Tuesday, April 2, 2019

Chinese woman arrested with flash drive full of malware after lying her way into Mar-A-Lago

President Trump near Air Force One. BBC/AFP.

A Chinese woman has been arrested after being discovered with a flashdrive and external hardrive filled with malware at President Trump's Mar-A-Lago club. BBC. The woman, Yujing Zhang, a 32 year old, told security that she was their to use the pool. At the reception desk, she told the receptionist that she was their for a UN Chinese American Association event. This raised suspicions and she was searched, revealing the malware, along with four cellphones and a laptop computer. Zhang claimed that someone named "Charles" had instructed her to speak to someone in the Trump family about Chinese-American economic relations. Zhang has been charged with lying to federal officials and illegally entering a restricted area. President Trump was present at Mar-A-Lago when the incident occurred. 

 My Comment:
This case just screams espionage to me. It seems very clear that this woman's goal was to install malware in Mar-A-Lago so whoever ordered her to do this could gather intelligence. Mar-A-Lago is a critical Trump property and is often called the "Southern White House". Trump visits the property very frequently and it's an obvious target for espionage. 

It seems that the attack failed though. She was able to bluff her way past security but was not able to do so against the front desk. She apparently faked an inability to speak English well and claimed to be related to someone who was a member at the club. That seems to have worked but when her story at the front desk didn't work out she got caught. 

Her timing was poor. It's fairly dumb to try to install malware at the President's resort when the President was there. Security would have been much tighter then it would have been if he wasn't visiting at the time. Indeed, she may have been able to bluff her way past security and make her way to a computer and install the malware. 

But even then, would it have worked long term? I doubt it. I am guessing that Mar-A-Lago has a robust security system and it would be very unlikely that any intrusion like this would go undetected. Either she would be caught on camera trying to install the malware or the virus would be detected right away after being installed. It's not likely to have worked even if she got access to a computer. 

I'm guessing though that whoever put this woman up to this thinks it's worth the risk. Being able to spy on President Trump would be a huge advantage and could reveal state secrets. It could change the balance of power and it's even possible that the malware could spread beyond Mar-A-Lago. 

So who was responsible for this attack? Well Zhang is of Chinese descent so China is the obvious suspect. They certainly have the means, motive and opportunity to do such a thing, plus they are very good at trying to spy on Americans. They usually aren't this blatant though. Other suspects include Russia, North Korea, Iran or even a non-state actor. There's even a tiny chance Zhang worked alone. 

Thankfully, this attack failed. It really didn't even come close to succeeding. I am guessing that a security review is going to happen and it's likely the guard(s) that let Zhang on site will get fired. However, the receptionist that sounded the alarm should get a promotion as he or she did a great service to the country. 

No comments:

Post a Comment