Li Xiaoyu and Dong Jiazhi
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Li Xiaoyu and Dong Jiazhi are two Chinese nationals who have been identified as contractors working with the Ministry of State Security of China. They operate under the aliases Li Xiaoyu and Dong Jiazhi and are based in China. Public indictments describe them as acting with the assistance and acquiescence of an officer from China’s Ministry of State Security, indicating a clear state‑linked affiliation. Their activities have been characterized as theft of trade secrets, intellectual property and other valuable business information, with occasional attempts to extort victims for ransom and to provide passwords of human rights activists to their government contact.
The actors have targeted a broad range of sectors including high‑technology manufacturing, pharmaceutical companies, makers of educational software and medical equipment, defense contractors, and organizations involved in coronavirus vaccine and treatment research. Victim organizations have been located in the United States, Australia, Germany, Japan, South Korea and other countries, reflecting an international scope. Their strategic objectives have been explicitly described as acquiring information of obvious interest to the Chinese government, supporting state‑directed espionage efforts, and in one case seeking financial gain through extortion. No public statements attribute a purely financial or disruptive motive to their operations.
Typical tactics involve exploiting publicly disclosed software vulnerabilities, often using newly announced flaws before victims have had time to apply patches. Initial access has been gained through web servers and software collaboration programs, after which the actors deploy tools that allow them to issue further commands and password‑stealing programs to harvest credentials. To move laterally they reuse stolen credentials to reach additional parts of the victim networks. For data exfiltration they compress stolen files into archive formats, alter the file extensions to evade detection, and have been observed hiding malware and stolen data in the recycle bins of compromised systems. They have also returned to previously compromised victims years later to collect additional information.
Notable publicly reported operations include a decade‑long campaign beginning around 2009 that resulted in the alleged theft of hundreds of millions of dollars’ worth of intellectual property from hundreds of companies worldwide. In March 2015 they breached the Hanford Site, a Department of Energy nuclear waste facility, which led to their discovery by a private security firm and subsequent FBI investigation. In early 2020 they conducted reconnaissance and attempted intrusions against biotech firms in Maryland, Massachusetts and California that were researching coronavirus vaccines and treatments, as well as a California firm producing coronavirus testing kits. These actions were cited in indictments as part of their broader effort to collect coronavirus‑related research data for the benefit of the Chinese government.
Incidents
Attributed incidents are available to members.
2 incidents