jian

Threat Actor updated 23 days ago (2024-11-29T14:28:32.646Z)
Download STIX
Preview STIX
Jian is a threat actor that has been linked to several significant cybersecurity incidents. One of its most notable activities was the use of a tool named Jian, a clone of the NSA Equation Group's "EpMe" hacking tool, which it reportedly used years before it was leaked online by Shadow Brokers hackers. This was discovered in 2022 by the Check Point Research team and made headlines globally. The group behind this tool, APT31 (also known as Zirconium, Judgment Panda, and Red Keres), is believed to be China-linked and has been involved in multiple cyber espionage operations. In a related development, Jian Wen, a 42-year-old individual with both UK and Chinese citizenship, was sentenced to six years and eight months in prison by the Southwark Crown Court in London for laundering $10.4 million worth of cryptocurrency linked to a billion-dollar investment fraud. This case further highlighted the growing concern about the role of threat actors like Jian in global cybercrime. However, these allegations have been met with denial from Chinese officials. Lin Jian, a Chinese Foreign Ministry spokesperson, described the UK accusations as "false information" and called for "objective evidence." Several experts have weighed in on the situation, including Dr Chia-Mu Yu of the National Institute of Cybersecurity, Mr Jian-Lung Lin, Director of High-Tech Crime Center of the Taiwan Ministry of Interior Affairs, and Mr Ming-Jen Wu of the Department of Communications and Cyber Resilience. They have spoken on mitigation measures for crime prevention and safeguarding critical information infrastructure, emphasizing the importance of international cooperation in dealing with such threats. Despite the controversy surrounding the attribution of these cyber-attacks, the consensus is clear: the threat posed by actors like Jian necessitates collective action and robust cybersecurity measures.
Description last updated: 2024-11-28T11:47:14.995Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
APT31 is a possible alias for jian. APT31, also known as Zirconium, is a threat actor believed to be linked to the Chinese government. This group has been associated with numerous cyber attacks, including a significant exploit of CVE-2017-0005. This exploit, dubbed "Jian," was initially attributed to APT31 but upon further analysis by
2
ZIRCONIUM is a possible alias for jian. Zirconium, also known as APT31, Judgment Panda, and Red Keres, is a threat actor linked to numerous cyber espionage operations. The group came into the spotlight in 2022 when the Check Point Research team discovered that it had used a tool called "Jian," a clone of the NSA Equation Group's hacking t
2
Epme is a possible alias for jian. EpMe is a software vulnerability (CVE-2017-0005) that was first discovered within the Equation Group's exploit arsenal, with its existence traced back to at least 2013. The Equation Group, believed to be linked to the NSA, developed this exploit as part of their cyber toolset which also included Dan
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Equation Group Threat Actor is associated with jian. The Equation Group is a threat actor, believed to have ties to the United States, that has been involved in numerous cyber espionage operations. The group's favorite vulnerabilities include CVE-2017-0144, a Windows server message block code execution vulnerability that was leaked by another group knUnspecified
2
Source Document References
Information about the jian Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CISA
24 days ago
BankInfoSecurity
7 months ago
Securityaffairs
9 months ago
InfoSecurity-magazine
9 months ago
CERT-EU
9 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
2 years ago
Securityaffairs
2 years ago
CERT-EU
2 years ago