No public evidence in CrowdStrike’s account confirms that military strategy documents were stolen. CrowdStrike said an attacker tried to access a think-tank server associated with an ongoing military research project. Its December 20, 2017 report described attacks observed in late October and early November that year, but did not name the think tank or establish that the attempted access succeeded.
What CrowdStrike said happened
CrowdStrike Falcon Intelligence reported that actors it described as PRC-based targeted at least four Western think tanks and two nongovernmental organizations (NGOs) in late October and early November 2017. The firm characterized the activity as espionage-driven and more selective than earlier, broader “smash-and-grab” operations.
The people targeted included staff researching Chinese economic policy and the Chinese economy, as well as people with expertise in defense, international finance, U.S.–China relations, cyber governance, and democratic elections. CrowdStrike’s report stated: “The targeting of these six organizations may signal a more widespread and active campaign to collect sensitive material and enable future operations.” That was the company’s assessment of a possible broader campaign, not proof of its scale.
What the military-research-project case establishes
In a separate case study, CrowdStrike described attempted access to a think-tank web server that appeared to be connected to an ongoing military research project. An account compromised through spear-phishing was used in an attempt to access the server with China Chopper, a webshell. CrowdStrike said its Falcon endpoint protection blocked the webshell from running commands.
#1 Best Overall
The actor returned over several days, tried another webshell, and later attempted SQL injection. After the intrusion attempts failed, the think tank’s website experienced a low-volume distributed denial-of-service (DDoS) attack. CrowdStrike noted the persistence but said the DDoS attack’s purpose was unclear.
The public case study does not identify the think tank or say that military strategy documents were obtained. An attempted compromise of a server associated with a research project is not evidence that project files—or any documents—were stolen.
How the reported attacks worked
CrowdStrike said most of the intrusions used China Chopper and/or tools for harvesting credentials from Microsoft Active Directory infrastructure. It named Mimikatz as one such tool; credentials could support movement from an initial foothold to other systems on a network.
In at least two cases, the firm observed email-directory dumps. Such collections can reveal staff names and addresses, helping an attacker identify people to target or prepare convincing follow-on spear-phishing messages from trusted accounts. CrowdStrike also reported searches for terms including “china,” “cyber,” “japan,” “korea,” “chinese,” and “eager lion.”
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
Why think tanks can be targets
CrowdStrike’s earlier reporting argued that think tanks may be attractive because their staff can include former senior officials who retain government contacts, and private correspondence can expose policy options being considered. Access to a staff mailbox could also help an intruder send credible phishing messages to government contacts.
This explains a potential intelligence value of think-tank access; it does not establish the tasking or motive behind any specific intrusion. The observed subject matter and collection methods are consistent with targeted interest in policy expertise and communications, but do not prove what information the attackers ultimately acquired.
Rank #4
How the 2017 activity differed from earlier operations
CrowdStrike contrasted the reported campaign with earlier, broader collection it called “smash-and-grab” activity. In its account, the late-2017 targeting focused more on selected people and subjects. The firm also described access techniques that could support follow-on collection: compromised credentials, webshells, and email-directory gathering.
This is a comparison of activity CrowdStrike described, not evidence that all Chinese cyber operations changed in the same way. The reporting supports a shift in the cases discussed, not a universal trend.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
What organizations can take from the report
CrowdStrike recommended that organizations with think-tank or NGO ties review security, train users to recognize phishing, and maintain endpoint visibility. The reported case highlights several practical areas to include in that work:
- Review identity and directory security. Protect Active Directory credentials and investigate unusual credential-harvesting activity or unexpected use of administrative accounts.
- Monitor web-facing systems. Look for unauthorized webshells, attempts to execute commands through a web server, and suspicious SQL injection activity.
- Prepare staff for targeted phishing. A message tailored to a person’s research area or sent from a trusted contact can be more convincing than generic spam; provide a clear way to report suspicious messages.
- Watch for mailbox and directory misuse. Unexpected exports of address books or other email-directory data can indicate reconnaissance for later phishing.
- Keep endpoint detection and response coverage current. CrowdStrike said endpoint protection blocked webshell commands in its case study, but that reported outcome does not guarantee that any product will stop a future attack.
What remains unconfirmed
The public sources for this account are CrowdStrike’s own reporting. They support what the company said it observed, but do not independently verify attribution, name the affected organizations, or confirm a successful theft of military strategy documents. The defensible conclusion is narrower: CrowdStrike reported targeted espionage activity against at least four Western think tanks and two NGOs, including attempted access to a server associated with a military research project.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

