U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Northern District of Georgia.
- Primary Target Sector: Financial Services, Consumer Credit.
- Documented Financial Loss: $1.4 billion.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.
Operational & Financial Fallout
Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.
Adversary Kill Chain Flow
4 Documented PhasesChinese PLA military intelligence hackers exploited CVE-2017-5638 by sending malicious HTTP requests with crafted Content-Type headers, executing commands with web server privileges.
Operatives ran approximately 9,000 internal database queries to locate consumer credit data, extracting unencrypted credentials stored in plaintext configuration files.
Defendants established encrypted communications through proxy servers in Germany and Switzerland and systematically purged server access logs daily to conceal their presence.
Stolen records were split into compressed archives and exfiltrated to overseas staging servers over 76 separate intrusion days.
Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.
Procedural & Incident Timeline
Federal grand jury returns nine-count indictment against four Chinese PLA military intelligence hackers.
Attorney General William Barr publicly announces the unsealing of charges against members of the 54th Research Institute.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "The conspirators exploited a known vulnerability in the Apache Struts Web Framework (CVE-2017-5638) on Equifax's online dispute portal to obtain initial remote shell execution." | Indictment ¶ 14, Page 6 | reviewed |
| T1070 | Indicator Removal Defense Evasion | "Defendants routinely deleted temporary files and log entries, routed communications through encrypted tunnels, and ran roughly 9,000 queries to mask their database reconnaissance." | Indictment ¶ 22, Page 11 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Operatives packaged stolen records containing names, Social Security numbers, and birth dates into compressed archives and exfiltrated them to overseas staging servers." | Indictment ¶ 26, Page 13 | reviewed |