Anthem Breach Evidence Points to China, Security Researchers Say | eWeek

Anthem Breach Evidence Points to China, Security Researchers Say

Anthem Breach Source 2
Written By
Robert Lemos
Robert Lemos
Feb 28, 2015
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A new open-source intelligence analysis of the breach of health insurer Anthem has reinforced theories that the data theft leads back to a Chinese espionage program, security firm ThreatConnect stated on Feb. 27.

In the report, which is based on public sources or “open-source” intelligence, security researchers at ThreatConnect and other companies found technical evidence that linked the malware reportedly used in the Anthem attack to a Chinese espionage group and a professor at Southeast University, which works with a government contractor, Beijing Topsec Technology Co.

A variety of evidence—including email addresses, domains registered for the command-and-control servers and the certificate used to sign the malware—led back to the trio of actors, Rich Barger, chief intelligence officer for ThreatConnect, told eWEEK.

“All of this evidence, from the technical aspect, pointed back to China in numerous ways despite the actors’ best efforts to shroud their origins,” Barger said. “They made an effort to hide, but they messed up.”

The analysis is the latest attempt to gain insight into the massive breach of Anthem, the largest health care insurer of the 37 companies that make up the Blue Cross Blue Shield Association. In early February, the company, formerly known as Wellpoint, announced that attackers may have accessed personally identifiable information on more than 80 million patients, including names, dates of birth, Social Security numbers, health care ID numbers, home addresses, email addresses and employment information. The information of other Blue Cross Blue Shield members who were treated in the regions served by Anthem may have also been compromised.

Cyber-criminals typically attempt to sell such data, but so far, there is little evidence that the information has been sold, according to ThreatConnect’s analysis.

The analysis linked espionage malware known as Derusbi, associated with Chinese espionage groups, and signed with the valid signature of DETOPTOOLZ, a Korean software firm.

The DTOPTOOLZ signature has been seen in conjunction with the Derusbi, Sakula, and HttpBrowser/HttpDump malware families. All of them are linked to Chinese advanced persistent threat (APT) groups, according to ThreatConnect’s analysis. One case of the malware added to ThreatConnect’s intelligence platform linked Sakula to command-and-control servers using the domains we11point.com, where the “ll” was replaced with the number 11.

Other similar attacks linked the domain owner to an email address connected to an information security competition run by the Southeast University-Topsec Information Security and Mobile Internet Technology Joint Research Center. A U.S. Department of State memo, leaked by WikiLeaks in 2009, noted that Topsec had received significant investment from the People’s Liberation Army.

In all, the evidence forms a clear picture of a Chinese attack designed to collect information on U.S. citizens, Barger said. The Blue Cross and Blue Shield Association serves one-in-three Americans and 5.3 million federal employees, retirees and their dependents, which could indicate a motive for the attack.

“Some people say that attribution is hard in cyber,” he said. “But denial and deception [the act of deceiving defenders] in cyber is even harder.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.