The beauty of this article is they assume its Chinese probably because of an IP address associated with the Chinese.<p>However, did Mandiant [1] think to time the round trip of the packets, in other words, assuming TCP and not UDP used, did the round trip of the return packet take about the right amount of time crossing the globe, or was some switch infrastructure "hacked" or modded nearby perhaps in the same country, which made it look like the packets were going to a Chinese ip address with appropriate time lags?<p>I bet they didnt!<p>[1] <a href="https://www.mandiant.com/" rel="nofollow">https://www.mandiant.com/</a>