CASE DOSSIER fugitive

U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)

Docket: 1:20-cr-00071 Court: U.S. District Court for the Northern District of Georgia Opened: 2020-01-28 Sector: Financial Services, Consumer Credit

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$1.4 billion
Equifax incurred over $1.4 billion in remediation, technological overhauls, and federal class action settlement expenditures.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Northern District of Georgia.
  • Primary Target Sector: Financial Services, Consumer Credit.
  • Documented Financial Loss: $1.4 billion.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Four military officers with the Chinese People's Liberation Army (PLA) 54th Research Institute charged with hacking into Equifax networks, stealing trade secrets, and exfiltrating personally identifiable information (PII) of roughly 147 million American citizens.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.

Operational & Financial Fallout

Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.

Adversary Kill Chain Flow

4 Documented Phases
1
Initial Exploitation Apache Struts Web Server RCE
MITRE ATT&CK T1190 →

Chinese PLA military intelligence hackers exploited CVE-2017-5638 by sending malicious HTTP requests with crafted Content-Type headers, executing commands with web server privileges.

Artifacts & Tooling: CVE-2017-5638 Apache Struts OGNL expression payload China Chopper webshell
2
Internal Reconnaissance & Queries Database Schema and Credentials Enumeration
MITRE ATT&CK T1083 →

Operatives ran approximately 9,000 internal database queries to locate consumer credit data, extracting unencrypted credentials stored in plaintext configuration files.

Artifacts & Tooling: Plaintext database credentials Automated SQL reconnaissance scripts
3
Defense Evasion Log Purging and Encrypted Tunneling
MITRE ATT&CK T1070 →

Defendants established encrypted communications through proxy servers in Germany and Switzerland and systematically purged server access logs daily to conceal their presence.

Artifacts & Tooling: SSH encrypted tunnels log wipe commands
4
Exfiltration Segmented Archive Cloud Exfiltration
MITRE ATT&CK T1567 →

Stolen records were split into compressed archives and exfiltrated to overseas staging servers over 76 separate intrusion days.

Artifacts & Tooling: tar.gz archives Segmented file downloads
Real-World Blast Radius & Operational Fallout

Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Maintain an authoritative software asset inventory to identify and patch vulnerable software components within 48 hours of public CVE disclosure.
✓ Deploy Web Application Firewalls (WAF) with inspection rules for malicious HTTP headers and OGNL injection attacks.
✓ Encrypt sensitive database fields at rest and prohibit plaintext credentials in application config files.
✓ Inspect outbound SSL/TLS traffic with network decryption to detect unauthorized bulk data exfiltration.

Procedural & Incident Timeline

2020-01-28 indictment

Federal grand jury returns nine-count indictment against four Chinese PLA military intelligence hackers.

2020-02-10 advisory

Attorney General William Barr publicly announces the unsealing of charges against members of the 54th Research Institute.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"The conspirators exploited a known vulnerability in the Apache Struts Web Framework (CVE-2017-5638) on Equifax's online dispute portal to obtain initial remote shell execution." Indictment ¶ 14, Page 6 reviewed
T1070 Indicator Removal
Defense Evasion
"Defendants routinely deleted temporary files and log entries, routed communications through encrypted tunnels, and ran roughly 9,000 queries to mask their database reconnaissance." Indictment ¶ 22, Page 11 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Operatives packaged stolen records containing names, Social Security numbers, and birth dates into compressed archives and exfiltrated them to overseas staging servers." Indictment ¶ 26, Page 13 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute), No. 1:20-cr-00071 (U.S. District Court for the Northern District of Georgia 2020), https://cybercaselibrary.com/cases/us-v-wu-equifax-pla/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-wu-equifax-pla" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>