ClaimUnverified
A China IP is not a finding that Beijing ran the 9 March hack
Routing fact · operator unknown
CSM said exfiltrated mail went to an IP address in China. Headlines called it a Chinese hack. The agency did not publish a named operator. Compromised machines, third-party infrastructure and a false flag remain live. Not established, not ruled out.
Destination geolocation is the weakest form of attribution. The working chart is right to keep ‘unknown attacker(s)’ on the map and to list state-linked, non-state, third-party and false-flag as open. File the IP as CSM’s reported routing. File ‘China did it’ as unverified.
Sources
- The Star / CSM, 20 Aug 2014; working chart · two waves
Related
TimelineConfirmed9 Mar 2014
Investigation networks spear-phished the day after MH370 vanished
CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014
EvidenceOpen9 Mar 2014
Two waves of MH370-themed cyberattacks
9 March official-network intrusion · March–April public malware lures
HypothesisOpen
Interstate politics — China, Russia, Iran
Manifest geography is not a state-act finding