Skip to content
TimelineConfirmed9 Mar 2014Investigation

Investigation networks spear-phished the day after MH370 vanished

CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014

Open in cross-ref

Confirmed as CSM’s public account. On 9 March, officials at the Department of Civil Aviation, the National Security Council and Malaysia Airlines were sent malware disguised as a news article that the aircraft had been found. About thirty computers were infected. Outbound mail carrying confidential files, including meeting minutes and classified documents, some related to MH370, was traced to an IP in China. CSM shut the machines down and asked Chinese providers to block the traffic. Police and Interpol were involved. What exactly was stolen is still unpublished.

The Star, 20 August 2014, quoting CyberSecurity Malaysia CEO Amirudin Abdul Wahab: administrators reported networks congested with outbound email; those mails held confidential data from officials’ computers; some of it related to the MH370 investigation; the destination was an IP address in China; the malware was a well-crafted PDF/news lure that antivirus missed. About thirty PCs. Motive, CSM said, appeared to be the investigation itself — at a moment when the government was being accused of holding information back. That is a contemporaneous official account, not a reconstructed loot list. It does not name radar recordings, search orders, or who sat behind the China IP. A destination address is a routing fact. It is not attribution. The timing — while military primary was being played back and the civilian rescue centre had not yet been told of the west track — is the reason the event sits next to the radar file. Convert timing into a finding only with a document that was actually taken.

Sources

Related