China's Hacker Army

The myth of a monolithic Chinese cyberwar is starting to be dismantled. A look inside the teeming, chaotic world that exists instead -- and that may be far more dangerous.

BY MARA HVISTENDAHL | MARCH 3, 2010

In fact, the hacking scene in China probably looks more like a few intelligence officers overseeing a jumble of talented -- and sometimes unruly -- patriotic hackers. Since the 1990s, China has had an intelligence program targeting foreign technology, says James A. Lewis, senior fellow for cybersecurity and Internet policy at the Center for Strategic and International Studies. Beyond that, however, things get complicated. "The hacking scene can be chaotic," he says. "There are many actors, some directed by the government and others tolerated by it. These actors can include civilian agencies, companies, and individuals."

To anyone who speaks Chinese, that chaos is obvious. Google the characters for heike -- a transliteration of "hacker" that means, literally, "black guest" -- and you'll come up with pages and pages of results. Sites such as www.chinahacker.com, www.cnhacker.com, and www.hackbase.com contain step-by-step instructions, advertisements for how-to seminars -- become a hacker in a few short weeks! -- and screen shots of foreign casualties. And yet they are clearly not the work of the central government. Read on (or don't -- the sites are packed with malware and users visit at their own peril) and you'll find threads roiling with bitter infighting, foul-mouthed forum posts, and photos of scantily clad women.

"There are literally hundreds of these sites," says Scott J. Henderson, an intelligence contractor and former U.S. Army linguist who has written a book on Chinese hackers. "They all have different agendas and different personnel. It's not as well-coordinated as everyone sitting down in a room and someone saying, 'You, go write this code.' 'You, go write that.'"

Instead, China's hackers spring up organically. Mix together widespread youth nationalism with a highly wired population -- China now boasts the most Internet users in the world, with 384 million people online -- and out comes patriotic hacking. The self-described "red hackers" are the product of the "the fact that we live in a time when our country is moving toward prosperity," SharpWinner once said, quite accurately. Prosperity also ensures a market for abundant hacker memorabilia: hacker magazines, hacker T-shirts, and tell-all books like his. While traveling through rural China once, I stumbled across bins in a village store filled with Hacker brand candy. (It tastes like saltwater taffy.)

Every August, top hackers convene in Beijing for a conference ostensibly about information security but described by one participant as including seminars on common attack techniques. China's hackerati range from flamboyant prima donnas like SharpWinner to Sunwear, a slight, pixie-ish twentysomething who marks his website defacements with the innocuous tag line "just for fun!", to Xiao Tian, the unattainable femme fatale leader of China Girl Security Team. Many of their causes neatly overlap with the interests of the Chinese government. Take one of the events that drove the development of hacker culture in China: the 1999 NATO bombing of the Chinese Embassy in Belgrade. In retaliation, hackers plastered the website of the U.S. Embassy in Beijing with the phrase "Down with the Barbarians!" Or the targeting of email accounts of the Save Darfur Coalition, which opposes Chinese involvement in Sudan, in 2008. Or GhostNet, the cyberspying operation originating in China that was revealed last year to have infected 1,295 computers in 103 countries -- including the Dalai Lama's network in Dharamsala, India. The University of Toronto researchers who uncovered the attack have not yet pinpointed its architects, but in a report on the attack, they noted the operation could easily be the work of patriotic hackers using "do-it-yourself signals intelligence."

LIU JIN/AFP/Getty Images

 

Mara Hvistendahl's writing has appeared in Harper's, The New Republic, and Science. She is writing a book on Asia's gender imbalance, due out in 2011 from Public Affairs.

TORO

9:43 PM ET

March 3, 2010

Translation

I noticed, in slide 7, you simply called it 'Hackers Language', without providing a translation. Hackers language is called Leet Speak (Elite Speak), otherwise known as leet, or 1337. Pretty much anybody who plays video games seriously knows it, and it's not just for hackers alone. Here's the full translation:

Google runs on a unique combination of advanced hardware and software. The speed you experience can be attributed in part to the efficiency of our search algorithm and partly to the thousands of low cost pc’s we’ve networked together to create a superfast search engine. The heart of our software is pagerank (TM), a system for ranking web pages developed by our founders Larry Page and Sergey Brin at Stanford University. And while we have dozens of engineers working to improve every aspect of Google on a daily basis, Pagerank continues to provide the basis for all of our web search tools.

 

JAVELINA520

6:24 PM ET

March 4, 2010

search engine

I can't find my glasses--can your algorithm help?

 

BLACKSHYLD

1:43 AM ET

March 4, 2010

So what are we doing about this?

I'm curious as to what exactly are we doing about this? I mean America is where the Internet began after all, I would like to think we are not helpless in the face of these "Red hackers"

Granted I would imagine it is hard to set up a top down hierarchy that could effectively tackle this, but why not fight fire with fire? Certainly we have our own homegrown Hackers who could do just as good at attacking and defending against these threats, provided the right incentives are there.

 

ADDYTHEBAT

7:39 AM ET

March 4, 2010

All I can think of when the

All I can think of when the author talks about Chinese hacker groups is the movie Hackers (from 1995); groups of rebellious youth taking on "the man".

 

NORBOOSE

6:36 PM ET

March 4, 2010

Deceptive Statistic

The article says 50,000 to 100,000 "civilian" hackers. "Civilian" dos not mean private individuals. If anything, a Chinese government backed hacking program would be orchestrated by "civilian" intelligence agencies, not the PLA. It makes it hard to believe this article, since 99,000 of the serious hackers could be working for the government, just not the "military" per se.