Curated reference on Chinese state-sponsored APT groups, their tactics, techniques and procedures (mapped to MITRE ATT&CK), and a timeline of recent public incidents. Sourced from CISA, Mandiant, Microsoft, Citizen Lab, and DOJ filings.
Volt Typhoon
PRC state-sponsored (MSS-aligned) · since Mid-2021
Pre-positioning operations against US critical infrastructure (water, energy, transport, communications) with the apparent goal of disruption during a Taiwan contingency.
Vanguard PandaBRONZE SILHOUETTEInsidious Taurus
Primary targets
US critical infrastructure
Guam telecom
Water utilities
Energy sector
Primary TTPs
Initial Access: exploitation of edge devices (Fortinet, Cisco, Netgear)
Persistence: web shells on perimeter routers/SOHO botnets
Defense Evasion: living-off-the-land (LOLBins, no malware)
Long-running telecom intrusion campaign. In 2024 breached multiple US carriers and accessed CALEA lawful-intercept systems, exposing communications of senior US officials.
FamousSparrowGhostEmperorEarth Estries
Primary targets
US telecom carriers
ISPs
Government communications
Political campaigns
Primary TTPs
Initial Access: Microsoft Exchange / edge router exploits
Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.
Double DragonWicked PandaBARIUMWinnti
Primary targets
Healthcare
Telecom
Game studios
Government
Higher education
Primary TTPs
Initial Access: supply-chain compromise (CCleaner, ASUS Live Update)
Intellectual property and political intelligence collection. Indicted by DOJ in 2024 for targeting US political dissidents, journalists, and members of IPAC.
ZirconiumJudgment PandaViolet Typhoon
Primary targets
Politicians
Journalists
Think tanks
Aerospace
Defense
Primary TTPs
Initial Access: spearphishing with tracking pixels for recon
Credential Access: home router compromise to harvest creds