Skip to content

Resources

Resources

Official papers, films, Wikipedia and its citations, programmes, claims and open questions.

10 hits

TimelineConfirmed9 Mar 2014

Investigation networks spear-phished the day after MH370 vanished

CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014

Confirmed as CSM’s public account. On 9 March, officials at the Department of Civil Aviation, the National Security Council and Malaysia Airlines were sent malware disguised as a news article that the aircraft had been found. About thirty computers were infected. Outbound mail carrying confidential files, including meeting minutes and classified documents, some related to MH370, was traced to an IP in China. CSM shut the machines down and asked Chinese providers to block the traffic. Police and Interpol were involved. What exactly was stolen is still unpublished.

EvidenceOpen9 Mar 2014

Two waves of MH370-themed cyberattacks

9 March official-network intrusion · March–April public malware lures

Working chart of two separate campaigns. Attack one: 9 March spear-phish of officials at the Department of Civil Aviation, National Security Council and Malaysia Airlines — CyberSecurity Malaysia’s public account, disclosed in August. Attack two: MyCERT alerts on 24 March and 18 April about MH370-themed backdoors and a fake investigation-transcript phish aimed more widely. Destination IP in China is not the same as a finding that Beijing ran the operation.

TimelineConfirmed24 Mar 2014

MyCERT: MH370-themed backdoor and fake-transcript spear-phish

MA-381 · 24 March 2014 · MA-386 · 18 April 2014

Confirmed public advisories, a different campaign from the 9 March official-network intrusion. 24 March: a Facebook-app lure dropping a backdoor with remote-control (C2) capability. 18 April: emails posing as an investigation team / ICAO portal item, password-protected archive, fake MH370 transcript, command-and-control. Aimed at organisations and the public, not shown to be the DCA/NSC/MAS breach.

Open questionOpen

What was actually taken on 9 March — and did it include radar?

CSM said minutes of crisis meetings and classified documents, some related to MH370. The working chart asks whether radar information or discussions of the turn-back were in that set. No public loot list answers it. A negative would also be a finding.

EvidenceOpen9 Mar 2014

The radar story and the 9 March cyberattack

Working chart · tracks, delays, and a spear-phish of the investigation

Two panels. Left: civilian secondary, Malaysian military primary, Thai paint disclosed ten days later, and the 12-hour lag before the civilian rescue centre was told. Right: one day after the loss, officials on the investigation were hit with a spear-phish that CyberSecurity Malaysia later said stole classified material toward an IP in China. Presence of a hack is confirmed as that agency’s public account. What was in the take — and whether it included radar — is still open.

OrganisationConfirmed20 Aug 2014

CyberSecurity Malaysia

National cyber agency · publicly described the 9 March intrusion in August 2014

Confirmed. Agency under the then Ministry of Science, Technology and Innovation. CEO Amirudin Abdul Wahab is the named source for the 9 March spear-phish of investigation officials. Digital forensics support to the affected departments; work with police and Interpol.

ClaimUnverified

A China IP is not a finding that Beijing ran the 9 March hack

Routing fact · operator unknown

CSM said exfiltrated mail went to an IP address in China. Headlines called it a Chinese hack. The agency did not publish a named operator. Compromised machines, third-party infrastructure and a false flag remain live. Not established, not ruled out.

EvidenceConfirmed10 Apr 2013

Hugo Teso, 2013 — FMS proof-of-concept

Hack in the Box · research demonstration, not a 9M-MRO finding

Confirmed as a public research talk: Teso showed that flight-management logic could be reached and manipulated in a lab/simulation setting. FAA disputed operational risk. No record in this file places that path on 9M-MRO.

DocumentConfirmed1 Mar 2019

USAF PB2020 — MAGIC/Orion continued after 2014

PE 0305205F · Congressional adds FY2015–FY2018

MAGIC/Orion did not fade from the budget after 2014. Adds: $20m FY2015, $5m FY2016, $50m FY2017, $40m FY2018, on top of $19m FY2012 and $50m FY2013. Post-2016 money was for airworthiness, cybersecurity, interoperability and mission capability toward a deployable Block 1 Orion.

EvidenceOpen20 Sep 2026

Remote-control claims versus evidence gaps

Patent, QF-16, Teso FMS proof-of-concept · installation on 9M-MRO still open

Working chart: unmanned flight of a fighter-class jet was demonstrated in 2013; Boeing’s uninterruptible-autopilot patent exists; Hugo Teso showed an FMS proof-of-concept the same year. Boeing told Malaysian investigators there was no commercial implementation on the 2002 delivery. Radar proves a turn at IGARI, not who commanded it. Ten data requests remain.

273 records in the file.