China to lay off five to six million workers

Hank Paulson: China needs to let ‘failing companies fail’

Former U.S. Treasury Secretary Henry Paulson, who oversaw bank bailouts during the global financial crisis, has different advice for China: Let companies fail.

“They can show right now they’re very serious about dealing with inefficient state-owned enterprises as they take capacity out of the steel industry, coal industry and others by letting some failing companies fail,” Paulson, who was Treasury secretary from 2006-2009, told CNBC’s Squawk Box on the sidelines of an Institute of International Finance event organized in conjunction with the G20 meeting in Shanghai.

As Treasury secretary, Paulson oversaw a $700 billion government-funded bailout of U.S. financial institutions that were seen as “too big to fail” in the global financial crisis.

Paulson, who is also a former chairman and CEO of Goldman Sachs, added that China needed to move faster to promote competition.

“Competition is about opening up to the private sector, which is the future, and it’s about putting the state-owned enterprises on a level playing field,” said Paulson,, who earlier this decade founded the independent think tank Paulson Institute promoting sustainable and environmental projects. “There’s clearly room to move faster.”

Last year, China issued guidance on reforming often-inefficient state enterprises, such as introducing mixed public-private ownership as well as pushing for mergers and share sales, but the market isn’t always certain of progress on this front.

Exclusive: China to lay off five to six million workers, earmarks at least $23 billion

Reuters: China aims to lay off 5-6 million state workers over the next two to three years as part of efforts to curb industrial overcapacity and pollution, two reliable sources said, Beijing’s boldest retrenchment program in almost two decades.

China’s leadership, obsessed with maintaining stability and making sure redundancies do not lead to unrest, will spend nearly 150 billion yuan ($23 billion) to cover layoffs in just the coal and steel sectors in the next 2-3 years.

The overall figure is likely to rise as closures spread to other industries and even more funding will be required to handle the debt left behind by “zombie” state firms.

The term refers to companies that have shut down some of their operations but keep staff on their rolls since local governments are worried about the social and economic impact of bankruptcies and unemployment.

Shutting down “zombie firms” has been identified as one of the government’s priorities this year, with China’s Premier Li Keqiang promising in December that they would soon “go under the knife”..

The government plans to lay off five million workers in industries suffering from a supply glut, one source with ties to the leadership said.

A second source with leadership ties put the number of layoffs at six million. Both sources requested anonymity because they were not authorized to speak to media about the politically sensitive subject for fear of sparking social unrest.

The ministry of industry did not immediately respond when asked for comment on the reports.

The hugely inefficient state sector employed around 37 million people in 2013 and accounts for about 40 percent of the country’s industrial output and nearly half of its bank lending.

It is China’s most significant nationwide retrenchment since the restructuring of state-owned enterprises from 1998 to 2003 led to around 28 million redundancies and cost the central government about 73.1 billion yuan ($11.2 billion) in resettlement funds.

On Monday, Yin Weimin, the minister for human resources and social security, said China expects to lay off 1.8 million workers in the coal and steel industries, but he did not give a timeframe.

China aims to cut capacity gluts in as many as seven sectors, including cement, glassmaking and shipbuilding, but the oversupplied solar power industry is likely to be spared any large-scale restructuring because it still has growth potential, the first source said.

DEBT OVERHANG

The government has already drawn up plans to cut as much as 150 million tonnes of crude steel capacity and 500 million tonnes of surplus coal production in the next three to five years.

It has earmarked 100 billion yuan in central government funds to deal directly with the layoffs from steel and coal over the next two years, vice-industry minister Feng Fei said last week.

The Ministry of Finance said in January it would also collect 46 billion yuan from surcharges on coal-fired power over the coming three years in order to resettle workers. In addition, an assortment of local government matching funds will also be made available.

However, the funds currently being offered will do little to resolve the problems of debts held by zombie firms, which could overwhelm local banks if they are not handled correctly.

“They have proposed this dedicated fund only to pay the workers, but there is no money for the bad debts, and if the bad debts are too big the banks will have problems and there will be panic,” said Xu Zhongbo, head of Beijing Metal Consulting, who advises Chinese steel mills.

Factories shut down would have to repay bank loans to avoid saddling state banks with a mountain of non-performing loans, the sources said. “Triangular debt”, or money owed by firms to other enterprises, would also have to be resolved, they added.

Although China has promised to help local banks transfer the bad debts of zombie steel mills to asset management firms, local governments are not expected to gain access to the worker lay-off funds until the zombie firms have actually been shut down and debt issues settled.

($1 = 6.5476 Chinese yuan)

China’s Exploding Military Footprint

This Map Visualizes China’s Growing Military Capabilities In The South China Sea

This Map Visualizes China's Growing Military Capabilities In The South China Sea

This awesome interactive map shows China’s emerging area denial and anti-access military capabilities in the South China Sea. It is useful in visually tracking China’s progress towards creating an overlapping field of control over a vast majority of the area.

The map, which you can access here, is built by the Center for Strategic and International Studies (CSIS).

Great work Tyler:One of China’s highly developed islands in the northern part of the South China Sea, Woody Island, has been equipped with surface-to-air missiles and fighter aircraft. These moves have come just as many defense analysts have predicted for years and are likely an indication of things to come for China’s other island outposts throughout the South China Sea.

There is also evidence that China is installing a high-frequency long-range radar array on Cuarteron Reef, one of their handful of manmade islands in the south-central part of the South China Sea. This radar type is known to be used for detecting aircraft and ships at extreme ranges far over-the-horizon and can theoretically detect some stealthy aircraft under certain circumstances. It is just one of many other sensors popping up on this island and others, although the existence of such a capability provides even more evidence that China is actively seeking an aggressive anti-access, area denial strategy over the South China Sea.

China might be installing HF radar that can detect stealth aircraft in S. China Sea

This all comes as China’s largest island building project out of their manmade island initiative, Fiery Cross Reef, officially activated its 9,000-foot runway early last month. The runway is capable of supporting even China’s heaviest bomber and transport aircraft.

With any luck CSIS will keep updating this fabulous visual resource as China expands its military capabilities to its other islands that remain under construction in the South China Sea. Undoubtedly, the threat rings you see today will blossom and multiply, creating a massive overlapping area of control backed up by anti-ship and anti-air missiles, as well as fighter and maritime surveillance and attack aircraft.

Going back to 2015: (So much for that Obama Asia Pivot)

WSJ:

Analysts say the imminent end to China’s island-building work could signal a willingness to seek compromise with Washington and rival claimants in the South China Sea, even as it demonstrates Beijing’s ability to unilaterally dictate terms in the long-standing dispute.

“This is a step toward halting land reclamation, which the U.S. has demanded, and at the same time, China can tell its people that it has accomplished what it wanted to do,” said Huang Jing, an expert on Chinese foreign policy at the Lee Kuan Yew School of Public Policy in Singapore.

“China unilaterally started the land reclamation and now China is unilaterally stopping it,” Mr. Huang said. “China is showing that—as a major power—it can control escalation, that it has the initiative, and that it can do what it sees fit for its interests.”

Beijing lays claim to almost the entire South China Sea, a stretch of resource-rich waters that carries more than half the world’s trade. Its claims overlap with those of Malaysia, Vietnam, Brunei, Taiwan and the Philippines—several of whom have criticized China’s rapid and extensive construction program in the Spratlys as the latest in a series of aggressive Chinese efforts to assert territorial rights.

 

A Plane Titled Arsenal

Here’s what we know about the Pentagon’s new, secret warplane

BusinessInsider: There’s increasing chatter about a secret, potentially costly, Defense Department weapons program with an interesting moniker: the “Arsenal Plane.”

Defense Secretary Ash Carter mentioned the project earlier this month while describing the work of the Strategic Capabilities Office (SCO), a clandestine workshop established within the Pentagon in 2012 to develop the next generation of bleeding-edge weapons, ostensibly to counter China and Russia.

The new warplane effort “takes one of our oldest aircraft platform and turns it into a flying launch pad for all sorts of different conventional payloads,” Carter said during a Feb. 2 speech previewing the department’s then-pending fiscal 2017 budget request.

“In practice, the arsenal plane will function as a very large airborne magazine, networked to fifth generation aircraft that act as forward sensor and targeting nodes, essentially combining different systems already in our inventory to create holy new capabilities,” he said, referring to the F-35 Joint Strike Fighter.

The Pentagon chief mentioned the project again on Thursday when he testified before the House Appropriations Defense subpanel and ticked off a handful of technologies SCO is working on, including the Air Force’s budget-busting Long Range Strike Bomber (LRSB) program and “swarming 3-D printed micro-drones.”

But what’s known about the Arsenal Plane beyond that? Defense leaders aren’t giving up any specifics.

The concept is being developed “in partnership with DARPA. We will be supporting, and the idea is to look for additional ways to arm a particular aircraft so that it might be able to do different types of missions. More munitions and different types of munitions,” Air Force Secretary Deborah Lee James said during a Feb. 12 Air Force Association event.

But when asked what kind of legacy aircraft might be retrofitted to essentially turn it into an airborne aircraft carrier, James punted: “I think all of this is still being discussed. It’s still a program in development. Those decisions haven’t been reached yet.”

Air Force

The concept was originally introduced in the 1980s, when the military considered turning one of its existing bombers, or a commercial plane like the Boeing 747, into a launcher capable of carrying anywhere from 50 to 70 missiles. The idea was scrapped due to the envisioned platform’s lack of connectivity and precision weapons and the large platform’s inherent vulnerability to enemy attack aircraft.

However, the idea is getting a second-look in the wake of China’s aggressive behavior in the Asia-Pacific region, especially in the South China Sea where Beijing is reclaiming land in the disputed Spratly Islands and turning them into manmade outposts for some of it most advanced military hardware.

The Arsenal Plane is also “a response to the limits of the F-35,” according to Richard Aboulafia, Vice President of Analysis at the Teal Group. For all its traits, the plane “doesn’t hold a whole lot of ordnance.”

Indeed, an F-35 maxes out at around 18,000 pounds of ordnance, and that when munitions are loaded on the plane’s wings – a move that would compromise its stealth technology (and therefore the whole point of the aircraft itself).

That limited amount of weaponry could prove deadly in a dogfight.

“Obviously, in Asia, you’ve got the problem with Chinese numbers,” Aboulafia said, referring to China’s years-long push to modernize and expand all aspects of its military.

Ideally, the new aircraft would be loaded for bear with precision guided missiles so that a squadron of F-35s that might encounter a number of hostile jets could rely on the larger plane for assistance, or cue in targeting information to help it fight or bug out

Aboulafia said the concept is “worth investigating” because one of China’s highest military priorities has been to develop long range, heavy combat fighters — along the lines of its J-20 jet — that are stealthy and capable of taking out tankers or AWACS, an airborne early warning aircraft, which packs little to no firepower.

He said modern technology has largely solved the connectivity and precision issue from the ‘80s, but the size and vulnerability problem remains.

“These things … become missile magnets in a time of war,” he said.

The Pentagon may be moving forward, regardless. Inside Defense, a trade publication, speculates that the department’s 2017 budget request for $198 million in funding for advanced component development for an “Alternative Strike” program is actually for the Arsenal Plane.

The spending request is under the SCO umbrella and states the “project will demonstrate the feasibility and utility of launching existing/modified weapons from existing launch platforms,” the publication notes.

Provided the Air Force’s LRSB effort — expected to start replacing the service’s aging B-52 and B-1 bomber fleets in the 2020s – comes online according to plan, the Pentagon would have no shortage of platforms it could retrofit into a flying fortress instead of shipping off to the boneyard.

The new effort will no doubt be swarmed with questions about affordability, especially after a think-tank report released earlier this month warned of a coming “bow wave” in bills to the Air Force budget in the 2020s as the service looks to modernize.

But Aboulafia noted those costs are driven mostly by the F-35, the LRSB and the service’s new tanker programs.

“What might make this more affordable is an off-the-shelf platform … its cash footprint might be smaller,” he predicted.

This story was originally published by  The Fiscal Times.

After Ukraine, DHS Warns Domestic Utility Companies

Feds advise utilities to pull plug on Internet after Ukraine attack

WashingtonExaminer: The Department of Homeland Security advised electric utilities Thursday that they may need to stop using the Internet altogether, after the agency found that a cyberattack that brought down Ukraine’s power grid in December could have been far more devastating than reported.

The Dec. 23 cyberattack forced U.S. regulators to place utilities on alert after unknown attackers caused thousands of Ukrainian residents to lose power for hours by installing malicious software, or malware, on utility computers. But the Department of Homeland Security said Thursday that the attack may have been directed at more than just the country’s electricity sector, suggesting the attackers were looking to cause more harm than was reported.

In response, federal investigators are recommending that U.S. utilities and other industries “take defensive measures.” To start with, they need to best practices “to minimize the risk from similar malicious cyber activity,” according to an investigative report issued Thursday by Homeland Security’s Industrial Control Systems Cyber Emergency Response Team.

But the team is also recommending more drastic action, such as keep control-system computers away from the Internet.

“Organizations should isolate [industrial control system] networks from any untrusted networks, especially the Internet,” the report says. “All unused ports should be locked down and all unused services turned off. If a defined business requirement or control function exists, only allow real-time connectivity to external networks. If one-way communication can accomplish a task, use optical separation.”

The findings show that the power outages were caused by three attacks using cyberintrusion software to attack electric power distribution companies, affecting about 225,000 customers. It also reveals that once power was restored, the utilities continued “to run under constrained operations,” implying that the damage to grid control systems was profound.

The team also learned that “three other organizations, some from other critical infrastructure sectors, were also intruded upon but did not experience operational impacts.” That suggests the attackers were going after more than just the power grid, and may have been planning a much more economy-wide attack. The team does not disclose what other sectors of the country were targeted.

The team said the attack was well-planned, “probably following extensive reconnaissance of the victim networks,” the report says. “According to company personnel, the cyberattacks at each company occurred within 30 minutes of each other and impacted multiple central and regional facilities.”

The attackers were attempting to make the damage permanent. The report says the attackers installed “KillDisk” malware onto company computers that would erase data necessary to reboot operations after a cyberattack.

There is also a mystery to the attackers’ actions.

“Each company also reported that they had been infected with BlackEnergy malware; however, we do not know whether the malware played a role in the cyberattacks,” the report says. The malware was delivered using an email embedded hacking technique known as “spear phishing” that contained a number of malicious Microsoft Office attachments.

“It is suspected that BlackEnergy may have been used as an initial access vector to acquire legitimate credentials; however, this information is still being evaluated,” the team says.

The investigation was done with Ukraine authorities and involved the FBI, Department of Energy and the North American Electric Reliability Corporation.

*** 

New research is shining a light on the ongoing evolution of the BlackEnergy malware, which has been spotted recently targeting government institutions in the Ukraine.

Security researchers at ESET and F-Secure each have dived into the malware’s evolution. BlackEnergy was first identified several years ago. Originally a DDoS Trojan, it has since morphed into “a sophisticated piece of malware with a modular architecture, making it a suitable tool for sending spam and for online bank fraud,” blogged ESET’s Robert Lipovsky.

“The targeted attacks recently discovered are proof that the Trojan is still alive and kicking in 2014,” wrote Lipovsky, a malware researcher at ESET.

ESET has nicknamed the BlackEnergy modifications first spotted at the beginning of the year ‘BlackEnergyLite’ due to the lack of a kernel-mode driver component. It also featured less support for plug-ins and a lighter overall footprint.

“The omission of the kernel mode driver may appear as a step back in terms of malware complexity: however it is a growing trend in the malware landscape nowadays,” he blogged. “The threats that were among the highest-ranked malware in terms of technical sophistication (e.g., rootkits and bootkits, such as Rustock, Olmarik/TDL4, Rovnix, and others) a few years back are no longer as common.”

The malware variants ESET has tracked in 2014 – both of BlackEnergy and of BlackEnergy Lite – have been used in targeted attacks. This was underscored by the presence of plugins meant for network discovery, remote code execution and data collection, Lipovsky noted.

“We have observed over a hundred individual victims of these campaigns during our monitoring of the botnets,” he blogged. “Approximately half of these victims are situated in Ukraine and half in Poland, and include a number of state organizations, various businesses, as well as targets which we were unable to identify. The spreading campaigns that we have observed have used either technical infection methods through exploitation of software vulnerabilities, social engineering through spear-phishing emails and decoy documents, or a combination of both.”

In a whitepaper, researchers at F-Secure noted that in the summer of 2014, the firm saw samples of BlackEnergy targeting Ukrainian government organizations for the purposes of stealing information. These samples were nicknamed BlackEnergy 3 by F-Secure and identified as the work of a group the company refers to as “Quedagh.” According to F-Secure, the group is suspected to have been involved in cyber-attacks launched against Georgia during that country’s conflict with Russia in 2008.

“The Quedagh-related customizations to the BlackEnergy malware include support for proxy servers and use of techniques to bypass User Account Control and driver signing features in 64-bit Windows systems,” according to the F-Secure whitepaper. “While monitoring BlackEnergy samples, we also uncovered a new variant used by this group. We named this new variant BlackEnergy 3.”

Only Quedagh is believed to be using BlackEnergy 3, and it is not available for sale on the open market, noted Sean Sullivan, security advisor at F-Secure.

“The name [of the group] is based on a ship taken by Captain Kidd, an infamous privateer,” he said. “It is our working theory that the group has previous crimeware experience. Its goals appear to be political but they operate like a crimeware gang. There have been several cases this year of which BlackEnergy is the latest. The trend is one of off-the-shelf malware being used in an APT [advanced persistent threat] kind of way. The tech isn’t currently worthy of being called APT, but its evolving and scaling in that direction.”

Within a month of Windows 8.1’s release, the group added support for 64-bit systems. They also used a technique to bypass the driver-signing requirement on 64-bit Windows systems.

In the case of BlackEnergy 3, the malware will only attempt to infect a system if the current user is a member of the local administration group. If not, it will re-launch itself as Administrator on Vista. This will trigger a User Account Control (UAC) prompt. However, on Windows 7 and later, the malware will look to bypass the default UAC settings.  

“The use of BlackEnergy for a politically-oriented attack is an intriguing convergence of criminal activity and espionage,” F-Secure notes in the paper. “As the kit is being used by multiple groups, it provides a greater measure of plausible deniability than is afforded by a custom-made piece of code.”

In 2014 from the Department of Interior and DHS:

Summary: Investigation of NPS-GCNP SCADA SYSTEM

Report Date: August 7, 2014

OIG investigated allegations that the Supervisory Control and Data Acquisition (SCADA) system at Grand Canyon National Park (Park) may be obsolete and prone to failure. In addition, it was alleged only one Park employee controlled the system, increasing the potential for the system to fail or become unusable.

The SCADA system is a private utilities network that monitors and controls critical infrastructure elements at the Park. Failure of the system could pose a health and safety risk to millions of Park visitors. Due to potential risks that system failure posed, we consulted with the U.S. Department of Homeland Security Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) and asked that they assess the overall architecture and cybersecurity of the Park’s SCADA system.

ICS-CERT conducted an onsite review and issued a report outlining the weaknesses it found at the Park’s SCADA system, including obsolete hardware and software, inadequate system documentation and policies, insufficient logging and data retention. We provided a copy of ICS-CERT’s assessment report to the National Park Service for review and action.

 

 

Chilling Details of the Sony Hack, Reported

These Are the Cyberweapons Used to Hack Sony

MotherBoard: In late November 2014, a mysterious group of hackers calling itself “God’sApstls” sent an ominous and jumbled email to a few high-level Sony Pictures executives.

“The compensation for it, monetary compensation we want,” the hackers wrote. “Pay the damage, or Sony Pictures will be bombarded as a whole.”

The executives at the Hollywood studio, which was about to release the controversial James Franco and Seth Rogen’s comedy The Interview, ignored the email. Just three days later, the hackers’ followed through with their threat and breached the studio’s systems, displaying a message on the computer screen of every employee: “Hacked by #GOP [Guardians of Peace].”

The hackers not only defaced employee’s computers, they then wiped their hard disks, crippling Sony Pictures for weeks, and costing the company $35 million in IT damages, according to its own estimate.

Now, more than a year later, several security researchers are still hunting down the hackers behind the attack, which the FBI officially identified as North Korean government-employed hackers. And despite the fact that the group is apparently still alive and well, a coalition of security researchers believes they can now disrupt them by exposing their extensive malware arsenal.

On Wednesday, a group of companies led by Novetta released a report detailing the Sony hackers’ long history of operations, as well as its large stock of malware. It’s perhaps the most detailed and extensive look at the group behind what might be the most infamous cyberattack ever.

Andre Ludwig, the senior technical director at Novetta Research and Interdiction Group, said that the investigation started from four hashes (values that uniquely identify a file) that the Department of Homeland security published after the attack. With those few identifying strings, and after months of sleuthing, the researchers found 2,000 malware samples, both from online malware portal VirusTotal, as well as from antivirus companies. Of those, they manually reviewed and catalogued 1,000, and were able to identify 45 unique malware strains, revealing that the Sony hackers had an arsenal more sophisticated and varied than previously thought.

The researchers hope that by shedding light on the hackers’ toolkit, the group, which the researchers called “Lazarus Group,” will be forced to adapt, spending resources and time, and perhaps even lose capabilities after antivirus companies and potential targets put up new defenses.

“There is no more shadows to hide in for these tools.”

“If all of a sudden you have antivirus signatures that detect and delete all the group’s arsenal, boom!” Jaime Blasco, the chief scientist at AlienVault Labs and one of the researchers who investigated the Sony hackers, told Motherboard. “They lose access to all the victims’ they got before.”

As Ludwig put it, “there is no more shadows to hide in for these tools.”

As it turns out, the hackers’ arsenal contains not only malware capable of wiping and destroying files on a hard disk like the Sony hack, but also Distributed Denial of Service (DDoS) tools, tools that allow for remotely eavesdropping on a victim’s computer, and more, according to the report. The researchers tracked some of this tools in cyberattacks and espionage operations that go as far as back as 2009, perhaps even 2007, showing the hackers that hit Sony have a long history.

While others suspected this before, Blasco said that nobody demonstrated it as conclusively until now.

Novetta researchers and their partners, which include AlienVault and Kaspersky Lab, don’t get into saying who the hackers really are, but they also don’t question the FBI’s controversial claim that North Korea was behind the attack.

The main reason, LaMontagne explained, is that the new data they found discredits the alternative theories that the hackers were actually a disgruntled former employee or just an independent hacktivist group.

A former Sony system administrator is unlikely to have built more than 45 malware tools in the span of more than seven years, LaMontagne told me. And the same time, he added, it’s also unlikely that a previously unheard of hacktivist group would pop up, claim responsibility for such a high-profile attack, and then disappear.

“They’re extremely motivated, regimented, organized, and they can definitely execute.”

“We have no reason to dispute what the US government and other governments have asserted as the threat being North Korean,” Peter LaMontagne, the CEO of Novetta, told me.

And as it turns out, those hackers have been around for longer than anyone thought—wielding sophisticated weapons. This, according to the researchers, shows the group was much more seasoned than anyone believed.

“Their motivation and operational execution, it’s impressive,” Ludwig said. “They’re extremely motivated, regimented, organized, and they can definitely execute.”

Now that their methods and tools are exposed, however, the researchers hope that they won’t be as effective.

The head-scratcher is sanctions are only for the missile test?

US to present UN sanctions resolution on North Korea

United Nations (United States) (AFP) – The United States will on Thursday present a draft UN resolution toughening sanctions on North Korea after reaching agreement with China on a joint response to Pyongyang’s fourth nuclear test and a rocket launch.

The UN Security Council will meet at 2:00 pm (1900 GMT) to discuss the draft text detailing a new package of measures to punish North Korea, but there will be no immediate vote.

US Ambassador Samantha Power “intends to submit for consideration by the Security Council a draft sanctions resolution in response to the DPRK’s recent nuclear test and subsequent proscribed ballistic missile launch,” US spokesman Kurtis Cooper said, using the abbreviation for North Korea’s formal name.

“We look forward to working with the Council on a strong and comprehensive response to the DPRK’s latest series of tests aimed at advancing their nuclear weapons program.”

UN diplomats said a vote was expected as early as Friday.