Research Espionage and Foreign Interference: The PRC in Canada
Cyber Espionage and the Global Infrastructure of GhostNet\n\n* Discovery in India (2008): Researcher Shishir Nagaraja and Greg Walton entered the Dalai Lama’s offices to investigate computer anomalies. They were sent by Rafal Rohozinski of SecDev, a digital security firm connected to the Information Warfare Monitor (founded by Ron Deibert of the University of Toronto’s Citizen Lab).\n* Methodology: Nagaraja and Walton used WireShark software to scan network traffic. They worked three 14-hour days under intense scrutiny. They discovered a remote command ordering the retrieval of a specific file regarding "classified information about building contracts for schools in Tibet."\n* GhostNet and GhostRat: The malware, which they dubbed GhostNet (the network) and GhostRat (the code), spread via Microsoft Word and PDF documents. \n * Versatility: GhostRat could view monitors, log keystrokes, download files, activate webcams for covert recording, and control computers remotely.\n * Uniqueness: It searched for specific bits of information requested by its controllers rather than just bulk-copying data.\n* Tracking the Handlers: Nick Villeneuve, a researcher at Citizen Lab, identified a unique 22-character text string in the URL of a control server. This led to the discovery of:\n * One control server in the US used as a data dump.\n * Five control servers located in China.\n* Targets of Interest: The network infected Thousands of machines, including those in embassies, international government offices, the Asian Development Bank, and Tibetan/Taiwanese groups.\n\n# The Scale and Methodologies of PRC Intellectual Property Theft\n\n* The Global Impact: In 2012, NSA director Keith Alexander described China’s theft as "the greatest transfer of wealth in human history."\n* Commercial Targets: James Dyson noted the theft of vacuum designs; paint manufacturer Dupont reported the theft of trade secrets regarding the color white.\n* Outsourced Hacking: The PRC frequently outsources to private firms such as I-Soon and Chengdu 404 (whose members were indicted by the US government).\n * A leaked I-Soon document showed a Shandong public security bureau paid approximately $55,000 for one year of access to 10 email accounts.\n * I-Soon boasted of its ability to hack X (formerly Twitter) and Facebook and assist in "anti-terrorism" in the Xinjiang region to monitor the Uyghur population.\n* Critical Infrastructure Attacks: In September 2013, Telvent Canada, which manages 60% of oil and gas pipelines in the western hemisphere, was attacked by the Comment Group, a PRC hacking organization. Stolen items included technology to mesh older electrical grids with smart technologies.\n\n# Military Espionage and High-Value Asset Theft\n\n* The Su Bin (Stephen) Case: Su Bin operated Lode-Tech in British Columbia. In 2014, he was identified as a "spotter" who identified targets (engineers and industry experts) for the PLA.\n * Data Breach: Between 2009 and 2014, Su assisted in stealing 630,000 files (65 gigabytes) related to the C-17 reconnaissance transport aircraft (R\u0026D cost: $30 billion).\n * Other Targets: He stole 220 megabytes of data on the F-22 Raptor and significant files on the F-35.\n * Laundering Data: Files were moved through multiple countries to Hong Kong, where data was physically transported to mainland China to avoid digital tracking.\n * Outcome: Su Bin pleaded guilty in 2016 and did not contest extradition.\n* Pratt \u0026 Whitney Canada: In 2012, the company pleaded guilty to violating US export laws by providing technology that enabled China to build its first attack helicopter, the Z-10 Zhisheng. Despite the conviction, the Canadian government and Public Works official Pascal Girard allowed the company to keep bidding for contracts since the original sale was government-approved.\n\n# Hostage Diplomacy: The Detention of Kevin and Julia Garratt\n\n* Context: In retaliation for the arrest and extradition process of Su Bin, the PRC detained Canadians Kevin and Julia Garratt in Dandong on August 4, 2014.\n* Profile of the Targets: The Garratts were Christians who ran Peter’s Coffee House near the North Korean border. They had been in China since the 1980s.\n* Detention Conditions: They were lured to dinner, separated into black sedans, and kept under constant surveillance (24 hours). They faced daily interrogations lasting 6 hours.\n* Swap Strategy: Charges included stealing intelligence on military targets, mimicking the charges against Su Bin. Canadian Ambassador Guy Saint-Jacques confirmed it was a clear attempt at a prisoner swap. Julia was released in May 2016 and Kevin in September 2016 after Su Bin’s guilty plea.\n\n# Biological Threats and the Winnipeg NML Laboratory Incident\n\n* Personnel: Xiangguo Qiu (medical doctor/biologist) and her husband Keding Cheng worked at the National Microbiology Laboratory (NML) in Winnipeg, Canada’s only biosafety level 4 (P4) facility.\n* Breakthrough Research: Qiu discovered ZMab, a monoclonal antibody mixture that cured Ebola. She received a Governor General’s Award in 2018.\n* Security Breaches: Qiu was removed from the lab in 2019 for the following reasons:\n * Collaborations: Lying about secret partnerships with the Wuhan Institute of Virology (WIV) and the Academy of Military Medical Sciences (AMMS), a group researching chemical and biological weapons for the PLA.\n * Talent Programs: Applying for PRC talent recruitment programs (Thousand Talents Plan) that offered him $1 million in research grants.\n * Unauthorized Shipments: Sending Ebola and Nipah virus samples to Wuhan without a Material Transfer Agreement (MTA).\n * Internal Access: Her husband, Keding Cheng, provided lab passwords and unsupervised access to restricted visitors, including one connected to the PLA who attempted to smuggle out vials.\n* Current Status: Qiu and Cheng are back in China living under aliases, continuing military-linked research.\n\n# COVID-19 Origins and Gain of Function Research\n\n* The Lab Leak Theory: The US Department of Energy and the FBI (by 2023) assessed with "low confidence" that COVID-19 originated from a lab leak at WIV. In January 2025, the CIA also reached this conclusion with low confidence.\n* Gain of Function (GOF): This involves creating synthetic virus strains to study pathogenicity before they occur in nature. Researcher Shi Zhengli ("bat woman") conducted GOF research on SARS-like viruses.\n* The Qiu Link: In Spring 2019, Qiu was approved by a PRC evaluation committee to lead "overall planning" for a project at the Wuhan lab involving cross-species infection of synthetic viruses and "bat filoviruses."\n* Vaccine Failures: Canada attempted a vaccine deal with CanSino Biologics (linked to the PLA), but the deal collapsed when China refused to send samples to Canada.\n\n# Interference in Academia and Talent Recruitment\n\n* Recruitment Strategy: "Feed, Trap, and Kill": Prof. Ben Fung (McGill) described the PRC’s three-stage approach to co-opting academics:\n 1. Feed: Approaching targets with enticing offers (money, labs, fame) when they are vulnerable (e.g., during budget cuts or sabbaticals).\n 2. Trap: Forcing dependency on PRC funding, making it impossible to refuse unreasonable requests later.\n 3. Kill: Discarding or discrediting the researcher once the IP is stolen or the target is no longer useful.\n* Thousand Talents Plan (TTP): Targeted ethnically Chinese scientists to bolster PRC strategic goals. Participants often signed contracts giving China ownership of IP created at Western universities. It was succeeded by the NHFERP (National High-End Foreign Experts Recruitment Plan) in 2019.\n* Sensitive Collaboration: Between 2005 and 2022, researchers at 50 Canadian universities collaborated with PLA scientists. This included research on quantum cryptography and missile systems with the National University of Defense Technology (NUDT), which has been blacklisted by the US since 2015.\n\n# Confucius Institutes (CI) and Social Control\n\n* Propaganda: Senior PRC official Li Changchun described CIs as an "important part of China’s overseas propaganda set-up." They were overseen by the United Front Work Department (UFWD).\n* Censorship: Agreements included secrecy clauses and prohibited the discussion of the "3 Ts" (Tibet, Taiwan, Tiananmen) and Falun Gong. \n* Global Pushback: \n * McMaster University: Closed its CI in 2013 after a human rights complaint from teacher Sonia Zhao.\n * Toronto District School Board (TDSB): Rejected a CI deal in 2014 due to CCP ties.\n * New Brunswick: Ended its contract in 2019 despite threats to lobster exports from the PRC consul general.\n* Rebranding: In 2020, the headquarters (Hanban) was renamed the Centre for Language Education and Cooperation. CIs are often rebranded as collaborative university partnerships to bypass US and Canadian scrutiny.\n\n# Institutional Capture: The AIIB and TikTok\n\n* AIIB (Asian Infrastructure Investment Bank): Bob Pickard (Communications Director) fled China in 2023, revealing the bank was a "PR arm of the Belt and Road Initiative" controlled by the CCP. He reported that party members monitored all staff and that Canada ($1 billion investment) received no benefit.\n* TikTok: Owned by ByteDance. Investigations found user data was accessed by employees in China and content (Hong Kong protests) was censored. \n * Canada's Response: Banned from government devices in February 2023. Ordered Canadian offices to close in November 2024, though Canadians can still use the app. \n * US Response: A full ban occurred on January 19, 2025 after ByteDance refused to divest.\n* Recent Targeting: The FBI (not the Canadian government) notified Canadian MPs in 2024 that they had been targets of a 2021 cyberattack by the PRC group APT31.", "title": "Research Espionage and Foreign Interference: The PRC in Canada"}