FBI Seeks Jiang Lizhi in APT 41 International Cyberattack and Ransomware Case
Chinese National Linked to APT 41 Investigation
Jiang Lizhi is wanted by the FBI for his alleged involvement in a global cybercrime operation connected to the Chinese hacking group known as APT 41, also called BARIUM. According to the FBI, Jiang and his co-defendants allegedly carried out unauthorized computer intrusions while employed by Chengdu 404 Network Technology Company. The alleged attacks targeted hundreds of companies across numerous industries and countries.
Global Cyber Intrusion Campaign
Federal authorities accuse Jiang and other alleged APT 41 members of conducting extensive computer intrusions against networks throughout the world. The operation allegedly relied in part on supply-chain attacks that allowed the defendants to obtain unauthorized access to computer systems.
The FBI states that hundreds of companies were targeted. Industries affected by the alleged campaign included social media, telecommunications, government, defense, education, and manufacturing. The broad selection of targets made the operation a significant international cybercrime investigation.
Companies Across Several Countries Targeted
According to the FBI, companies in Australia, Brazil, Germany, India, Japan, and Sweden were among the victims of the alleged computer intrusions. The defendants are accused of targeting organizations across different industries rather than concentrating on a single geographic region or business sector.
The international scope of the alleged campaign also extended to telecommunications infrastructure. Federal investigators identified telecommunications providers across numerous countries and regions as targets of the defendants' activities.
Telecommunications Providers Targeted
The FBI states that telecommunications providers in the United States, Australia, China's Tibet region, Chile, India, Indonesia, Malaysia, Pakistan, Singapore, South Korea, Taiwan, and Thailand were allegedly targeted.
Telecommunications networks can contain significant amounts of sensitive information and provide access to large numbers of users and organizations. The allegations involving these providers form an important part of the broader federal case against Jiang and his co-defendants.
Ransomware and Payment Demands
Federal authorities also accuse the defendants of deploying ransomware against victims. According to the FBI, payments were demanded following some of these attacks.
The ransomware allegations add a financial component to a case that also involves unauthorized computer access and information theft. Investigators allege that the defendants participated in multiple forms of cybercrime while conducting operations against organizations around the world.
Chengdu 404 Network Technology Company
Jiang allegedly conducted the computer intrusions while employed by Chengdu 404 Network Technology Company. The FBI also identifies Fu Qiang and Qian Chuan as Chinese nationals charged alongside him in connection with the company's alleged activities.
The three men are accused of participating in cyber operations associated with APT 41 while working for the Chengdu-based company. Their alleged activities ultimately resulted in a federal grand jury investigation in Washington, D.C.
Federal Indictment Filed
On August 11, 2020, a federal grand jury in the District of Columbia returned an indictment against Jiang Lizhi, Qian Chuan, and Fu Qiang. The indictment included numerous charges arising from the alleged unauthorized computer intrusions.
The FBI lists charges including racketeering conspiracy, conspiracy, identity theft, aggravated identity theft, access device fraud, obtaining information through unauthorized access to protected computers, intentionally causing damage to protected computers, threatening to damage a protected computer, and money laundering.
The charges remain allegations unless and until established through the federal judicial process.
FBI Description of Jiang Lizhi
According to the FBI's wanted information, Jiang Lizhi is a Chinese national with ties to Chengdu, China. His association with Chengdu is particularly relevant because of his alleged employment with Chengdu 404 Network Technology Company.
The FBI identifies several aliases associated with Jiang, including “Blackfox,” “Blackfox_2,” and “Fox.” These online identifiers may be important to individuals who encountered him through technical communities, online communications, or other cyber-related activities.
APT 41 and BARIUM
APT 41 is the designation used for the Chinese hacking group associated with the defendants in the FBI's case. The group has also been identified as BARIUM. The investigation into Jiang is part of a broader federal effort involving several individuals accused of participating in the group's cyber operations.
The FBI continues seeking information concerning individuals associated with APT 41 and the activities described in the federal indictments. Information concerning professional relationships, online identities, locations, or associates may assist investigators.
Ties to Chengdu
The FBI specifically notes Jiang's ties to Chengdu, China. Individuals who previously worked with him, communicated with him online, or encountered him through Chengdu 404 Network Technology Company may possess information relevant to the investigation.
Information concerning Jiang's current location, employment, associates, or online identities should be provided directly to authorities. Members of the public should not attempt to independently investigate or locate him.
FBI Seeks Information
The FBI's Washington Field Office is responsible for Jiang's wanted case. Anyone with information concerning Jiang Lizhi or his whereabouts can contact the FBI or submit information through the Bureau's official tip system. Individuals outside the United States may also contact the nearest U.S. embassy or consulate.
Sources
FBI — Jiang Lizhi Wanted Profile