Great Firewall" keeps internet users in China from accessing censored foreign sites such as those that advocate Tibetan autonomy. Users' traffic is filtered based on domain names, internet addresses and keywords in web addresses.
Chinese hackers have also used denial-of-service attacks to take out sites whose activity the government wants to block. By 2003, China's interest in cyberespionage was apparent: A series of cyberintrusions that US investigators code-named "Titan Rain" was traced back to computers in China. The hackers, believed to be from the Chinese army, had invaded and stolen sensitive data from computers belonging to the US Department of Defense, defense contractors and other government agencies.
Titan Rain was followed by a rash of espionage incidents that originated in China and were given code names like "Byzantine Hades," "GhostNet" and "Aurora." The thieves were after a wide range of data.
In 2013, the American cyberintelligence firm Mandiant, now part of FireEye, issued a landmark report on a Chinese espionage group it named "Advanced Persistent Threat 1." According to the report, APT1 had stolen hundreds of terabytes of data from at least 141 organizations since 2006.
The Mandiant report gave details of operations and provided evidence linking those thefts to the People's Liberation Army. This was the first time any security firm had publicly disclosed data tying a cyberoperation against the US to a foreign government. In 2014, the US indicted the five Chinese officers for computer hacking and economic espionage.
Mandiant described APT1 as "one of more than 20 APT groups with origins in China." Many of these are believed to be associated with the government. A report from the nonprofit Institute for Critical Infrastructure Technology describes 15 state-sponsored advanced persistent threat groups, including APT1 and two others associated with PLA units. The report does not identify sponsors for the remaining groups.
According to the institute, China's espionage supports the country's 13th Five-Year Plan (covering the years 2016 to 2020), which calls for technology innovations and socioeconomic reforms.
In its 2015 Global Threat Report, the American cyberintelligence firm CrowdStrike identified dozens of Chinese adversaries targeting business sectors that are key to the Five-Year Plan. It found 28 groups going after defense and law enforcement systems alone. Other sectors victimized worldwide included energy, transportation, government, technology, health care, finance, telecommunications, media, manufacturing and agriculture.
In September 2015, President Obama met with China's President Xi Jinping to address a range of issues affecting the two countries. With respect to economic espionage, they agreed that their governments would not conduct or knowingly support cyber-enabled theft of business secrets that would provide competitive advantage to their commercial sectors. They did not agree to restrict government espionage, a practice that countries generally consider to be fair game.
In June 2016, FireEye reported that since 2014 there had been a dramatic drop in cyberespionage from 72 suspected China-based groups. FireEye attributed the reduction to several "factors including President Xi's military and political initiatives, the widespread exposure of Chinese cyberoperations, and mounting pressure from the US Government." The ICIT believes China may also be asserting greater control over its operatives and focusing on unspecified high-priority targets.
