Jia Tan is the persona associated with the XZ Utils software supply chain compromise that introduced the liblzma backdoor tracked as CVE-2024-3094. The actor operated under the GitHub handle JiaT75 and presented as "Jia Tan." According to the content, the account was created in October 2021 and spent more than 30 months building trust through legitimate contributions before obtaining commit access to the XZ Utils project in January 2023. The operation is described as a long-term maintainer infiltration and social-engineering campaign. Additional personas, including Jigar Kumar and Hans Jansen, are reported to have pressured maintainer Lasse Collin to merge Jia Tan’s patches faster and shift maintenance control. The malicious payload was introduced in February 2024 via binary test files bad-3-corrupt_lzma2.xz and good-large_compressed.lzma, and the build process used tr to de-obfuscate code that injected a precompiled object into liblzma at build time. The resulting implant hooked RSA_public_decrypt resolution in SSHD and weakened public-key authentication on affected Linux environments. The backdoor was highly environment-dependent and stealthy. It activated only under specific conditions including x86_64 architecture, systemd presence, libsystemd in process memory, and packaging-targeted build contexts rather than ordinary upstream Git builds. The content also notes the backdoor was fragile, with behavior varying across rebuilds and build concurrency, and that it was updated in early March 2024, likely to improve robustness. The compromise was discovered by Andres Freund on March 28, 2024 after he observed anomalous CPU usage and SSH authentication latency on Debian sid. The malicious releases were XZ Utils 5.6.0 and 5.6.1, and the issue was detected before reaching stable Debian and Fedora distributions. The content characterizes the operation as unusually sophisticated and notes that some reporting and commentary described Jia Tan as a suspected nation-state actor; however, the provided material does not attribute the activity to a specific country with high confidence. Known aliases and identifiers directly mentioned in the content: Jia Tan, JiaT75. Related personas mentioned in the operation: Jigar Kumar, Hans Jansen.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a long-term supply chain compromise of XZ Utils by building trust as a legitimate contributor, using coordinated social pressure via additional personas, and ultimately inserting a backdoor into release artifacts that affected SSH authentication on targeted Linux environments.
Suspected of being a nation-state hacker who inserted a backdoor into the open-source XZ Utils software, potentially enabling unauthorized access to systems using the utility.
Suspected malicious contributor who spent ~2 years gaining trust in the XZ/LZMA project, then introduced an obfuscated supply-chain backdoor into liblzma (XZ Utils) that could be indirectly loaded by distro-patched OpenSSH/sshd builds (e.g., systemd integration), enabling covert access under specific build/runtime conditions and with anti-analysis/trigger logic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.