Research Espionage and Foreign Interference: The PRC in Canada

Cyber Espionage and the Global Infrastructure of GhostNet\n\n* Discovery in India (20082008): Researcher Shishir Nagaraja and Greg Walton entered the Dalai Lama’s offices to investigate computer anomalies. They were sent by Rafal Rohozinski of SecDev, a digital security firm connected to the Information Warfare Monitor (founded by Ron Deibert of the University of Toronto’s Citizen Lab).\n* Methodology: Nagaraja and Walton used WireShark software to scan network traffic. They worked three 1414-hour days under intense scrutiny. They discovered a remote command ordering the retrieval of a specific file regarding "classified information about building contracts for schools in Tibet."\n* GhostNet and GhostRat: The malware, which they dubbed GhostNet (the network) and GhostRat (the code), spread via Microsoft Word and PDF documents. \n * Versatility: GhostRat could view monitors, log keystrokes, download files, activate webcams for covert recording, and control computers remotely.\n * Uniqueness: It searched for specific bits of information requested by its controllers rather than just bulk-copying data.\n* Tracking the Handlers: Nick Villeneuve, a researcher at Citizen Lab, identified a unique 2222-character text string in the URL of a control server. This led to the discovery of:\n * One control server in the US used as a data dump.\n * Five control servers located in China.\n* Targets of Interest: The network infected Thousands of machines, including those in embassies, international government offices, the Asian Development Bank, and Tibetan/Taiwanese groups.\n\n# The Scale and Methodologies of PRC Intellectual Property Theft\n\n* The Global Impact: In 20122012, NSA director Keith Alexander described China’s theft as "the greatest transfer of wealth in human history."\n* Commercial Targets: James Dyson noted the theft of vacuum designs; paint manufacturer Dupont reported the theft of trade secrets regarding the color white.\n* Outsourced Hacking: The PRC frequently outsources to private firms such as I-Soon and Chengdu 404 (whose members were indicted by the US government).\n * A leaked I-Soon document showed a Shandong public security bureau paid approximately $55,000\$55,000 for one year of access to 1010 email accounts.\n * I-Soon boasted of its ability to hack X (formerly Twitter) and Facebook and assist in "anti-terrorism" in the Xinjiang region to monitor the Uyghur population.\n* Critical Infrastructure Attacks: In September 20132013, Telvent Canada, which manages 60%60\% of oil and gas pipelines in the western hemisphere, was attacked by the Comment Group, a PRC hacking organization. Stolen items included technology to mesh older electrical grids with smart technologies.\n\n# Military Espionage and High-Value Asset Theft\n\n* The Su Bin (Stephen) Case: Su Bin operated Lode-Tech in British Columbia. In 20142014, he was identified as a "spotter" who identified targets (engineers and industry experts) for the PLA.\n * Data Breach: Between 20092009 and 20142014, Su assisted in stealing 630,000630,000 files (6565 gigabytes) related to the C-17 reconnaissance transport aircraft (R\u0026D cost: $30\$30 billion).\n * Other Targets: He stole 220220 megabytes of data on the F-22 Raptor and significant files on the F-35.\n * Laundering Data: Files were moved through multiple countries to Hong Kong, where data was physically transported to mainland China to avoid digital tracking.\n * Outcome: Su Bin pleaded guilty in 20162016 and did not contest extradition.\n* Pratt \u0026 Whitney Canada: In 20122012, the company pleaded guilty to violating US export laws by providing technology that enabled China to build its first attack helicopter, the Z-10 Zhisheng. Despite the conviction, the Canadian government and Public Works official Pascal Girard allowed the company to keep bidding for contracts since the original sale was government-approved.\n\n# Hostage Diplomacy: The Detention of Kevin and Julia Garratt\n\n* Context: In retaliation for the arrest and extradition process of Su Bin, the PRC detained Canadians Kevin and Julia Garratt in Dandong on August 44, 20142014.\n* Profile of the Targets: The Garratts were Christians who ran Peter’s Coffee House near the North Korean border. They had been in China since the 19801980s.\n* Detention Conditions: They were lured to dinner, separated into black sedans, and kept under constant surveillance (2424 hours). They faced daily interrogations lasting 66 hours.\n* Swap Strategy: Charges included stealing intelligence on military targets, mimicking the charges against Su Bin. Canadian Ambassador Guy Saint-Jacques confirmed it was a clear attempt at a prisoner swap. Julia was released in May 20162016 and Kevin in September 20162016 after Su Bin’s guilty plea.\n\n# Biological Threats and the Winnipeg NML Laboratory Incident\n\n* Personnel: Xiangguo Qiu (medical doctor/biologist) and her husband Keding Cheng worked at the National Microbiology Laboratory (NML) in Winnipeg, Canada’s only biosafety level 44 (P4) facility.\n* Breakthrough Research: Qiu discovered ZMab, a monoclonal antibody mixture that cured Ebola. She received a Governor General’s Award in 20182018.\n* Security Breaches: Qiu was removed from the lab in 20192019 for the following reasons:\n * Collaborations: Lying about secret partnerships with the Wuhan Institute of Virology (WIV) and the Academy of Military Medical Sciences (AMMS), a group researching chemical and biological weapons for the PLA.\n * Talent Programs: Applying for PRC talent recruitment programs (Thousand Talents Plan) that offered him $1\$1 million in research grants.\n * Unauthorized Shipments: Sending Ebola and Nipah virus samples to Wuhan without a Material Transfer Agreement (MTA).\n * Internal Access: Her husband, Keding Cheng, provided lab passwords and unsupervised access to restricted visitors, including one connected to the PLA who attempted to smuggle out vials.\n* Current Status: Qiu and Cheng are back in China living under aliases, continuing military-linked research.\n\n# COVID-19 Origins and Gain of Function Research\n\n* The Lab Leak Theory: The US Department of Energy and the FBI (by 20232023) assessed with "low confidence" that COVID-19 originated from a lab leak at WIV. In January 20252025, the CIA also reached this conclusion with low confidence.\n* Gain of Function (GOF): This involves creating synthetic virus strains to study pathogenicity before they occur in nature. Researcher Shi Zhengli ("bat woman") conducted GOF research on SARS-like viruses.\n* The Qiu Link: In Spring 20192019, Qiu was approved by a PRC evaluation committee to lead "overall planning" for a project at the Wuhan lab involving cross-species infection of synthetic viruses and "bat filoviruses."\n* Vaccine Failures: Canada attempted a vaccine deal with CanSino Biologics (linked to the PLA), but the deal collapsed when China refused to send samples to Canada.\n\n# Interference in Academia and Talent Recruitment\n\n* Recruitment Strategy: "Feed, Trap, and Kill": Prof. Ben Fung (McGill) described the PRC’s three-stage approach to co-opting academics:\n 1. Feed: Approaching targets with enticing offers (money, labs, fame) when they are vulnerable (e.g., during budget cuts or sabbaticals).\n 2. Trap: Forcing dependency on PRC funding, making it impossible to refuse unreasonable requests later.\n 3. Kill: Discarding or discrediting the researcher once the IP is stolen or the target is no longer useful.\n* Thousand Talents Plan (TTP): Targeted ethnically Chinese scientists to bolster PRC strategic goals. Participants often signed contracts giving China ownership of IP created at Western universities. It was succeeded by the NHFERP (National High-End Foreign Experts Recruitment Plan) in 20192019.\n* Sensitive Collaboration: Between 20052005 and 20222022, researchers at 5050 Canadian universities collaborated with PLA scientists. This included research on quantum cryptography and missile systems with the National University of Defense Technology (NUDT), which has been blacklisted by the US since 20152015.\n\n# Confucius Institutes (CI) and Social Control\n\n* Propaganda: Senior PRC official Li Changchun described CIs as an "important part of China’s overseas propaganda set-up." They were overseen by the United Front Work Department (UFWD).\n* Censorship: Agreements included secrecy clauses and prohibited the discussion of the "33 Ts" (Tibet, Taiwan, Tiananmen) and Falun Gong. \n* Global Pushback: \n * McMaster University: Closed its CI in 20132013 after a human rights complaint from teacher Sonia Zhao.\n * Toronto District School Board (TDSB): Rejected a CI deal in 20142014 due to CCP ties.\n * New Brunswick: Ended its contract in 20192019 despite threats to lobster exports from the PRC consul general.\n* Rebranding: In 20202020, the headquarters (Hanban) was renamed the Centre for Language Education and Cooperation. CIs are often rebranded as collaborative university partnerships to bypass US and Canadian scrutiny.\n\n# Institutional Capture: The AIIB and TikTok\n\n* AIIB (Asian Infrastructure Investment Bank): Bob Pickard (Communications Director) fled China in 20232023, revealing the bank was a "PR arm of the Belt and Road Initiative" controlled by the CCP. He reported that party members monitored all staff and that Canada ($1\$1 billion investment) received no benefit.\n* TikTok: Owned by ByteDance. Investigations found user data was accessed by employees in China and content (Hong Kong protests) was censored. \n * Canada's Response: Banned from government devices in February 20232023. Ordered Canadian offices to close in November 20242024, though Canadians can still use the app. \n * US Response: A full ban occurred on January 1919, 20252025 after ByteDance refused to divest.\n* Recent Targeting: The FBI (not the Canadian government) notified Canadian MPs in 20242024 that they had been targets of a 20212021 cyberattack by the PRC group APT31.", "title": "Research Espionage and Foreign Interference: The PRC in Canada"}