Affichage des articles dont le libellé est Ministry of State Security. Afficher tous les articles
Affichage des articles dont le libellé est Ministry of State Security. Afficher tous les articles

mercredi 21 novembre 2018

China steps up efforts to steal Australian company secrets

  • China directed an increase in cyber attacks on Australian companies this year that breached a bilateral agreement between the two countries to not steal each other's commercial secrets.
  • An investigation by Fairfax Media and broadcaster Nine News found that China's Ministry of State Security was responsible for the so-called "Operation Cloud Hopper."
  • It was a wave of attacks that were detected by Australia and its partners in the "Five Eyes" intelligence sharing alliance — the U.S., U.K., New Zealand and Canada.
By Saheli Roy Choudhury

China directed an increase in cyber attacks on Australian companies this year that breached a bilateral agreement between the two countries pledging not to steal each other's commercial secrets, the Sydney Morning Herald reported Tuesday.
An investigation by Australian broadcaster Nine News and Fairfax Media — which owns the Sydney Morning Herald — found that China's Ministry of State Security was responsible for the so-called "Operation Cloud Hopper." 
It was a wave of attacks that were detected by Australia and its partners in the "Five Eyes" intelligence sharing alliance — which is made up of the U.S., U.K., New Zealand and Canada.
A senior Australian government source told the Sydney Morning Herald that China's activity was a "constant, significant effort" to steal intellectual property. 
Others said local companies and universities were not doing enough to tighten their cybersecurity against such attacks, the newspaper reported.
Cybersecurity experts also told the newspaper they had noticed "a significant increase in attacks in the first six months of this year" and that the activity was "mainly from China."
Relevant contact details for China's Ministry of State Security were not immediately available.
The Sydney Morning Herald's report came after recent remarks from U.S. Vice President Mike Pence, who accused Beijing of intellectual property theft during the Asia Pacific Economic Cooperation Summit.
Western countries have long accused China of stealing intellectual property as well as commercial and military secrets.
In recent years, China has stepped up efforts to create sophisticated home-grown technologies as it aims to catch up with other high-tech countries like the U.S. and Germany.
In 2015, Chinese dictator Xi Jinping struck an agreement with former President Barack Obama to curb cyber espionage. 
However, a U.S. intelligence official said earlier this month that China was violating the agreement.

mardi 20 novembre 2018

Born to Spy

China uses the cloud to step up spying on Australian business
By Nick McKenzie, Angus Grigg & Chris Uhlmann

China’s peak security agency has directed a surge in cyber attacks on Australian companies over the past year, breaching an agreement struck between Li Keqiang and former Prime Minister Malcolm Turnbull to not steal each other’s commercial secrets.
A Fairfax Media/Nine News investigation has confirmed that China’s Ministry of State Security is responsible for what is known in cyber circles as “Operation Cloud Hopper”, a wave of attacks detected by Australia and its partners in the Five Eyes intelligence sharing alliance.

China's Ministry of State Security is overseeing a massive hacking operation of large Australian businesses. 

A senior Australian Government source described China’s activity as “a constant, significant effort to steal our intellectual property”.
The cyber theft places intense pressure on the Morrison government to respond either via law enforcement, diplomatic channels or public advocacy, in order to uphold the cyber security pact signed between the two countries only last year.
The US Department of Justice has ramped up its investigation and prosecution of Chinese cyber hackers this year, and over the weekend US Vice President Mike Pence again accused China of “intellectual property theft” as part of an escalating trade and strategic battle with Beijing.
The Australian Federal Police and Australian Security Intelligence Organisation have stepped up their cooperation to respond to the threat, according to a senior police source, although they are many months behind the US operation.
Without enforcement, there was no effective deterrence, said one national security source.
Other sources said the Australian Signals Directorate has detected attacks against several Western businesses, although the names of the affected firms have not been made public. 
The ASD works with the other Five Eyes countries – the US, Canada, UK and New Zealand – on cyber security issues.
A spokesman for the federal government said Australia condemns the cyber enabled theft of intellectual property for commercial gain from any country.
"The Coalition Government has been active in strengthening Australia’s capability to detect and respond to cyber enabled threats and is committed to ensuring businesses and the Australian community are resilient to cyber-attacks," the spokesman said.
One major irritation, raised by several police and intelligence officials, was that Australian companies and universities failed to heed repeated warnings to harden their security against both criminals and attacks directed by nation states.
These state actors are called advanced persistent threats because they work over months or years, adapt to defences and often strike the same victim multiple times. 
One of the most active Chinese adversaries has been dubbed “APT10”, while “Cloud Hopper” refers to the technique used by this group as they “hop” from cloud storage services into a company’s IT system.
In this case the Chinese penetrated poorly secured IT service providers, to which Australian firms had outsourced their IT. 
The targets include cloud storage companies and helpdesk firms in North America and Asia. 
The initial penetration by the Cloud Hopper team allowed the hackers to enter the IT systems of Australian companies.
Adrian Nish, BAE Systems’ Head of Threat Intelligence, said the APT10/Cloud Hopper attacks had focussed on the mining, engineering and professional service companies.
“It is still active. We have evidence of [Cloud Hopper] again actively compromising managed service providers,” he said.
The theft of intellectual property is part of China’s broader industrial policy to match the US’s technological edge by 2025. 
The theft can shorten the research and development process and give Chinese companies a crucial market edge. 
They can also acquire sensitive information around pricing and corporate activity.
A national security official said the Turnbull-Li agreement had initially led to a significant reduction in cyber espionage from China. 
The US experienced a comparable drop-off in attacks after former President Barack Obama struck a similar agreement with Chinese dictator Xi Jinping in 2015.
A former senior Government official familiar with the cyber security agreement said: “The way these things usually go with the Chinese is they behave themselves for a while before they go back to being bad”.

Chinese empty promises -- "Australia and China agreed that neither country would conduct or support cyber-enabled theft of intellectual property, trade secrets or confidential business information with the intent of obtaining competitive advantage," the Prime Minister's office said in a brief statement.

The attacks on Australian firms since the start of this year, including Cloud Hopper activity, showed the bilateral agreement was being ignored.
Security officials and cyber experts, including Mike Sentonas a vice president at US firm CrowdStrike, have linked the Cloud Hopper hackers to the Ministry of State Security.
“We noticed a significant increase in attacks in the first six months of this year. The activity is mainly from China and it's targeting all sectors,” he said.
“There’s no doubt the gloves are off.”
Dr Nish from BAE, who has published the most comprehensive report on Cloud Hopper, said he discovered that attacks on multiple clients appeared to be part of the same campaign of “espionage activity”.
“It was clear it was a much bigger campaign,” Dr Nish said.
BAE referred it to the UK’s National Cyber Security Centre, who referred it to their Australian counterparts at ASD. 
While Dr Nish declined to confirm the Cloud Hopper attack was directed by Chinese intelligence services, he said there was “no reason to doubt” those who claimed it was.
He said that while outsourcing IT functions was a sensible business decision, Australian firms needed to ask “tough questions” of managed service providers. 
Some providers offered cheaper IT services because they scrimped on their own security, effectively allowing a backdoor into their clients' IT systems.
In October, the US Department of Justice provided a case study on Chinese hacking within a 21-page indictment naming the MSS and accusing the MSS and its provincial counterparts of hacking an Australian domain name provider in order to access computer systems at aviation companies in the United States and Europe.
Under direction from the MSS, the hackers are accused of either creating fake domain names or redirecting existing domain names to malicious addresses.
The MSS is headquartered in Beijing but has extensive provincial operations and is regarded by western intelligence services as a sophisticated outfit able to combine human intelligence with the advanced cyber capabilities.
Previously, Unit 61398 of the People’s Liberation Army was viewed as the main vehicle for China’s efforts to steal commercial secrets after being named by cyber security firm Mandiant in 2014.
But since a reorganisation of China’s armed forces in 2015, the PLA cyber units are believed to have refocused on military and political intelligence, leaving commercial espionage to the MSS.

mercredi 31 octobre 2018

China's theft of intellectual property

Two Chinese intelligence officers accused of stealing US jet engine tech
By Ben Westcott and Mary Kay Mallonee

Two Chinese intelligence officers have been charged by the United States Justice Department with trying to steal the details for a type of jet engine technology from US-based companies.
Zha Rong and Chai Meng, intelligence officers with the Jiangsu provincial branch of the Ministry of State Security (MSS) in China, are accused of attempting to hack and infiltrate private companies over the course of five years in an attempt to steal the technology.
"This action is yet another example of criminal efforts by the MSS to facilitate the theft of private data for China's commercial gain," US Attorney Adam Braverman said in a statement.
"The concerted effort to steal, rather than simply purchase, commercially available products should offend every company that invests talent, energy, and shareholder money into the development of products."
The US Department of Justice statement does not explicitly state where Zha Rong and Chai Meng are presently located. 
The United States does not have an extradition treaty with China -- and if the men are in China, the Chinese government would be unlikely to give them up.
The charges come at a time when pressure is building on Beijing to address US concerns over the widespread theft of intellectual property by Chinese agents to fuel the country's economic rise.
The new charges mark the third time since September that charges have been brought against Chinese intelligence officers for trying to steal US intellectual property.
On October 11, the Department of Justice charged Chinese intelligence officer Yanjun Xu with attempting to commit economic espionage, including working to get aviation employees to reveal their trade secrets. 
In an indictment released by the Justice Department Tuesday, the US Justice Department alleged Zha and Chai from January 2010 began to work with a team of hackers to steal the technology for the engine which was being developed jointly by a French and a US-based company.
"At the time of the intrusions, a Chinese state-owned aerospace company was working to develop a comparable engine for use in commercial aircraft manufactured in China and elsewhere," the statement said.
Attempts to infiltrate the company weren't limited to hacking, according to the US statement. 
Two Chinese nationals working for the company, Tian Xi and Gu Gen were co-opted by Chinese intelligence and given malware to install in their employer's computer system.
"The threat posed by Chinese government-sponsored hacking activity is real and relentless," John Brown, FBI Special Agent in Charge of the San Diego Field Office, said in a statement.

mardi 28 novembre 2017

Nation of Thieves: Chinese Ministry of State Security Behind APT3

This is the first time researchers have been able to attribute a threat actor group with a high degree of confidence to the Ministry of State Security.
By Insikt Group

Key Takeaways
  • APT3 is the first threat actor group that has been attributed with a high degree of confidence directly to the Chinese Ministry of State Security (MSS).
  • On May 9, a mysterious group called “intrusiontruth” attributed APT3 to a company, Guangzhou Boyu Information Technology Company, based in Guangzhou, China.
  • Recorded Future’s open source research and analysis has corroborated the company, also known as Boyusec, is working on behalf of the Chinese Ministry of State Security.
  • Customers should re-examine any intrusion activity known or suspected to be APT3 and all activity from associated malware families as well as re-evaluate security controls and policies.

Introduction

On May 9, a mysterious group calling itself “intrusiontruth” identified a contractor for the Chinese Ministry of State Security (MSS) as the group behind the APT3 cyber intrusions.

Recorded Future timeline of APT3 victims.


Screenshot of a blog post from “intrusiontruth in APT3.”

“Intrusiontruth” documented historic connections between domains used by an APT3 tool called Pirpi and two shareholders in a Chinese information security company named Guangzhou Boyu Information Technology Company, Ltd (also known as Boyusec).

Registration information for a domain linked to the malware Pirpi. The details show the domain was registered to Dong Hao and Boyusec.

APT3 has traditionally targeted a wide-range of companies and technologies, likely to fulfill intelligence collection requirements on behalf of the MSS (see research below).
Recorded Future has been closely following APT3 and has discovered additional information corroborating that the MSS is responsible for the intrusion activity conducted by the group.

Recorded Future Intel Card for APT3.

Background
APT3 (also known as UPS, Gothic Panda, and TG-011) is a sophisticated threat group that has been active since at least 2010
APT3 utilizes a broad range of tools and techniques including spearphishing attacks, zero-day exploits, and numerous unique and publicly available remote access tools (RAT). 
Victims of APT3 intrusions include companies in the defense, telecommunications, transportation, and advanced technology sectors — as well as government departments and bureaus in Hong Kong, the U.S., and several other countries.

Analysis
On Boyusec’s website, the company explicitly identifies two organizations that it cooperatively partners with, Huawei Technologies and the Guangdong Information Technology Security Evaluation Center (or Guangdong ITSEC).

Screenshot of Boyusec’s website where Huawei and Guangdong ITSEC are identified as collaborative partners.

In November 2016, the Washington Free Beacon reported that a Pentagon internal intelligence report had exposed a product that Boyusec and Huawei were jointly producing. 
According to the Pentagon’s report, the two companies were working together to produce security products containing a backdoor, that would allow Chinese intelligence “to capture data and control computer and telecommunications equipment.” 
The article quotes government officials and analysts stating that Boyusec and the MSS are “closely connected,” and that Boyusec appears to be a cover company for the MSS.

Boyusec is located in Room 1103 of the Huapu Square West Tower in Guangzhou, China.

Boyusec’s work with its other “cooperative partner,” Guangdong ITSEC, has been less well-documented. 
As will be laid out below, Recorded Future’s research has concluded that Guangdong ITSEC is subordinate to an MSS-run organization called China Information Technology Evaluation Center (CNITSEC) and that Boyusec has been working with Guangdong ITSEC on a joint active defense lab since 2014.
Guangdong ITSEC is one in a nation-wide network of security evaluation centers certified and administered by CNITSEC. 
According to Chinese state-run media, Guangdong ITSEC became the sixteenth nationwide branch of CNITSEC in May 2011. 
Guangdong ITSEC’s site also lists itself as CNITSEC’s Guangdong Office on its header.
According to academic research published in China and Cybersecurity: Espionage, Strategy, and Politics in the Digital Domain, CNITSEC is run by the MSS and houses much of the intelligence service’s technical cyber expertise. 
CNITSEC is used by the MSS to “conduct vulnerability testing and software reliability assessments.” Per a 2009 U.S. State Department cable, it is believed China may also use vulnerabilities derived from CNITSEC’s activities in intelligence operations. 
CNITSEC’s Director, Wu Shizhong, even self-identifies as MSS, including for his work as a deputy head of China’s National Information Security Standards Committee as recently as January 2016.
Recorded Future research identified several job advertisements on Chinese-language job sites such as jobs.zhaopin.com, jobui.com, and kanzhun.com since 2015, Boyusec revealed a collaboratively established joint active defense lab (referred to as an ADUL) with Guangdong ITSEC in 2014. Boyusec stated that the mission of the joint lab was to develop risk-based security technology and to provide users with innovative network defense capabilities.


Job posting where Boyusec highlights the joint lab with Guangdong ITSEC. The translated text is, “In 2014, Guangzhou Boyu Information Technology Company and Guangdong ITSEC cooperated closely to establish a joint active defense lab (ADUL).”

Conclusion

The lifecycle of APT3 is emblematic of how the MSS conducts operations in both the human and cyber domains. 
Many of these elements, especially at the provincial and local levels, include organizations with valid public missions to act as a cover for MSS intelligence operations. 
Some of these organizations include think tanks such as CICIR, while others include provincial-level governments and local offices.
In the case of APT3 and Boyusec, this MSS operational concept serves as a model for understanding the cyber activity and lifecycle:
  • While Boyusec has a website, an online presence, and a stated “information security services” mission, it cites only two partners, Huawei and Guangdong ITSEC.
  • Intrusiontruth and the Washington Free Beacon have linked Boyusec to supporting and engaging in cyber activity on behalf of the Chinese intelligence services.
  • Recorded Future’s open source research has revealed that Boyusec’s other partner is a field office for a branch of the MSS. Boyusec and Guangdong ITSEC have been documented working collaboratively together since at least 2014.
  • Academic research spanning decades documents an MSS operational model that utilizes organizations, seemingly without an intelligence mission, at all levels of the state to serve as cover for MSS intelligence operations.
  • According to its website, Boyusec has only two collaborative partners, one of which (Huawei) it is working with to support Chinese intelligence services, the other, Guangdong ITSEC, which is actually a field site for a branch of the MSS.

Graphic displaying the relationship between the MSS and APT3.

Impact
The implications are clear and expansive. 
Recorded Future’s research leads us to attribute APT3 to the Chinese Ministry of State Security and Boyusec with a high degree of confidence. 
Boyusec has a documented history of producing malicious technology and working with the Chinese intelligence services.
APT3 is the first threat actor group that has been attributed with a high degree of confidence directly to the MSS. 
Companies in sectors that have been victimized by APT3 now must adjust their strategies to defend against the resources and technology of the Chinese government. 
In this real-life David versus Goliath situation, customers need both smart security controls and policy, as well as actionable and strategic threat intelligence.
APT3 is not just another cyber threat group engaging in malicious cyber activity; research indicates that Boyusec is an asset of the MSS and their activities support China’s political, economic, diplomatic, and military goals.
The MSS derives intelligence collection requirements from state and party leadership, many of which are defined broadly every five years in official government directives called Five Year Plans. 
Many APT3 victims have fallen into sectors highlighted by the most recent Five Year Plan, including green/alternative energy, defense-related science and technology, biomedical, and aerospace.

lundi 26 juin 2017

Bumbling Ex-CIA Officer Charged With Selling Secrets to China

A prestigious Chinese think tank provided cover for the intelligence operation that ensnared Kevin Mallory.
BY BETHANY ALLEN-EBRAHIMIAN, ELIAS GROLL

Caught with a bag of cash and an electronic device used to communicate with his handlers, a former government official with years of military and intelligence experience is accused of spying for China.
Kevin Mallory of Leesburg, Virginia is charged with providing defense-related information to a foreign government and lying to federal agents.
Mallory provided several classified government documents to a Chinese contact, who initially claimed affiliation with a prestigious Shanghai think tank, in exchange for cash. 
Documents filed by federal prosecutors depict Mallory, an experienced Chinese-speaking former operative, as a bumbling spy who executed his treason clumsily.
Mallory’s career spanned decades and multiple government agencies. 
After graduating from Brigham Young University in 1981, he served as active duty military and then an Army reservist for several years. 
From 1987 to 2013, he worked for different government agencies and U.S. defense contractors — as well as the CIA, according to a report in the Washington Post. 
He held a top secret security clearance for much of that time and was posted to regions including Iraq, China, and Taiwan.
It was only this year that Mallory began to stray from the straight and narrow, according to court documents. 
A Chinese handler posing as an employee of the Shanghai Academy of Social Sciences (SASS) made contact with Mallory during trips to China in March and April.
The SASS is a reputable and internationally known think tank. 
But it also maintains a close working relationship with the Shanghai State Security Bureau, a regional office of the Ministry of State Security, China’s intelligence arm.
In the following weeks, Mallory provided classified documents to Chinese intelligence officials in exchange for $25,000.
The FBI’s affidavit describing Mallory’s espionage activity appears to indicate that the former CIA officer tried to cover up his crimes. 
After he was stopped at Chicago’s O’Hare airport returning from Shanghai with $16,500 in undeclared cash in one of his bags, Mallory approached American intelligence agencies to describe his meetings in Shanghai with individuals he described as Chinese intelligence officers.
Having been caught with a payment that investigators believe was in exchange for classified government information, Mallory disclosed his contacts with the Chinese intelligence officers and may have offered his services as a double agent in order to conceal his espionage on behalf of Beijing. 
The FBI affidavit never claims he offered to serve as a double agent, but in approaching an unspecified government agency with a communications device provided to him by the Chinese, Mallory appears to have made an overture to an American intelligence agency.
“He had a security clearance, he had apparently also worked at CIA, so he knew what he was doing,” said Peter Mattis, a former government analyst and now a fellow at the Jamestown Foundation’s China Program.
But then Mallory made what Mattis called a “stupid mistake.”
Kevin Mallory

The FBI affidavit filed in a Virginia federal court this week paints a picture of extraordinary technical incompetence by Mallory and his Chinese handlers. 
Mallory’s Chinese contacts supplied him with a communications device — likely a smart phone — to exchange messages and transfer classified documents.
In a May 24 meeting with FBI agents, Mallory showed off the device and demonstrated how to move from a “normal” to “secure” messaging mode. 
When he toggled over to the secure mode, he was surprised to find that it displayed a history of his secure messages. 
Mallory seems to have assumed they would be deleted.
Mallory voluntarily turned the device over to the bureau for a forensic analysis. 
When the bureau’s technical experts dug into it, they were able to recover additional secure messages exchanged between Mallory and his Chinese contacts.
In an exchange of messages on May 3, 2017, Mallory’s handler asked why the documents had been blacked out at the top and bottom. 
“The black was to cross out the security classification (TOP SECRET//ORCON//),” Mallory replied. “I had to get it out without the chance of discovery. Unless read in detail, it appeared like a simple note.”
Two days later, Mallory discussed his motives with his handler: “Your object is to gain information, and my object is to be paid.” 
His handler replied: “My current object is to make sure your security and try to reimburse you.”
The FBI analysis also discovered four documents on the phone, three of which are described in court documents as government materials. 
One is top secret; the other two are classified as secret. 
The affidavit provides no hint as to what the documents contain.
Mattis told Foreign Policy that the “scope, scale and potential impact of Chinese intelligence operations” has been of primary concern to U.S. national security agencies for years.
Chinese think tanks, including SASS, work closely with the Ministry of State Security. 
China’s spy arm prefers to meet sources inside China, and social science academies provide a useful front for intelligence and influence operations.
“Chinese think tanks are used to invite someone over who is either a person of interest or a source,” said Mattis. 
“That person comes over and gives a talk, and they’ll be met and have meetings with the local state security element or the People’s Liberation Army.”
But these intelligence-linked Chinese think tanks also maintain a known presence in Washington. 
One of those is the China Institutes of Contemporary International Relations, which bills itself as a “comprehensive research institution” but which is also an official numbered bureau of the Ministry of State Security, functioning rather like the CIA’s Open Source Center.
The institute actively engages in the Washington think tank ecosystem and also invites U.S. officials and academics for events in Beijing. 
The Center for Strategic and International Studies, a nonpartisan Washington think tank, has co-hosted numerous cybersecurity dialogues with the Chinese institute in recent years.
For more than two decades, the institute has sent a fellow to Washington, who stays for a year or two, according to Mattis. 
“I guess some people find value in talking with them,” he said. 
“I have mixed feelings on that score.”

mardi 13 juin 2017

U.S. 3.8 Million Chinese Spies

This Is How Chinese Spying Inside the U.S. Government Really Works
By Peter Mattis

The Department of Justice on March 29 unsealed a criminal complaint against Candace Claiborne, an office-management specialist with the U.S. Department of State, who is now facing charges related to concealing a relationship with Chinese intelligence. 
The extended fifty-nine-page affidavit catalogues Claiborne’s relationship with the Ministry of State Security, or MSS, China’s civilian intelligence service.
The MSS is a sprawling organization centered in Beijing. 
It has provincial departments and municipal bureaus all over the country. 
The central ministry does run intelligence operations, but the subnational departments and bureaus almost certainly include most of the ministry’s personnel. 
The main task of these departments is to protect state security inside their operational jurisdiction. However, some of them also run operations against foreign targets to support national policymakers.
The MSS unit with which Claiborne became involved was the Shanghai State Security Bureau (SSSB). 
Largely unknown outside of the small group of people who look at Chinese intelligence operations, the SSSB has surfaced only a few times in public. 
In 2009, the SSSB raided the China offices of Australian mining firm Rio Tinto. 
The office director, Stern Hu, came under investigation, because his aggressive approach to investment cost the Chinese government and state-owned enterprises several hundred million dollars. A year later, the FBI arrested Glenn Duffie Shriver, who applied to work at the State Department and CIA in exchange for $70,000. 
The SSSB recruited Shriver in Shanghai when he responded to an essay contest on U.S.-China relations and encouraged him to take a position in the U.S. government.
The affidavit reveals that the SSSB can operate all over China and the world, not just in Shanghai. 
In communications with Claiborne, her SSSB contacts—identified only as Co-Conspirator B and Co-Conspirator C—offered to meet her in Beijing as well as any third country if and when she left the United States. 
Co-Conspirator B also made references to business trips in Italy and Africa.
Despite the possibility of meetings anywhere, the case still exhibits the China connection that is distinctive of nearly every espionage case. 
The SSSB’s spotting and assessing work most likely took place in China. 
The affidavit states that Claiborne knew the SSSB officers at least since 2007 if not before. 
In 2007, Claiborne was stationed in Buenos Aires and had been away from China for two years. 
Her second tour in China was at the U.S. Consulate General in Shanghai from 2003–05.
The SSSB also operates with some unusual cover arrangements that suggests in some cases individual officers develop their own cover. 
Some of the normal MSS covers inside the country include unnamed, numbered government offices (e.g. Shanghai Municipal Government Office number seven), think tanks and businesses. 
Co-Conspirator B operated an import-export company, and he also owned a spa and a restaurant. 
In addition to allowing Co-Conspirator B to appear as ordinary businessman, these businesses were used to provide employment to Co-Conspirator A. 
The affidavit does nothing to describe Co-Conspirator C apart from his SSSB affiliation.
A caveat on Co-Conspirator B’s cover arrangements perhaps is in order. 
He may be what the affidavit calls a “cut out” or a “co-optee” of the SSSB. 
The affidavit describes this role in some detail as part of the background but it is mentioned nowhere else. 
The affidavit states “A cut-out or co-optee is a mutually trusted person or mechanism used to create a compartment between members of an operation to enable them to pass material and/or messages securely. A cut-out or co-optee can operate under a variety of covers, posing as diplomats, journalists, academics, or business people both at home and abroad. These individuals are tasked with spotting, assessing, targeting, collecting, and running sources.” 
Co-Conspirator B could easily be a co-optee from the description of him and his business activities. His role in handling Claiborne fits completely within the above definition, and the affidavit contains nothing to clarify his position.
Co-Conspirator A and his relationship with Claiborne illustrates the creative ways in which the MSS will develop emotional leverage over an agent. 
The affidavit does little to describe Co-Conspirator A apart from making it clear that the young man is someone important to Claiborne, probably a relative, because he lived with her in China from 2001–05. 
Her relationship with the SSSB was not simply an exchange of money for information, of dollars for documents. 
Much of the money dispensed by the SSSB went to pay for Co-Conspirator A’s college tuition, provide him with work, a furnished apartment, and pay for his travel rather than Claiborne directly. 
In several different emails, she told Co-Conspirator A to extricate himself of his relationship with the SSSB, because she did not want herself or him to continue to be indebted to Chinese intelligence.
Building a relationship with an agent almost appears to more important than collecting intelligence information. 
The SSSB paid out “tens of thousands of dollars in gifts and benefits” to Claiborne and Co-Conspirator A, but the return appeared minimal. 
For example, in 2011, at least four years into the relationship, the SSSB tasked Claiborne with gathering internal evaluations of the U.S.-China Strategic and Economic Dialogue. 
They specifically wanted to know about Chinese yuan exchange rates and what pressures Washington would be prepared to bring if China’s adjustments were insufficient. 
The SSSB officers complained of one of Claiborne’s responses that “It is useful but it is also on the Internet. What they are looking for is what they cannot find on the Internet,” believing that the publicly available information was not necessarily representative of U.S. government thinking.
There is little exotic in how the SSSB handled Candice Claiborne if the case ultimately holds up in court as described. 
They built psychological leverage through Co-Conspirator A. 
They exploited Claiborne’s greed through small payments and the promise of more—she believed the SSSB could pay as much as $20,000 per year. 
The only thing strange appears to be the callousness with which the SSSB treated her concerns about security and the seeming absence of any plans to end the relationship productively. 
Countering Chinese intelligence, then, is not about a dramatic departure from past practice, but rather a commitment to counterintelligence fundamentals and professionalism.

mardi 23 mai 2017

Chinese Fifth Column: VOA Blocks Businessman From Revealing Chinese Spying Secrets

Guo Wengui details PRC intel operations, a potential intelligence windfall for FBI, CIA
By Bill Gertz

Guo Wengui 

An exiled Chinese businessman with close ties to the government has begun revealing secrets about Beijing's intelligence operations after China pressured the official Voice of America radio to curtail a lengthy interview with him.
Four VOA employees were suspended last month after more than an hour of the radio's exclusive interview with billionaire businessman Guo Wengui exceeded a time limit imposed under radio rules.
The four employees of the Chinese language radio division are now calling on Congress to investigate whether VOA managers gave in to pressure from China's government to shorten the Guo interview and as a result undermined the radio's integrity.
Sasha Gong, one of the four suspended employees and chief of VOA's Mandarin language service, says Congress should probe the matter.
"I would like the Congress to investigate if the management of the taxpayer-funded Voice of America caved in to the request and demand of the Chinese government. If so, what is the reason behind their decision?" she said.
A VOA spokesman defended the decision to cut off the interview after an hour based on the radio's practices limiting time devoted to live interviews.
"Pressure from the Chinese government played no role in any decision-making," said the spokesman, George Mackenzie. 
"VOA and the [parent organization Broadcasting Board of Governors] have decades-long histories of producing full fair and balanced journalism in the face of even the most extreme pressures."
VOA is the official U.S. government radio broadcaster providing news in 40 languages.
Critics have charged VOA is poorly managed and its news reports are too friendly toward anti-democratic states such as China.
Guo has close ties to senior Chinese Communist Party leaders, including government ministers and Politburo members. 
In April, he began disclosing detailed information on what he says is corruption among senior Chinese leaders, along with details of Chinese intelligence activities.
The four employees charged in an open letter to Congress that "a series of arguments and debates" led VOA to halt the April 19 on-air interview with Guo after one hour and 19 minutes. 
They said said cutting off the interview "gravely damaged" the "integrity and credibility of VOA as a media outlet."
"Furthermore, as VOA is a federal entity, the U.S. government's integrity and credibility have been greatly damaged, too," they said. 
"Therefore, the U.S. national interests have been greatly undermined as well."
MacKenzie, the VOA spokesman, said decisions on handling the Guo interview were based on journalistic guidelines requiring verification, balance, and fairness that apply to all VOA's various language services.
"There was no input whatsoever from the U.S. government, nor would the firewall permit any such input," MacKenzie said, referring to limits of official U.S. government controls.
China, meanwhile, has taken steps to intimidate Guo's family members and the businessman himself who is said to be in hiding in New York.
Guo's knowledge of Chinese intelligence operations could provide an intelligence windfall for the CIA and FBI, based on his access to Ministry of State Security (MSS) operations overseas and in the United States.
Ma Jian, a former MSS vice minister who was imprisoned for corruption last year, recently surfaced in an online Chinese video charging that he was in the pay of Guo and that they shared information.
After the VOA curtailed his interview, Guo, who has claimed to be working with Chinese intelligence and security services, took to social media and began providing daily videos and reports revealing Chinese spying and other sub rosa activities.
Writing on Twitter under the name @KwokMiles, Guo recently disclosed that MSS operatives work closely with wealthy Chinese nationals like him who are tasked with funding and conducting intelligence operations on behalf of MSS.
For example, in the United States, Chinese surrogates have funded private investigators to spy on the offspring of high-ranking Chinese officials, many of whom are in the real estate business or attend American universities.
In a bid to silence Guo, China detained two of his brothers. 
The brothers were eventually released and Guo said they had been tortured by authorities.
Additionally, Guo's wife and daughter currently have been allowed by Chinese authorities to visit him in New York but are required to return to China after 20 days where they can be used for political leverage against Guo.
Guo stated in one recent video that he fears his family is being used by the government to pressure him into silence or to force his return to China.
Guo also announced that he is offering $100 million to anyone who can produce evidence, such as bank records, revealing high-level corruption by Chinese officials.
In the portion of the VOA interview that aired, Guo dismissed the Interpol red notice as part of Chinese effort to silence him. 
China spent $60 million annually to arrange for Interpol to pick a Chinese national as its director. 
The current director is Meng Hongwei.
Guo said he has been in the United States since 2015 and holds several foreign passports. 
Asked about MSS activities, Guo said the ministry uses Chinese businessmen as agents called "commercial anchors" who assist MSS.
Ma Jian, the imprisoned MSS official, was in charge of directing his overseas business activities on behalf of the service, Guo said, adding that he has no formal relationship with MSS beyond the use of his business resources.
Guo also alleged he has information about corruption involving the family of Wang Qishan, the senior Party official in charge of Xi Jinping's nationwide anti-corruption drive. 
Wang is a member of the Politburo Standing Committee, the seven member collective dictatorship that rules China.
On Capitol Hill, committee aides said both the Senate Foreign Relations Committee and House Foreign Affairs Committee are monitoring the issue.
A House committee spokesman said: "The Foreign Affairs Committee is aware of the matter and following it. Sadly, this appears to be one more example of the need for reform at VOA."
A Senate Republican aide added: "Since the reports first surfaced, we have been tracking the suspensions and are prepared to conduct further oversight if necessary."
Sen. James Lankford (R., Okla.) is also looking into the matter, a spokesman said.
A Justice Department spokesman declined to comment.
According to the suspended VOA employees, Guo earlier this year contacted the radio and said he wanted to go public with details of corruption by senior Chinese officials.
The employees who signed the statement to Congress are Sasha Gong, Fred Wang, Huchen Zhang, and Robert Li
They have denied any wrongdoing and are asserting that VOA management is treating them unfairly over the Guo interview.
Days before the planned three-hour live interview on VOA, China issued an arrest warrant for Guo in Dalian, and then an Interpol "red notice" calling for Guo's detention, claiming he was wanted for unspecified bribery charges.
An official at China's embassy then called VOA on April 18 and demanded the radio cancel its upcoming interview with Guo.
VOA managers, including director Amanda Bennett and deputy director Sandy Sugawara, decided to limit the Guo interview to one hour and ordered it halted
after the interview exceeded that limit.

A White House petition was set up May 18 calling on the U.S. government to protect Guo as a "whistleblower."
"Chinese billionaire Guo Wen Gui is hunted by Chinese communist party by all means, he is exposing the massive corruption on highest level of Communist party and launching a campaign to push for Chinese Constitutional reform," the petition states.
The petition also said China has issued "an assassination bounty reward" for Guo and his family.
The dissident Chinese news outlet China Digital Times has documented some of Guo's charges and reported that Guo is planning an international news conference at an unspecified time in the future.
Disclosure of the Chinese intelligence activities come as the New York Times reported last weekend that China executed or imprisoned up to 20 of the CIA's recruited agents, based on a Chinese mole in the agency or a compromise of its secure communications.
The newspaper quoted intelligence sources as saying the damage began in 2010 and continued for two years, effectively neutralizing the CIA's sources of information on a major intelligence target.