Intellectual Property Stolen from Japanese Companies in Chinese Cyberattacks—GoldenSpy and the Grave Reasons Behind the Exclusion of Huawei
This article examines allegations that Chinese hackers stole video-game source code, high-performance gas-turbine drawings and specifications, medical-device data, and other intellectual property from Japanese companies. It also addresses the GoldenSpy malware found in Chinese government-mandated tax software, the exclusion of Huawei by the United States and the United Kingdom, and the national-security risks posed by backdoors in routers and communications equipment.
September 2, 2020
Chinese Cyberattacks That Stole Intellectual Property from Japanese Companies—“GoldenSpy,” Huawei, and the National-Security Threats Hidden in Communications Equipment
The following is taken from an article by Fumiaki Yamasaki, Chief Researcher at the Institute of Information Security, published in this month’s issue of the monthly magazine Hanada as part of its major special feature, “Fight Back Against Xi Jinping! Zoom, TikTok, Huawei… Chinese Cyberweapons More Frightening Than Nuclear Weapons.”
This is essential reading not only for the Japanese people but for people throughout the world.
Withdraw from Business in China Immediately
On July 21, the United States Department of Justice announced the indictment of two Chinese nationals, Li Xiaoyu, aged thirty-four, and Dong Jiazhi, aged thirty-three, for attempting to steal information from research institutions in the United States working on vaccines for COVID-19.
According to Assistant Attorney General for National Security John Demers, the two suspects were also believed to have stolen intellectual property from hundreds of companies in the United States and elsewhere, including Japan, and to have targeted human-rights activists in mainland China and Hong Kong.
In cases involving Japanese companies, the stolen material reportedly included the source code of video games, drawings and specifications for high-performance gas turbines, and medical-device data.
The two men were classmates at the University of Electronic Science and Technology of China in Chengdu and were said to have links to officials in China’s intelligence agency, the Ministry of State Security.
The damage extended beyond the United States and Japan to the United Kingdom, Germany, Australia, Sweden, Belgium, the Netherlands, Spain, and South Korea.
The two men are currently believed to be in China, beyond the jurisdiction of United States law enforcement.
On July 14, the American security company Trustwave discovered that a computer virus was hidden in Golden Tax Invoicing Software, or GTS, tax software that the Chinese government requires companies to install.
In response, the FBI distributed a document on July 23 warning American companies that “tax software mandated by the Chinese government contains malware that enables backdoor access” (Alert No. AC-0001291TT).
A backdoor enables unauthorized access, while malware means a malicious computer program.
GTS is a system used to issue receipts for China’s value-added tax, known as the 増値税, equivalent to Japan’s consumption tax, and to pay taxes to the Chinese taxation authorities.
However, when the software is installed, a computer virus is reportedly downloaded at the same time.
It bypasses the computer’s authentication functions and thereafter allows the computer to be freely controlled from outside in privileged mode, through which all settings and administrative functions can be accessed.
Who could imagine that a virus would be embedded in official software whose installation was mandated by the government of a country?
It has been said that the Chinese government’s purpose is to detect companies evading value-added tax.
However, once this virus, named “GoldenSpy,” penetrates a computer, it can freely access personal information and intellectual-property information, leaving all of a company’s information exposed.
This fact alone constitutes an incident serious enough for Japanese companies to consider withdrawing from business in China.
The “Five Companies” Excluded by the United States
On July 14, the United States federal government announced in the Federal Register that, as a measure based on Section 889 of the National Defense Authorization Act enacted in 2018, companies doing business with five major Chinese communications-equipment manufacturers would be excluded from federal-government procurement beginning on August 13.
The five companies were Huawei Technologies, ZTE, Hytera Communications, Hikvision Digital Technology, and Zhejiang Dahua Technology.
This was the second stage of measures following the prohibition, which took effect on August 13 of the previous year, on transactions between those five companies and the federal government.
Some regarded it as part of the United States’ protest against the implementation of the Hong Kong National Security Law, formally the Law of the People’s Republic of China on Safeguarding National Security in the Hong Kong Special Administrative Region.
However, it was fundamentally a measure already established as government policy in the preceding year.
Huawei and ZTE are both widely known in Japan as major communications-equipment manufacturers, while Hytera is another leading radio-equipment manufacturer.
Hikvision and Dahua Technology manufacture surveillance cameras, and because of the low prices of their products, their equipment has been adopted in large quantities in both the United States and Japan.
More than eight hundred Japanese companies are said to do business with the United States federal government, and the measure will probably have a considerable impact on Japan.
Sony, for example, supplies Hikvision with ultra-high-sensitivity image sensors and other components.
The movement to exclude Chinese communications equipment is not confined to the United States.
Following Australia, which decided on exclusion in 2018, the British government announced on July 14 that it would remove Huawei products from the United Kingdom’s 5G networks.
The decision was reportedly based on the latest advice from the United Kingdom’s National Cyber Security Centre, or NCSC.
Purchases of Huawei 5G products were to be completely prohibited after December 31 of that year.
The British government estimated that this would delay the deployment of 5G by two or three years and cost up to two billion pounds, approximately 269.5 billion yen.
Nevertheless, it declared that “national security is a vital duty of government to the people and must take precedence over all other considerations,” in a statement by Oliver Dowden, Secretary of State for Digital, Culture, Media and Sport, and decided to remove Huawei products completely by the end of 2027.
Why the World Moved Toward Exclusion
Although it is not widely known in Japan, Huawei established the Huawei Cyber Security Evaluation Centre, or HCSEC, within its British subsidiary in 2010 in an effort to win the trust of the British government and has used it to examine the safety of its communications equipment.
The evaluation reports produced there are sent to the Huawei Cyber Security Evaluation Centre Oversight Board, established within the NCSC in 2014, for final annual review.
All thirty-eight HCSEC staff members engaged in the evaluation work had passed the Vetting Security Clearance background checks developed by the NCSC for people seeking positions within British state institutions.
HCSEC therefore emphasized the neutrality of its evaluation results.
In February of the previous year, HCSEC had initially reported that the risks of using Huawei products in 5G could be controlled.
Behind the United Kingdom’s subsequent decision to exclude Huawei products from its 5G networks, however, lay an ineradicable distrust of Huawei’s technical capabilities and products.
In its “NCSC Advice on the Use of Equipment from High-Risk Vendors in UK Telecoms Networks,” published on January 28 of that year, the NCSC explained its reasons for excluding Huawei as follows:
“Our experience has shown that Huawei’s cybersecurity and engineering quality is low and that its processes are opaque. For example, the HCSEC Oversight Board expressed serious concerns in 2018 about Huawei’s engineering processes. Its 2019 report confirmed that there had been ‘no material progress’ by Huawei in correcting the technical issues reported in the 2018 report and highlighted ‘further significant technical issues’ that had not previously been identified.”
In other words, testing conducted on certain products in 2018 found hundreds of vulnerabilities.
The following year’s evaluation showed not only that those vulnerabilities had not been corrected but also that new technical problems had been discovered.
The conclusion, therefore, was that Huawei had to be described as lacking sufficient technical capability.
Huawei itself had in fact acknowledged this point, issuing a statement that improvements would take five years.
The word “vulnerability” is generally used to describe a defect or design error in a computer, operating system, or software.
However, leaving a problem unresolved for more than a year inevitably invites accusations that it is an intentional vulnerability—that is, a vulnerability deliberately created to make hacking possible.
The “further significant technical issues” identified by the NCSC referred to the fact that the source code of four products supplied by Huawei for evaluation did not match the source code of the products actually being used in the United Kingdom.
For the evaluation versions and the actual products to contain different code is an inconceivable situation that undermines the very foundations of HCSEC’s work.
Eavesdropping Functions in Routers
The problem is not limited to Huawei.
In January of that year, passwords for products made by Tenda, which had been increasing its share of the Japanese market with low-priced Wi-Fi routers, were exposed on the Internet.
According to Independent Security Evaluators, or ISE, a Baltimore-based American cybersecurity company that discovered the problem, the password was a fixed password written into the router—a default or initial password embedded in the hardware—and could be used with any Tenda router of the same model.
Consequently, if a hacker used that password, the hacker could remotely access the router and easily steal information.
It is not necessary to conceal an eavesdropping chip in communications equipment such as a router beforehand or to install a surveillance program in advance.
A manufacturer possessing the source code of the program that controls the communications equipment can, if it so chooses, give a particular device an eavesdropping function under the guise of a product update.
The installation of an eavesdropping program in communications equipment, including routers, represents one of the greatest possible cybersecurity threats.
Corporate networks are normally protected by a perimeter-defense system known as a firewall.
Routers, however, are installed outside that firewall, meaning that no one may notice even when data is being transferred improperly.
More than six months after the problem emerged in January, Tenda had still taken no action.
The fact that the discovered vulnerability had been left unresolved for more than six months was the same as with Huawei’s communications equipment.
Tenda still appeared to have offered no explanation.
Could it possibly claim that its response had been delayed because a new vulnerability had been discovered?
Or could it claim that the default password was merely a design error?
Neither explanation would normally be conceivable.
What has occurred can only appear to have been done deliberately.
Cases in which surveillance programs were embedded in hardware such as communications equipment had, in fact, already occurred in Japan.
In July 2015, file-sharing software known as BitTorrent was detected on a Taiwanese-made hard disk purchased by the Nuclear Material Control Center, a public-interest incorporated foundation.
The hard disk on which the virus was detected was made by the Taiwanese manufacturer D-Link, but it had been manufactured in China.
Quasi-public institutions such as public-interest foundations use a lowest-price bidding system, under which suppliers are selected solely on the basis of the bid price.
Consequently, Taiwanese and Chinese manufacturers are adopted in an overwhelmingly large number of cases.
The Nuclear Material Control Center stated that it had been subjected to 698 unauthorized accesses from servers in the United States and elsewhere but that no information had been leaked.
However, because file-sharing software automatically transfers the contents of a hard disk, the information that may have been transferred is a matter of profound concern.
Even if a product is described as “made in Taiwan,” when it is manufactured in China, it is impossible to dismiss the danger that mechanisms for stealing information, known as backdoors, may be incorporated into it.
Chinese-made robots have recently made remarkable advances into the Japanese market, and in some cases the routers and tablets built into them are made by Huawei.
The reality is that it has become impossible to identify Chinese manufacturers merely from a company’s name or stated nationality.
To be continued.