Chinese Spyware Code ‘Jian’ Was Copied From America's National Security Agency, Researchers Say

The researchers called Jian "kind of a copycat, a Chinese replica."

Advertisement
By Reuters | Updated: 22 February 2021 18:01 IST
Highlights
  • Checkpoint's head of research, called Jian kind of a copycat
  • In a statement, Lockheed said it routinely evaluates third-party software
  • How the Jian malware analysed by Checkpoint was used is not clear

The Chinese Embassy in Washington did not respond to requests for comment

Chinese spies used code first developed by the US National Security Agency to support their hacking operations, Israeli researchers said on Monday, another indication of how malicious software developed by governments can boomerang against their creators.

Tel Aviv-based Check Point Software Technologies issued a report noting that some features in a piece of China-linked malware it dubs "Jian" were so similar they could only have been stolen from some of the National Security Agency break-in tools leaked to the internet in 2017.

Advertisement

Yaniv Balmas, Checkpoint's head of research, called Jian "kind of a copycat, a Chinese replica."

The find comes as some experts argue that American spies should devote more energy to fixing the flaws they find in software instead of developing and deploying malicious software to exploit it.

Advertisement

The NSA declined comment. The Chinese Embassy in Washington did not respond to requests for comment.

A person familiar with the matter said Lockheed Martin – which is credited as having identified the vulnerability exploited by Jian in 2017 – discovered it on the network of an unidentified third party.

Advertisement

In a statement, Lockheed said it "routinely evaluates third-party software and technologies to identify vulnerabilities."

Countries around the world develop malware that breaks into their rivals' devices by taking advantage of flaws in the software that runs them. Every time spies discover a new flaw they must decide whether to quietly exploit it or fix the issue to thwart rivals and rogues.

Advertisement

That dilemma came to public attention between 2016 and 2017, when a mysterious group calling itself the "Shadow Brokers" published some of the NSA's most dangerous code to the Internet, allowing cybercriminals and rival nations to add American-made digital break-in tools to their own arsenals.

How the Jian malware analysed by Checkpoint was used is not clear. In an advisory published in 2017, Microsoft suggested it was linked to a Chinese entity it dubs "Zirconium," which last year was accused of targeting US election-related organizations and individuals, including people associated with President Joe Biden's campaign.

Checkpoint says Jian appears to have been crafted in 2014, at least two years before the Shadow Brokers made their public debut. That, in conjunction with research published in 2019 by Broadcom-owned cyber-security firm Symantec about a similar incident, suggests the NSA has repeatedly lost control of its own malware over the years.

Checkpoint's research is thorough and "looks legit," said Costin Raiu, a researcher with Moscow-based antivirus firm Kaspersky Lab, which has helped dissect some of the NSA's malware.

Balmas said a possible takeaway from his company's report was for spymasters weighing whether to keep software flaws secret to think twice about using a vulnerability for their own ends.

"Maybe it's more important to patch this thing and save the world," Balmas said. "It might be used against you."

© Thomson Reuters 2021


Is Samsung Galaxy S21+ the perfect flagship for most Indians? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: NSA
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 FE Launched in India With These Features
  2. Here's When the Samsung Galaxy Tab S12 Series Could Launch
  3. Vivo X500 Global Launch Inch Closer as New Flagship Bags SIRIM Approval
  4. Oppo Watch S2 Will Launch With These New Health Tracking Features
  5. iPhone 18 Pro Max Buyers Face Nearly Month-Long Wait for Delivery
  6. Redmi Note 17 Pro Drops in India Today: How to Watch the Launch Live
  7. Oracle Cuts More Jobs as AI Data Centre Spending Rises
  8. Xiaomi Pad 9, Xiaomi Pad 9 Pro Launched in China
  9. Here's When the Lava Virat Curve Will Launch in India
  1. iPhone Air Trade-In Value Matches Cheaper iPhone 17 in US, Despite Higher Launch Price
  2. Oracle Layoffs Reportedly Begin as Company Ramps Up AI Infrastructure Investments
  3. Samsung Galaxy Tab S12 Series Will Reportedly Launch Early Next Month: Expected Specifications
  4. Samsung Galaxy S27 Ultra Tipped to Feature M16 OLED Panels; May Prioritise Privacy Over Brightness
  5. Anthropic Says Claude Assisted Cyberattacks and Military Weapons Development
  6. iPhone 18 Pro and iPhone 18 Pro Max Delivery Dates Slip to October in India, US After Preorders Begin
  7. Oppo F35, Oppo F35 Pro Design, Colour Options Reportedly Leak Ahead of India Launch
  8. Redmi Note 17 Pro Drops in India Today: How to Watch the Launch Live
  9. Symbiosis Recovers 15 BTC Following Attack on syBTC Minting
  10. Xiaomi 18 Worldwide Debut Inches Closer Following First Major Regulatory Move
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.