Chinese Spyware Code ‘Jian’ Was Copied From America's National Security Agency, Researchers Say

The researchers called Jian "kind of a copycat, a Chinese replica."

Advertisement
By Reuters | Updated: 22 February 2021 18:01 IST
Highlights
  • Checkpoint's head of research, called Jian kind of a copycat
  • In a statement, Lockheed said it routinely evaluates third-party software
  • How the Jian malware analysed by Checkpoint was used is not clear

The Chinese Embassy in Washington did not respond to requests for comment

Chinese spies used code first developed by the US National Security Agency to support their hacking operations, Israeli researchers said on Monday, another indication of how malicious software developed by governments can boomerang against their creators.

Tel Aviv-based Check Point Software Technologies issued a report noting that some features in a piece of China-linked malware it dubs "Jian" were so similar they could only have been stolen from some of the National Security Agency break-in tools leaked to the internet in 2017.

Advertisement

Yaniv Balmas, Checkpoint's head of research, called Jian "kind of a copycat, a Chinese replica."

The find comes as some experts argue that American spies should devote more energy to fixing the flaws they find in software instead of developing and deploying malicious software to exploit it.

Advertisement

The NSA declined comment. The Chinese Embassy in Washington did not respond to requests for comment.

A person familiar with the matter said Lockheed Martin – which is credited as having identified the vulnerability exploited by Jian in 2017 – discovered it on the network of an unidentified third party.

Advertisement

In a statement, Lockheed said it "routinely evaluates third-party software and technologies to identify vulnerabilities."

Countries around the world develop malware that breaks into their rivals' devices by taking advantage of flaws in the software that runs them. Every time spies discover a new flaw they must decide whether to quietly exploit it or fix the issue to thwart rivals and rogues.

Advertisement

That dilemma came to public attention between 2016 and 2017, when a mysterious group calling itself the "Shadow Brokers" published some of the NSA's most dangerous code to the Internet, allowing cybercriminals and rival nations to add American-made digital break-in tools to their own arsenals.

How the Jian malware analysed by Checkpoint was used is not clear. In an advisory published in 2017, Microsoft suggested it was linked to a Chinese entity it dubs "Zirconium," which last year was accused of targeting US election-related organizations and individuals, including people associated with President Joe Biden's campaign.

Checkpoint says Jian appears to have been crafted in 2014, at least two years before the Shadow Brokers made their public debut. That, in conjunction with research published in 2019 by Broadcom-owned cyber-security firm Symantec about a similar incident, suggests the NSA has repeatedly lost control of its own malware over the years.

Checkpoint's research is thorough and "looks legit," said Costin Raiu, a researcher with Moscow-based antivirus firm Kaspersky Lab, which has helped dissect some of the NSA's malware.

Balmas said a possible takeaway from his company's report was for spymasters weighing whether to keep software flaws secret to think twice about using a vulnerability for their own ends.

"Maybe it's more important to patch this thing and save the world," Balmas said. "It might be used against you."

© Thomson Reuters 2021


Is Samsung Galaxy S21+ the perfect flagship for most Indians? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: NSA
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus N6x With a 7,000mAh Battery Arrives in India at This Price
  2. HMD Pulse 2 Series Specifications, Colour Options Tipped
  3. Vivo X500 Pro Tipped to Feature BOE OLED Panel
  4. Vivo S2 Set to Launch in India on This Date
  5. Moto Pad 70 Groove With 9 JBL Pro Speakers, 10,200mAh Battery Launched in India
  1. Sony Not Backing Down From Decision to End Game Discs, Says Will 'Cautiously' Move Forward With Plan
  2. Samsung Galaxy S26 FE Camera Specifications Leaked Ahead of Expected Launch, May Reuse Its Predecessor's Main Rear Camera
  3. Bitcoin Wallet Exploit Costs Users $38 Million in 25-Minute Attack
  4. Tecno's Bezelless Concept Phone Teased Ahead of IFA 2026
  5. HMD Pulse 2, Pulse 2 Plus, Pulse 2 Pro Tipped to Feature 5,000mAh Battery, Unisoc Chipset
  6. Poco C95 Pro 4G, Redmi Note 17 Pro 5G Reportedly Spotted on NBTC Ahead of Expected Launch
  7. Samsung SDS Teams Up With Upbit Operator Dunamu to Explore Stablecoins and AI Payments
  8. Redmi K100 Pro Series Launch Confirmed for August 11; K100 Pro Max Design Revealed
  9. Anthropic Says Claude AI Breached Three Organisations During Cybersecurity Testing
  10. Samsung Working on New Galaxy Buds With Ear Hooks Design, Leak Suggests
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.