The perils of non-disclosure? China 'cloned and used' NSA zero-day exploit for years before it was made public

The perils of non-disclosure? China 'cloned and used' NSA zero-day exploit for years before it was made public

A zero-day exploit said to have been developed by the NSA was cloned and used by Chinese government hackers on Windows systems years before the cyber-weapon was leaked online, it is claimed.


Check Point put out a report on Monday digging into the Chinese malware it calls Jian, and argues persuasively this particular software nasty was spawned sometime around 2014 from NSA exploit code that leaked online in 2017.

The timeline basically seems to be, according to Check Point:


  • 2013: NSA's Equation Group developed a set of exploits including one called EpMe that elevates one's privileges on a vulnerable Windows system to system-administrator level, granting full control. This allows someone with a foothold on a machine to commandeer the whole box.

  • < ..

    Support the originator by clicking the read the rest link below.