top of page
Search

CMC Joint Intelligence Bureau Operation in South Korea

This intelligence report outlines a highly coordinated, multi-year espionage operation conducted by Chinese military intelligence targeting sensitive South Korean and U.S. military secrets. It details the recruitment tactics, logistical timeline, and specialized tradecraft used by a Chinese academic-turned-operative to infiltrate South Korean defense circles before his ultimate detection, arrest, and prosecution.


Bottom Line Up Front (BLUF)

The Supreme Court of South Korea has upheld a five-year prison sentence and financial confiscation for Qing (FNU), a Chinese national and university professor, for violating the Military Secrets Protection Act 1-3. Operating under the direction of "Ken Jake" an operational effort of the Central Military Commission’s Joint Intelligence Bureau, Qing and his handlers systematically targeted active-duty South Korean soldiers to obtain critical military secrets, including details regarding THAAD (Terminal High Altitude Area Defense), ROK-U.S. joint military exercise plans, and the situation in Taiwan. The conspiracy utilized sophisticated digital cover identities, encrypted communications, and physical dead drops on Jeju Island before it was compromised by an undercover counterintelligence operation.

Identified Chinese Persons and Units Involved

●     The "Ken Jake" Unit takes its name from a pseudonym used on social media to target the South Korean military. The operation was conducted by a unit operating under China’s Central Military Commission, Joint Intelligence Bureau.

●     Qing is a native of Shandong Province, China, who studied in South Korea, earned a master's degree in film, a PhD in Taiwan, and subsequently worked as a Chinese university professor. He operated as a civilian traveler and operational courier, making short-term trips to South Korea to execute intelligence tasks while claiming his travel was an authorized "university business trip."

●     Liu Nannan*: The primary handler for the Ken Jake unit. Liu spotted and recruited Qing while in Taiwan (2018 - 2022). Qing was tasked with collecting on a female Taiwan politician.

●     Active-Duty Asset Infiltration: Liu and PLA officers successfully compromised conscript Choi Hong-jae (who passed joint UFS operational plans using secure iPhones and disguised wrist-camera gear in exchange for 17.1 million won) and Navy Corporal Jung Da-jung (who passed the real-time GPS coordinates of the warship Seoul-ham).


Chronological Operational Timeline

Phase I: Spotting, Recruitment, and Initial Target Approaches (Late 2022 – Late 2023)

●     Late 2022: Liu Nannan coordinated the digital targeting of South Korean military assets.  Ken Jake began targeting South Korean military personnel. Liu used multiple aliases inside popular social media chat rooms (such as KakaoTalk open chat rooms) to approach South Korean active-duty soldiers.

●     July 2023: Qing worked with the Joint Intelligence Bureau to contact active-duty South Korean army personnel and collect military secrets. Around this time, Liu Nannan initiated contact with an undercover investigator from South Korea’s Defense Counterintelligence Command (who was disguised as an active-duty soldier). Liu offered upfront cash payments of 3.5 million Korean won to build trust, followed by offers of over two million won for Level 3 secrets and 4 million won for Level 2 secrets.

Phase II: Jeju Island Safe House Operations (May 2024 – July 2024)

●     May 2024: Qing made his first entry into South Korea under direct orders to build face-to-face trust with the target. He met the undercover investigator at a Jeju Island pensione, offering to cover all travel costs on behalf of the "institute". To maintain strict operational security, Qing avoided meeting his wife, who was studying in South Korea at the time 6. When she expressed concern, he told her, "I’m going on a mission" and "Don’t worry, we’re being patriotic." Six days later, a separate Ken Jake courier successfully retrieved a hidden USB drive containing military documents from the pensione and left $5,000 USD in exchange.

●     July 2024: Qing reentered South Korea to expand operations. He set up a safe house on Jeju Island, stocking a physical steel safe with $5,000 USD and a pre-configured secure mobile phone for covert communications.

Phase III: Physical Reconnaissance, Arrest, and Trial (March 2025 – July 2026)

●     March 2025: Qing executed his third entry into South Korea. He conducted physical reconnaissance on Jeju Island, inspecting public facilities to find optimal dead-drop locations. During a meeting at a Jeju building to exchange a Galaxy tablet PC for a USB drive containing military secrets, Qing was arrested on the spot by South Korean authorities.

●     April 2025: The Seoul Central District Prosecutors' Office formally indicted Qing.

●     Second Trial & Appeal (Post-Arrest): In court, Qing attempted to claim he was a civilian on an authorized "university business trip" and submitted forged cooperation letters from the Chinese Armed Police Force to argue he believed he was actually investigating a Chinese voice phishing ring. The courts dismissed this cover story as implausible, noting a state-affiliated intelligence group could easily forge such documentation.


Espionage Tradecraft Analysis

The Ken Jake intelligence apparatus utilized highly diverse and robust OPSEC and HUMINT methodologies to execute and protect this operation:

●     Digital Cover Identities & "Sockpuppets": PLA Intelligence Officers used multiple aliases to enter military-themed social media groups and open chat rooms. To disguise his state affiliations, Liu Nannan introduced himself on KakaoTalk as a "military researcher" or a "researcher at the Singapore International Research Institute".

●     Technical Exploitation Devices: The conspiracy utilized physical technical gear to capture classified documents. This included sending hidden-camera wristwatches to assets to secretly record physical military documents and also provided secure, pre-configured mobile phones dedicated entirely to encrypted communications.

●     Physical Dead Drops & Location Scouting: To avoid surveillance and face-to-face handoffs, handlers instructed targets to transmit data remotely. When physical exchanges were required, the network used dead drops. Qing personally conducted reconnaissance on Jeju Island, going so far as to check the physical sizing and toilet stall counts in public facilities to identify highly discreet, low-surveillance handover points.

●     Anti-Scrutiny Financial Handoffs: To bypass international banking regulations and anti-money laundering detection, Qing proposed a localized cash-out system. The handlers would send preloaded financial cards directly from China, transmit the PIN securely, and instruct the local asset to withdraw the operational funds anonymously via local South Korean ATMs.

●     Strict Operational Discipline: Despite operating in the same country where his wife was residing, Qing strictly avoided contacting or meeting her to minimize any chance of compromising his cover.

●     Digital Server Indicators: The custom drop-box server that the team's leader, Liu Nannan, set up for the undercover investigator to upload classified documents featured an interface coded entirely in Simplified Chinese characters (간체자), pointing directly back to mainland China.

●     Forensic Recovery of Disguised USBs: South Korean authorities seized a "charger-type" disguised USB used by the network. Forensics successfully recovered deleted directories that contained a photo showing Chinese military intelligence officers in a briefing/meeting room.


Status: Convicted

Ken Jake Network Operation
Ken Jake Network Operation

 
 
 

Comments


bottom of page