Iron Lady
Iron Lady

@nuwangzi

5 Tweets 25 reads Jul 19, 2023
#PLA #Cyber #SIGINT
*Thread*
The 2nd Technical Reconnaissance Bureau (AKA Unit 61398) was a Cyber-SIGINT unit that has systematically stolen massive data from at least 141 organizations across 20 industries worldwide since as early as 2006.
But what happened to that unit?
1/4
The 2TRB, then under the 3rd Department of former GSD, was stationed in Shanghai and operated via eight offices and several SIGINT (Work) stations.
Some of its offices were located within universities and hotels. Other stations were located in south China.
2/5
This unit was known in the cyber community as APT1, Comment Crew, Comment Panda, GIF89a, and Byzantine Candor
Between 2011 and 2012, this unit was reportedly hacked into top Israeli defense technology companies and possibly stole air defense technologies in order to clone it.
On 19 May 2014, the US DOJ announced that a Federal grand jury had returned an indictment of five 61398 officers on charges of theft of confidential business information and intellectual property from U.S. commercial firms and of planting malware on their computers.
3/5
Following this indictment, The unit was β€œvanished”, officers were moved to other TRBs, integrated to the MSS or experienced some sort of punishment.
The entity 2TRB may have gone, but its facilities are operating as usual, now under the newly Strategic Support Force (SSF).
5/5

Loading suggestions...