Skip to content

Resources

Resources

Official papers, films, Wikipedia and its citations, programmes, claims and open questions.

6 hits

TimelineConfirmed9 Mar 2014

Investigation networks spear-phished the day after MH370 vanished

CyberSecurity Malaysia · ~30 PCs · disclosed 20 August 2014

Confirmed as CSM’s public account. On 9 March, officials at the Department of Civil Aviation, the National Security Council and Malaysia Airlines were sent malware disguised as a news article that the aircraft had been found. About thirty computers were infected. Outbound mail carrying confidential files, including meeting minutes and classified documents, some related to MH370, was traced to an IP in China. CSM shut the machines down and asked Chinese providers to block the traffic. Police and Interpol were involved. What exactly was stolen is still unpublished.

OrganisationConfirmed20 Aug 2014

CyberSecurity Malaysia

National cyber agency · publicly described the 9 March intrusion in August 2014

Confirmed. Agency under the then Ministry of Science, Technology and Innovation. CEO Amirudin Abdul Wahab is the named source for the 9 March spear-phish of investigation officials. Digital forensics support to the affected departments; work with police and Interpol.

ClaimUnverified

A China IP is not a finding that Beijing ran the 9 March hack

Routing fact · operator unknown

CSM said exfiltrated mail went to an IP address in China. Headlines called it a Chinese hack. The agency did not publish a named operator. Compromised machines, third-party infrastructure and a false flag remain live. Not established, not ruled out.

Open questionOpen

What was actually taken on 9 March — and did it include radar?

CSM said minutes of crisis meetings and classified documents, some related to MH370. The working chart asks whether radar information or discussions of the turn-back were in that set. No public loot list answers it. A negative would also be a finding.

TimelineConfirmed24 Mar 2014

MyCERT: MH370-themed backdoor and fake-transcript spear-phish

MA-381 · 24 March 2014 · MA-386 · 18 April 2014

Confirmed public advisories, a different campaign from the 9 March official-network intrusion. 24 March: a Facebook-app lure dropping a backdoor with remote-control (C2) capability. 18 April: emails posing as an investigation team / ICAO portal item, password-protected archive, fake MH370 transcript, command-and-control. Aimed at organisations and the public, not shown to be the DCA/NSC/MAS breach.

EvidenceOpen9 Mar 2014

Two waves of MH370-themed cyberattacks

9 March official-network intrusion · March–April public malware lures

Working chart of two separate campaigns. Attack one: 9 March spear-phish of officials at the Department of Civil Aviation, National Security Council and Malaysia Airlines — CyberSecurity Malaysia’s public account, disclosed in August. Attack two: MyCERT alerts on 24 March and 18 April about MH370-themed backdoors and a fake investigation-transcript phish aimed more widely. Destination IP in China is not the same as a finding that Beijing ran the operation.

273 records in the file.