Cybersecurity company CrowdStrike claims that China launched a cyber espionage campaign to help the Commercial Aircraft Corporation of China (Comac) acquire sensitive information that led to the development of the C919.
Chinese hackers may have saved billions of dollars in development costs for the C919 through acquiring technical specifications of western aircraft, researchers believe.
The fundamental aim of this operation appears to have been decreasing Chinese dependency on western commercial airline companies and break the traditional duopoly maintained by Airbus and Boeing.
“Beijing still has a long way to go before it has a completely independent domestic commercial aviation industry, as evidenced by the $45 billion deal to purchase 300 Airbus planes during President Xi Jinping’s recent visit to France,” the report stated.
“Xi inked a similar purchase agreement for 300 Boeing planes during a November 2017 visit to the US. Yet China still seeks to decrease its dependence on this duopoly and eventually compete on an even footing with them,” the report added.
Recommended
- ‘Hacker-for-hire’ sentenced for cybercrime offences
- The global economy loses £2.3 million to cybercrime every minute
- Dark Web cybercrime markets are thriving
Development of the twinjet C919 aircraft commenced more than a decade ago but was fraught with lengthy setbacks and delays. In 2017, the jet made its maiden flight. However, despite Chinese claims that the airliner is a homegrown design, a significant number of western-made components are used in the aircraft.
CrowdStrike’s report claims that over a five year period between 2010 and 2015, researchers monitored a Chinese hacking group which has come to be known as Turbine Panda. The group is believed to be responsible for a number of cyber attacks against companies which supplied components for the C919.
The cyber espionage campaign was led by the Jiangsu Bureau (JSSD) of the secretive Ministry of State Security (MSS). Officers were selected by JSSD to recruit inside sources at foreign – mainly North American and European – aviation companies. Additionally, another JSSD asset was placed in control of the Turbine Panda hacking group, which carried out many of the espionage operations.
Five year’s worth of operation saw Turbine Panda infiltrate and successfully breach a host of supplier companies, which include Capstone Turbine, Honeywell, GE and many more. Malware was used to great effect by the group throughout the campaign, which was deployed on supplier machines and used to siphon trade secrets and intellectual property.
Two specific types of malware, PlugX and Winnti, were used extensively by the hacker group. Interestingly, the Crowdstrike report notes that another type, dubbed ‘Sakula’, was used. This particular form of malware was assessed to be unique to the group.
The Aero Engine Corporation of China (AECC) revealed its new homegrown engine, dubbed the CJ-1000AX, in 2016. This engine was earmarked to replace the C919 engine, built by US contractor CFM International.
However, Crowdstrike claims that the CJ-1000AX displayed “many similarities” to two engines developed by CFM – namely the LEAP-1C and LEAP-X engines.
From August 2017 to October 2018, the US Department of Justice (DoJ) released several indictments against a host of Chinese intelligence-linked figures, including Yu Pingan, developer of the Sakula malware used during the cyber espionage campaign, as well as JSSD intelligence office Xu Yanjun.
Xu Yanjun is believed to have led the recruitment of insider assets at aerospace companies targeted during the cyber espionage operation.
GE employee and insider, Zheng Xiaoqing and a host of other JSSD affiliated cyber operators were also included in the series of indictments.
“What makes these DoJ cases so fascinating is that, when looked at as a whole, they illustrate the broad, but coordinated efforts the JSSD took to collect information from its aerospace targets,” the Crowdstrike report noted.
“In particular, the operations connected to activity CrowdStrike Intelligence tracked as Turbine Panda showed both traditional human-intelligence (HUMINT) operators and its cyber operators working in parallel to pilfer the secrets of several international aerospace firms.”






