Investigation networks spear-phished the day after MH370 vanished
CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014
Confirmed as CSM’s public account. On 9 March, officials at the Department of Civil Aviation, the National Security Council and Malaysia Airlines were sent malware disguised as a news article that the aircraft had been found. About thirty computers were infected. Outbound mail carrying confidential files, including meeting minutes and classified documents, some related to MH370, was traced to an IP in China. CSM shut the machines down and asked Chinese providers to block the traffic. Police and Interpol were involved. What exactly was stolen is still unpublished.
The Star, 20 August 2014, quoting CyberSecurity Malaysia CEO Amirudin Abdul Wahab: administrators reported networks congested with outbound email; those mails held confidential data from officials’ computers; some of it related to the MH370 investigation; the destination was an IP address in China; the malware was a well-crafted PDF/news lure that antivirus missed. About thirty PCs. Motive, CSM said, appeared to be the investigation itself — at a moment when the government was being accused of holding information back. That is a contemporaneous official account, not a reconstructed loot list. It does not name radar recordings, search orders, or who sat behind the China IP. A destination address is a routing fact. It is not attribution. The timing — while military primary was being played back and the civilian rescue centre had not yet been told of the west track — is the reason the event sits next to the radar file. Convert timing into a finding only with a document that was actually taken.
Sources
- The Star, 20 Aug 2014 — Hacker targets info on MH370 probe
- Malay Mail, 20 Aug 2014
- South China Morning Post, 20 Aug 2014
Related
Two waves of MH370-themed cyberattacks
9 March official-network intrusion · March–April public malware lures
The radar story and the 9 March cyberattack
Working chart · tracks, delays, and a spear-phish of the investigation
CyberSecurity Malaysia
National cyber agency · publicly described the 9 March intrusion in August 2014
MyCERT: MH370-themed backdoor and fake-transcript spear-phish
MA-381 · 24 March 2014 · MA-386 · 18 April 2014
What was actually taken on 9 March — and did it include radar?
A China IP is not a finding that Beijing ran the 9 March hack
Routing fact · operator unknown
West-track disclosure lag — ministerial 10:30, ARCC 22:30, Thai 9–10 days
8 March and 18–19 March 2014
RMAF notifies KL ARCC of the western military track
22:30 MYT 8 March 2014 · ~12 hours after the minister