Comment Crew Exposé a New Level of China Attack Attribution

China has been blamed for cyberattacks on every major industrial base in the United States—and even in some corners for the Super Bowl blackout. But most of it has been rampant speculation coupled with the lacing together of a number of loose ends. Examples of the kind of direct attribution to the People’s Liberation Army (PLA) presented in a report today by security company Mandiant have been rare.

ChinaChina has been blamed for cyberattacks on every major industrial base in the United States—and even in some corners for the Super Bowl blackout. But most of it has been rampant speculation coupled with the lacing together of a number of loose ends. Examples of the kind of direct attribution to the People’s Liberation Army (PLA) presented in a report today by security company Mandiant have been rare.

Mandiant’s expose on the Comment Crew, responsible it said for infiltrations against 141 organizations in 20 industries—most of them located in English-speaking nations—reveals a seven-year operation focused on stealing terabytes of secret data ranging from intellectual property, test results, technology blueprints, as well as personal and corporate information such as email messages and contact lists. The report goes so far as to out three specific individuals involved, and the building and neighborhood where the gang operates.

The report also comes at a time when there is increased chatter from policymakers in Washington about Chinese hacking activity, its impact on the U.S. economy, and how it is, in part, the basis for China’s rapid economic growth. Last week’s executive order from President Barack Obama, which outlined a number of voluntary information-sharing initiatives between the public and private sector, was directed at a number of critical infrastructure industries that are favorite targets of the China described in the Mandiant report.

“The issue of attribution has always been a missing link in publicly understanding the landscape of APT cyber espionage,” the report said. “Without establishing a solid connection to China, there will always be room for observers to dismiss APT actions as uncoordinated, solely criminal in nature, or peripheral to larger national security and global economic concerns.”


Mandiant said it has been monitoring the activity of this particular group, which it labeled APT1, since 2006. It gathered enough evidence to link APT1 to the 2nd bureau of the PLA General Staff Department’s (GSD) 3rd Department, also known as Unit 61398, a group whose work is considered a state secret. The unit is staffed by specialists who skilled in English linguistics, as well as cover communications, network security, operating system internals and digital signing processes. Recruits primarily are plucked from a pair of universities, the Harbin Institute of Technology and Zhejiang University School of Computer Science and Technology.

As for the building in which the group operates, it’s a technological powerhouse, the report said. Located in the Pudong New Area of Shanghai, hundreds up to 2,000 work in the 12-story building which was wired with a special fiber optic communication infrastructure installed by China Telecom under special national defense orders, the report said.

The group’s specialty is persistence; using an arsenal of 42 families of backdoor malware and a nest egg of stolen credentials, they were able to keep access to victim networks on average up to a year without detection. The longest was four years and 10 months, Mandiant said, adding that data theft and pivoting about compromised networks was nonstop as long as access was maintained. Most of the victims were in the U.S., U.K., and Canada and businesses and government agencies that conduct business in English. The group stole indiscriminately from victims across the board in terms of industry type. Attacks were carried out against IT companies, aerospace, satellites and telecommunications, scientific research, energy, transportation, among many others related to specific strategic priorities listed by the Chinese. Attacks ramped up in 2011 in particular when 17 new victims were compromised from 10 industries; each was accessed simultaneously and in one case, 6.5 terabytes of data was stolen during a 10-month period.

“The results suggest that APT1’s mission is extremely broad; the group does not target industries systematically, but more likely steals from an enormous range of industries on a continuous basis,” the report said.

MandiantMandiant said it was able to cement the connection between APT1 and the Chinese because the attackers were forced by censorship measures in China to log into social media accounts such as Facebook and Twitter directly from their attack infrastructure. This, Mandiant said, helped simplify attribution.

Attacks attributed to Comment Crew follow a lifecycle typical to other APT actors, starting with a spear-phishing campaign that gives the attackers an initial foothold to start installing backdoors for communication with command and control servers. Credentials are stolen using publicly available password cracking tools enabling the attacker to pivot from system to system gaining access to shared resources and dropping more backdoors, further strengthening network persistence. All the while, data is accessed, archived and moved off the network disguised as normal network traffic over HTTP. Mandiant also noticed a number of custom tools in play, including two targeting email messages on Exchange Servers and PST messages archived in Outlook.

Mandiant was able to observe APT1’s command and control infrastructure and map locations to IP addresses in 13 countries. It said that in almost all instances where Comment Crew members connected to C&C, they were doing so with IP addresses registered in Shanghai and using systems set to Simplified Chinese language keyboard layouts over the Microsoft Remote Desktop client.

“The sheer scale and duration of sustained attacks against such a wide set of industries from a singularly identified group based in China leaves little doubt about the organization behind APT1,” the report said. “We believe the totality of the evidence we provide in this document bolsters the claim that APT1 is Unit 61398.”

Suggested articles


  • Anonymous on


    A secret, resourced organization full of mainland Chinese speakers with direct access to Shanghai-based telecommunications infrastructure is engaged in a multi-year, enterprise scale computer espionage campaign right outside of Unit 61398’s gates, performing tasks similar to Unit 61398’s known mission.


    APT1 is Unit 61398."




  • Anonymous on

    Why would they use Shanghai and use RDP? If people want to monitor you, they wouldn't use RDP. They wouldn't route and connect using RDP. These are some bogus techniques that it still doesn't make any sense.
  • AkbarRi on

    Only that "Youtube Video" that i dont understand.

    How the heck "Mandiant" recorded that?!

    It's seem like RD via SCCM, but how they do it?! Hacking a Hacker?!

    And why Chinese Hacker don't use Chinese Windows Version?! I think to get usual with English ^^v

  • Anonymous on

    i like how a large portion of this report is mandiant's superior googling skills. 


  • Anonymous on

    When forensic data specialists capture a data, it really isn’t a magical RDP session. They are various tools create foot prints. This security firm is the most talked about $100 million revenue cutting edge firm? Some of these techniques should have been caught by modern software.

  • Jeremy on

    How did Mandiant record or captured the screens of the hackers? Can someone please explain or answer? I dont think it was a simulation but they were actually recording it...

  • baby nfl jerseys on

    Anthem s rate filing includes projections for health insurance costs in their bronze plans. A 47-year-old male who does not smoke would be charged, on average, $307 per month. Sample plans from another plan, MDWise, predict a 47-year-old man will be charged $294 and $391 for a bronze and silver plan, respectively. baby nfl jerseys
  • Aumlib, Ixeshe Malware Updated in Targeted China Attacks | Threatpost on

    [...] 12 is not the same as the Comment Crew, also known as APT 1; APT 12 is very active and quiet, Mandiant [...]

Subscribe to our newsletter, Threatpost Today!

Get the latest breaking news delivered daily to your inbox.