CASE DOSSIER fugitive

U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)

Docket: 2:14-cr-00118 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2014-05-01 Sector: Nuclear Energy, Metals, Manufacturing, Clean Energy

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$100.0 million
Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies.
Techniques
2
Verified mappings
Defendants
2
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Nuclear Energy, Metals, Manufacturing, Clean Energy.
  • Documented Financial Loss: $100.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.

Operational & Financial Fallout

Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.001 →

Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.

Artifacts & Tooling: T1566.001 Spearphishing Attachment
2
Phase 2: Exfiltration Encrypted Cloud Data Exfiltration
MITRE ATT&CK T1041 →

Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.

Artifacts & Tooling: T1041 Exfiltration Over C2 Channel
Real-World Blast Radius & Operational Fallout

Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2014-05-01 indictment

Grand jury unseals 31-count indictment against five PLA Unit 61398 military officers.

2015-09-25 sanction

Cyber espionage agreement signed between U.S. and PRC following sustained enforcement pressure.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Sun Kailiang People's Republic of China fugitive Pending None PLA Unit 61398 military officer indicted in W.D. Pa. for economic cyber espionage.
Wang Dong People's Republic of China fugitive Pending None PLA Unit 61398 hacker indicted for intruding into U.S. commercial energy and manufacturing networks.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups." Indictment ¶ 15, Page 7 reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams." Indictment ¶ 29, Page 16 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1), No. 2:14-cr-00118 (U.S. District Court for the Western District of Pennsylvania 2014), https://cybercaselibrary.com/cases/us-v-sun-kailiang-pla-unit-61398/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-sun-kailiang-pla-unit-61398" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>