<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=PLA_Unit_61398</id>
	<title>PLA Unit 61398 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=PLA_Unit_61398"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=PLA_Unit_61398&amp;action=history"/>
	<updated>2026-09-24T03:10:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=PLA_Unit_61398&amp;diff=430215&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=PLA_Unit_61398&amp;diff=430215&amp;oldid=prev"/>
		<updated>2023-09-25T18:45:15Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|Chinese advanced persistent threat unit}}&lt;br /&gt;
{{Expand Chinese|topic=mil|date=February 2013}}&lt;br /&gt;
{{Use dmy dates|date=November 2014}}&lt;br /&gt;
{{Infobox military unit&lt;br /&gt;
| unit_name                     = People&amp;#039;s Liberation Army Unit 61398&lt;br /&gt;
| native_name                   = 61398部队&lt;br /&gt;
| image                         = China Emblem PLA.svg&lt;br /&gt;
| caption                       = Emblem of the People&amp;#039;s Liberation Army&lt;br /&gt;
| dates                         = 2014-Present&lt;br /&gt;
| country                       = {{PRC}}&lt;br /&gt;
| allegiance                    = {{CCP flag}}&lt;br /&gt;
| command_structure             = {{armed forces|China}}&lt;br /&gt;
| branch                        = [[File:PLASSF.svg|23px]] [[People&amp;#039;s Liberation Army Strategic Support Force]]&lt;br /&gt;
| type                          = [[Cyber force]], Cyber-espionage Unit&lt;br /&gt;
| specialization                = [[Cyberwarfare in China|Cyber warfare]] &amp;lt;br&amp;gt; [[Electronic warfare]]&lt;br /&gt;
| size                          = &lt;br /&gt;
| garrison                      = Tonggang Road, [[Pudong]], [[Shanghai]]&lt;br /&gt;
| commander1_label              = &lt;br /&gt;
| commander1                    = &lt;br /&gt;
| commander2                    = &lt;br /&gt;
| commander2_label              = &lt;br /&gt;
| commander3_label              = &lt;br /&gt;
| commander3                    = &lt;br /&gt;
| nickname                      = {{Bulleted list|APT 1|Comment Crew|Comment Panda|GIF89a|Byzantine Candor|Group 3|Threat Group 8223}}&lt;br /&gt;
| motto                         = &lt;br /&gt;
| colors                        = &lt;br /&gt;
| march                         = &lt;br /&gt;
| mascot                        = &lt;br /&gt;
| equipment                     = &lt;br /&gt;
| equipment_label               = &lt;br /&gt;
| battles                       = * [[GhostNet|Operation GhostNet]]&lt;br /&gt;
* [[Operation Aurat ]]&lt;br /&gt;
* [[Operation Shady RAT]]&lt;br /&gt;
| notable_commanders            = &lt;br /&gt;
| anniversaries                 = &lt;br /&gt;
| identification_symbol         = &lt;br /&gt;
}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;PLA Unit 61398&amp;#039;&amp;#039;&amp;#039; (also known as &amp;#039;&amp;#039;&amp;#039;APT 1&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;Comment Crew&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;Comment Panda&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;GIF89a&amp;#039;&amp;#039;&amp;#039;, and &amp;#039;&amp;#039;&amp;#039;Byzantine Candor&amp;#039;&amp;#039;&amp;#039;) ({{zh|61398部队}}, [[Pinyin]]: 61398 &amp;#039;&amp;#039;bùduì&amp;#039;&amp;#039;) is the [[Military Unit Cover Designator]] (MUCD)&amp;lt;ref name=MandiantAPT1&amp;gt;{{cite web|url=http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf|title=APT1: Exposing One of China&amp;#039;s Cyber Espionage Units|publisher=Mandiant|access-date=19 February 2013|archive-url=https://web.archive.org/web/20130219155150/http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf|archive-date=19 February 2013|url-status=live}}&amp;lt;/ref&amp;gt; of a [[People&amp;#039;s Liberation Army]] [[advanced persistent threat]] unit that has been alleged to be a source of Chinese [[hacker (computer security)|computer hacking]] attacks.&amp;lt;ref name=&amp;quot;NYT 2013-02-18&amp;quot;&amp;gt;{{Cite news |last1=Sanger |first1=David E. |last2=Barboza |first2=David |author-link2=David Barboza |last3=Perlroth |first3=Nicole |date=2013-02-19 |title=Chinese Army Unit Is Seen as Tied to Hacking Against U.S. |language=en-US |work=[[The New York Times]] |url=https://www.nytimes.com/2013/02/19/technology/chinas-army-is-seen-as-tied-to-hacking-against-us.html |access-date=2023-05-28 |issn=0362-4331}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web |date=19 February 2013 |title=Chinese military unit behind &amp;#039;prolific and sustained hacking&amp;#039; |url=https://www.theguardian.com/world/2013/feb/19/chinese-military-unit-prolific-hacking |url-status=live |archive-url=https://web.archive.org/web/20131220122401/http://www.theguardian.com/world/2013/feb/19/chinese-military-unit-prolific-hacking |archive-date=20 December 2013 |access-date=19 February 2013 |work=[[The Guardian]]}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;:0&amp;quot; /&amp;gt; The unit is stationed in [[Pudong]], [[Shanghai]].&amp;lt;ref&amp;gt;{{Cite web|url=http://www.cs.zju.edu.cn/chinese/redir.php?catalog_id=101913&amp;amp;object_id=106021|title=中国人民解放军61398部队招收定向研究生的通知|date=2004-05-13|website=Zhejiang University|trans-title=A notification of PLA Unit 64398 to recruit postgraduate students as PLA-funded scholarship student.|access-date=2019-01-05|archive-url=https://web.archive.org/web/20161202172240/http://www.cs.zju.edu.cn/chinese/redir.php?catalog_id=101913&amp;amp;object_id=106021|archive-date=2 December 2016|url-status=dead}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
[[File:FBI20140519.jpg|thumb|left|From left, Chinese military officers Gu Chunhui, Huang Zhenyu, Sun Kailiang, Wang Dong, and Wen Xinyu indicted on cyber espionage charges.]]{{See also|Chinese information operations and information warfare|Cyberwarfare by China}}&lt;br /&gt;
&lt;br /&gt;
A 2020 report in [[DNA India]] stated that the unit was involved in espionage on the [[Military of India]].&amp;lt;ref&amp;gt;{{cite web |title=Chinese Army&amp;#039;s secret &amp;#039;61398&amp;#039; unit spying on India&amp;#039;s defense and research, warns intelligence |url=https://www.dnaindia.com/india/report-chinese-army-s-secret-61398-unit-spying-on-india-s-defense-and-research-warns-intelligence-2835741 |website=[[DNA India]] |language=en}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===2014 indictment===&lt;br /&gt;
&lt;br /&gt;
On 19 May 2014, the [[US Department of Justice]] announced that a Federal [[grand jury]] had returned an indictment of five 61398 officers on charges of theft of confidential business information and intellectual property from U.S. commercial firms and of planting [[malware]] on their computers.&amp;lt;ref&amp;gt;Finkle, J., Menn, J., Viswanatha, J. [https://www.reuters.com/article/us-cybercrime-usa-china-idUSKCN0J42M520141120 &amp;#039;&amp;#039;U.S. accuses China of cyber spying on American companies.&amp;#039;&amp;#039;] {{Webarchive|url=https://web.archive.org/web/20170412015738/http://www.reuters.com/article/us-cybercrime-usa-china-idUSKCN0J42M520141120 |date=12 April 2017 }} Reuters, 20 Nov 2014.&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Clayton, M. [http://www.csmonitor.com/World/Security-Watch/Cyber-Conflict-Monitor/2014/0519/US-indicts-five-in-China-s-secret-Unit-61398-for-cyber-spying-on-US-firms &amp;#039;&amp;#039;US indicts five in China&amp;#039;s secret &amp;#039;Unit 61398&amp;#039; for cyber-spying.&amp;#039;&amp;#039;] {{Webarchive|url=https://web.archive.org/web/20140520075207/http://www.csmonitor.com/World/Security-Watch/Cyber-Conflict-Monitor/2014/0519/US-indicts-five-in-China-s-secret-Unit-61398-for-cyber-spying-on-US-firms |date=20 May 2014 }} Christian Science Monitor, 19 May 2014&amp;lt;/ref&amp;gt; The five are Huang Zhenyu (黄振宇), Wen Xinyu (文新宇), Sun Kailiang (孙凯亮), Gu Chunhui (顾春晖), and [[Wang Dong (hacker)|Wang Dong]] (王东).  Forensic evidence traces the base of operations to a 12-story building off Datong Road in a public, mixed-use area of [[Pudong]] in Shanghai.&amp;lt;ref name=&amp;quot;NYT 2013-02-18&amp;quot;/&amp;gt; The group is also known by various other names including &amp;quot;Advanced Persistent Threat 1&amp;quot; (&amp;quot;APT1&amp;quot;), &amp;quot;the Comment group&amp;quot; and &amp;quot;Byzantine Candor&amp;quot;, a codename given by US intelligence agencies since 2002.&amp;lt;ref&amp;gt;{{cite web |url=http://www.fiercegovernmentit.com/story/chinese-attacks-byzantine-candor-penetrated-federal-agencies-says-leaked-ca/2010-12-06 |title=Chinese attacks &amp;#039;Byzantine Candor&amp;#039; penetrated federal agencies, says leaked cable |author=David Perera |date=6 December 2010 |website=fiercegovernmentit.com |publisher=Fierce Government IT |archive-url=https://web.archive.org/web/20160419054340/http://www.fiercegovernmentit.com/story/chinese-attacks-byzantine-candor-penetrated-federal-agencies-says-leaked-ca/2010-12-06 |archive-date=19 April 2016 |url-status=live }}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;CSMonitor&amp;quot;&amp;gt;{{cite web|last=Clayton|first=Mark|title=Stealing US business secrets: Experts ID two huge cyber &amp;#039;gangs&amp;#039; in China|url=http://www.csmonitor.com/USA/2012/0914/Stealing-US-business-secrets-Experts-ID-two-huge-cyber-gangs-in-China|publisher=[[CSMonitor]]|access-date=24 February 2013|date=14 September 2012|archive-url=https://web.archive.org/web/20191115165311/https://www.csmonitor.com/USA/2012/0914/Stealing-US-business-secrets-Experts-ID-two-huge-cyber-gangs-in-China|archive-date=15 November 2019|url-status=live}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;Bloomberg EU DC&amp;quot;/&amp;gt;&amp;lt;ref&amp;gt;{{cite news|title=China&amp;#039;s Comment Group Hacks Europe—and the World|url=http://www.businessweek.com/articles/2012-08-02/chinas-comment-group-hacks-europe-and-the-world|access-date=12 February 2013|newspaper=[[Bloomberg Businessweek]]|date=2 August 2012|author=Michael Riley|author2=Dune Lawrence|archive-url=https://web.archive.org/web/20130219064600/http://www.businessweek.com/articles/2012-08-02/chinas-comment-group-hacks-europe-and-the-world|archive-date=19 February 2013|url-status=dead}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A report by the [[computer security]] firm [[Mandiant]] stated that PLA Unit 61398 is believed to operate under the 2nd Bureau of the [[People&amp;#039;s Liberation Army General Staff Department]] (GSD) [[People&amp;#039;s Liberation Army#Third Department|Third Department]] (总参三部二局)&amp;lt;ref name=MandiantAPT1/&amp;gt; and that there is evidence that it contains, or is itself, an entity Mandiant calls [[APT1]], part of the advanced persistent threat that has attacked a broad range of corporations and government entities around the world since at least 2006. APT1 is described as comprising four large networks in Shanghai, two of which serve the Pudong New Area. It is one of more than 20 APT groups with origins in China.&amp;lt;ref name=MandiantAPT1/&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=http://www.businessinsider.com/china-hacking-pla-unit-61398-2013-2|title=REPORT: An Overwhelming Number Of The Cyber-Attacks On America Are Coming From This Particular Army Building In China|publisher=Business Insider|date=18 February 2013|author=Joe Weisenthal and Geoffrey Ingersoll|access-date=19 February 2013|archive-url=https://web.archive.org/web/20130220095914/http://www.businessinsider.com/china-hacking-pla-unit-61398-2013-2|archive-date=20 February 2013|url-status=live}}&amp;lt;/ref&amp;gt; The Third and [[People&amp;#039;s Liberation Army#Fourth Department|Fourth Department]], responsible for [[electronic warfare]], are believed to comprise the PLA units mainly responsible for infiltrating and manipulating computer networks.&amp;lt;ref name=&amp;quot;huffingtonpost professional&amp;quot;&amp;gt;{{cite web|last=Bodeen|first=Christopher|title=Sign That Chinese Hackers Have Become Professional: They Take Weekends Off|url=http://www.huffingtonpost.com/2013/02/25/chinese-hackers_n_2756914.html|work=[[The Huffington Post]]|date=25 February 2013|access-date=27 February 2013|archive-url=https://web.archive.org/web/20130226184036/http://www.huffingtonpost.com/2013/02/25/chinese-hackers_n_2756914.html|archive-date=26 February 2013|url-status=live}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The group often compromises internal software &amp;quot;comment&amp;quot; features on legitimate web pages to infiltrate target computers that access the sites, leading it to be known as &amp;quot;the Comment Crew&amp;quot; or &amp;quot;Comment Group&amp;quot;.&amp;lt;ref name=&amp;quot;NYMag Comment Crew&amp;quot;&amp;gt;{{cite web|last=Martin|first=Adam|title=Meet &amp;#039;Comment Crew,&amp;#039; China&amp;#039;s Military-Linked Hackers|url=http://nymag.com/daily/intelligencer/2013/02/meet-comment-crew-chinas-military-hackers.html|work=[[New York (magazine)|NYMag.com]]|publisher=[[New York Media]]|access-date=24 February 2013|date=19 February 2013|archive-url=https://web.archive.org/web/20130222070617/http://nymag.com/daily/intelligencer/2013/02/meet-comment-crew-chinas-military-hackers.html|archive-date=22 February 2013|url-status=live}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|title=The Comment Group: The hackers hunting for clues about you|url=https://www.bbc.co.uk/news/business-21371608|publisher=BBC News|access-date=12 February 2013|author=Dave Lee|date=12 February 2013|archive-url=https://web.archive.org/web/20130212155404/http://www.bbc.co.uk/news/business-21371608|archive-date=12 February 2013|url-status=live}}&amp;lt;/ref&amp;gt; The collective has stolen [[trade secret]]s and other confidential information from numerous foreign businesses and organizations over the course of seven years such as [[Lockheed Martin]], [[Telvent]], and other companies in the shipping, aeronautics, arms, energy, manufacturing, engineering, electronics, financial, and software sectors.&amp;lt;ref name=&amp;quot;CSMonitor&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Dell SecureWorks]] says it believed the group includes the same group of attackers behind [[Operation Shady RAT]], an extensive computer espionage campaign uncovered in 2011 in which more than 70 organizations over a five-year period, including the United Nations, government agencies in the United States, Canada, [[South Korea]], Taiwan and Vietnam, were targeted.&amp;lt;ref name=&amp;quot;NYT 2013-02-18&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The attacks documented in the summer of 2011 represent a fragment of the Comment group&amp;#039;s attacks, which go back at least to 2002, according to incident reports and investigators. In 2012, [[FireEye, Inc.]] stated that they had tracked hundreds of targets in the last three years and estimated the group had attacked more than 1,000 organizations.&amp;lt;ref name=&amp;quot;Bloomberg EU DC&amp;quot;&amp;gt;{{cite news|last1=Riley|first1=Michael|title=Hackers Linked to China&amp;#039;s Army Seen From EU to D.C.|url=https://www.bloomberg.com/news/2012-07-26/china-hackers-hit-eu-point-man-and-d-c-with-byzantine-candor.html|publisher=[[Bloomberg L.P.|Bloomberg]]|access-date=24 February 2013|author2=Dune Lawrence|newspaper=Bloomberg.com|date=26 July 2012|archive-url=https://web.archive.org/web/20150111064254/http://www.bloomberg.com/news/2012-07-26/china-hackers-hit-eu-point-man-and-d-c-with-byzantine-candor.html|archive-date=11 January 2015|url-status=live}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most activity between [[malware]] embedded in a compromised system and the malware&amp;#039;s controllers takes place during business hours in Beijing&amp;#039;s time zone, suggesting that the group is professionally hired, rather than private hackers inspired by patriotic passions.&amp;lt;ref name=&amp;quot;huffingtonpost professional&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Public position of the Chinese government ==&lt;br /&gt;
Until 2013, the [[Government of China]] has consistently denied that it is involved in hacking.&amp;lt;ref name=&amp;quot;MW Feb 20&amp;quot;&amp;gt;{{cite web|last=Xu|first=Weiwei|title=China denies hacking claims|url=http://www.morningwhistle.com/html/2013/PoliticsSociety_0220/217214.html|publisher=Morning Whistle|access-date=8 April 2013|date=20 February 2013|archive-url=https://archive.today/20130629220425/http://www.morningwhistle.com/html/2013/PoliticsSociety_0220/217214.html|archive-date=29 June 2013|url-status=live}}&amp;lt;/ref&amp;gt; In response to the [[Mandiant]] Corporation report about Unit 61398, [[Hong Lei (politician)|Hong Lei]], a spokesperson for the [[Ministry of Foreign Affairs of the People&amp;#039;s Republic of China|Chinese foreign ministry]], said such allegations were &amp;quot;unprofessional&amp;quot;.&amp;lt;ref name=&amp;quot;MW Feb 20&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;:0&amp;quot;&amp;gt;{{Cite news |date=February 19, 2013 |title=Hello, Unit 61398 |newspaper=[[The Economist]] |url=https://www.economist.com/analects/2013/02/19/hello-unit-61398 |access-date=2023-05-28 |issn=0013-0613}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In 2013, China changed its position and openly admitted to having secretive cyber warfare units in both the military and the civilian part of the government{{snd}}however, the details of their activities were left to speculation.&amp;lt;ref&amp;gt;{{cite news|title=China Finally Admits focusing on Cyber Warfare|url=http://www.ucsusa.org/sites/default/files/attach/2015/03/chinese-nuclear-strategy-full-report.pdf|date=19 March 2015|access-date=13 September 2017|archive-url=https://web.archive.org/web/20170829025423/http://www.ucsusa.org/sites/default/files/attach/2015/03/chinese-nuclear-strategy-full-report.pdf|archive-date=29 August 2017|url-status=live}}&amp;lt;/ref&amp;gt; As a show of force towards the rest of the global community the Chinese government now openly lists their abilities when it comes to digital spying and network attack capabilities.&amp;lt;ref name=&amp;quot;BBC&amp;quot;&amp;gt;{{cite news | url=https://www.bbc.com/news/world-asia-china-22430224 | title=US accuses China government and military of cyber-spying | date=7 May 2013 | access-date=15 January 2019 | author=BBC | work=BBC News | archive-url=https://web.archive.org/web/20190115192443/https://www.bbc.com/news/world-asia-china-22430224 | archive-date=15 January 2019 | url-status=live }}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Titan Rain]]&lt;br /&gt;
* [[Chinese espionage in the United States]]&lt;br /&gt;
* [[National Security Agency]] of the United States&lt;br /&gt;
* [[PLA Unit 61486]]&lt;br /&gt;
* [[Signals intelligence]]&lt;br /&gt;
* [[Tailored Access Operations]] of the United States&lt;br /&gt;
* [[Mandiant]]&lt;br /&gt;
* [[FireEye]]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;br /&gt;
&lt;br /&gt;
{{-}}&lt;br /&gt;
{{Hacking in the 2000s}}&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
{{China national security}}&lt;br /&gt;
{{People&amp;#039;s Liberation Army}}&lt;br /&gt;
&lt;br /&gt;
{{coord|31|20|57.43|N|121|34|24.74|E|region:CN_type:landmark_source:MandiantReportPage12|display=title}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Military units and formations of the People&amp;#039;s Republic of China]]&lt;br /&gt;
[[Category:Cyberwarfare by China]]&lt;br /&gt;
[[Category:Chinese advanced persistent threat groups]]&lt;br /&gt;
[[Category:Information operations units and formations]]&lt;br /&gt;
[[Category:Hacking (computer security)]]&lt;br /&gt;
[[Category:Injection exploits]]&lt;br /&gt;
[[Category:Web security exploits]]&lt;br /&gt;
[[Category:Sabotage]]&lt;br /&gt;
[[Category:2002 establishments in China]]&lt;br /&gt;
[[Category:Chinese intelligence agencies]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>