U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Nuclear Energy, Metals, Manufacturing, Clean Energy.
- Documented Financial Loss: $100.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.
Operational & Financial Fallout
Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Attachment. Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.
Adversary Kill Chain Flow
2 Documented PhasesDefendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups.
Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams.
Theft of proprietary nuclear reactor designs, solar panel technology, and commercial negotiation strategies. Impacted Nuclear Energy, Metals, Manufacturing, Clean Energy infrastructure and associated victim operations.
Procedural & Incident Timeline
Grand jury unseals 31-count indictment against five PLA Unit 61398 military officers.
Cyber espionage agreement signed between U.S. and PRC following sustained enforcement pressure.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Sun Kailiang | People's Republic of China | fugitive | Pending | None | PLA Unit 61398 military officer indicted in W.D. Pa. for economic cyber espionage. |
| Wang Dong | People's Republic of China | fugitive | Pending | None | PLA Unit 61398 hacker indicted for intruding into U.S. commercial energy and manufacturing networks. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "Defendants sent spearphishing emails containing malicious attachments to corporate engineers, appearing to come from colleagues or trade groups." | Indictment ¶ 15, Page 7 | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams." | Indictment ¶ 29, Page 16 | reviewed |