Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

5/9/2019
05:40 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

US DoJ Indicts Chinese Man for Anthem Breach

Fujie Wang allegedly worked as part of a hacking team out of China that stole information on nearly 80 million Americans in the massive healthcare breach.

The US Department of Justice (DoJ) today unsealed an indictment of a Chinese national who allegedly was part of a hacking group in China behind the massive 2015 data breach of Anthem, as well as attacks on three other large US businesses.

As part of the hacking group, Fujie Wang, aka Dennis Wang and Wang Fujie, 32, allegedly helped steal names, identification numbers, birthdates, Social Security, and other personal information about 78.8 million people in the Anthem breach, as well as in attacks on unnamed technology, communications, and materials sector companies, according to the indictment. Also included in the filing is an unnamed individual named John Doe, aka Deniel Jack, Kim Young, and Zhou Zhihong, who, along with Wang, was charged with one count of conspiracy to commit fraud and related activity in relation to computers and identity theft, one count of conspiracy to commit wire fraud, and two counts of intentional damage to a protected computer.

While the DoJ indictment did not name the Chinese hacking team, Symantec previous had identified the Anthem hackers as part of the so-called Black Vine group that has been active since around 2012, targeting healthcare, aerospace, and energy organizations. The group was believed to have some ties to a China-based IT security organization named Topsec.

The findings documented in this report lead Symantec to believe that Black Vine is an attack group that has working relationships with multiple cyberespionage actors. The group is well-funded and organized, according to Symantec, and comprises at least a few members, some of whom may have a past or present association with a China-based IT security organization called Topsec.

"The allegations in the indictment unsealed today outline the activities of a brazen China-based computer hacking group that committed one of the worst data breaches in history," said Assistant Attorney General Brian Benczkowski. "These defendants allegedly attacked U.S. businesses operating in four distinct industry sectors, and violated the privacy of over 78 million people by stealing their PII."

But like most DoJ indictments of foreign nationals living in nations where the US has no extradition agreement, it's unlikely Wang will be apprehended by US authorities unless he travels outside China or Chinese officials turn him over to the US. Even so, the DoJ began executing its indictment strategy five years ago, starting with the historic indictment of five Chinese military officers for leading cyberattacks that stole intellectual property from major American steel, solar energy, and other manufacturing companies, including Alcoa, Westinghouse Electric, and US Steel.

Patiently Waiting
According to the indictment, the hackers began their attacks with spear-phishing emails that contained malicious URLs to employees at the victim businesses: Clicking on that link sent backdoor malware to the victim's machine. "Defendants sometimes patiently waited months before taking further action," the indictment said.

The attackers then began moving laterally and gathered intelligence, including from Anthem's data warehouse during October and November of 2014, where it stored PII information

In 2015, they ultimately siphoned the stolen data from Anthem in encrypted archive files and sent them to several locations in China, via the Citrix ShareFile data storage and transfer service as part of that transport. The attackers later deleted the archive files from the victim networks to cover their tracks.

Main Domain Man
Wang allegedly managed and controlled two domain names associated with the hacking group's operation. The attackers were tossed from Anthem's network around Jan. 31, 2015, when the healthcare company began its incident response operation.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5230
PUBLISHED: 2019-11-13
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform...
CVE-2019-5231
PUBLISHED: 2019-11-13
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
CVE-2019-5233
PUBLISHED: 2019-11-13
Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.
CVE-2019-5246
PUBLISHED: 2019-11-13
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain par...
CVE-2010-4177
PUBLISHED: 2019-11-12
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.