CHINA WATCH
Cyber Activity

PRC-attributed cyber actors

Curated reference on Chinese state-sponsored APT groups, their tactics, techniques and procedures (mapped to MITRE ATT&CK), and a timeline of recent public incidents. Sourced from CISA, Mandiant, Microsoft, Citizen Lab, and DOJ filings.

Volt Typhoon

PRC state-sponsored (MSS-aligned) · since Mid-2021

TTPs & targets

Pre-positioning operations against US critical infrastructure (water, energy, transport, communications) with the apparent goal of disruption during a Taiwan contingency.

Vanguard PandaBRONZE SILHOUETTEInsidious Taurus
Primary targets
  • US critical infrastructure
  • Guam telecom
  • Water utilities
  • Energy sector
Primary TTPs
  • Initial Access: exploitation of edge devices (Fortinet, Cisco, Netgear)
  • Persistence: web shells on perimeter routers/SOHO botnets
  • Defense Evasion: living-off-the-land (LOLBins, no malware)
  • Credential Access: LSASS dumping, ntds.dit theft
  • Discovery: WMI / PowerShell network enumeration

Salt Typhoon

PRC state-sponsored (MSS contractor) · since 2020

TTPs & targets

Long-running telecom intrusion campaign. In 2024 breached multiple US carriers and accessed CALEA lawful-intercept systems, exposing communications of senior US officials.

FamousSparrowGhostEmperorEarth Estries
Primary targets
  • US telecom carriers
  • ISPs
  • Government communications
  • Political campaigns
Primary TTPs
  • Initial Access: Microsoft Exchange / edge router exploits
  • Persistence: GhostSpider kernel rootkit
  • Collection: SIGINT-style metadata exfiltration
  • Command & Control: Demodex rootkit, custom HTTPS tunnels

Flax Typhoon

Integrity Technology Group (Beijing) — MSS contractor · since Mid-2021

TTPs & targets

Built and operated the Raptor Train IoT botnet (260k+ devices) used for intermediate routing and operational obfuscation. Targets Taiwan especially.

Ethereal Panda
Primary targets
  • Taiwan government
  • Education
  • Manufacturing
  • IoT/SOHO routers globally
Primary TTPs
  • Initial Access: public-facing app exploitation (VPNs, IIS)
  • Persistence: legitimate RMM tools (Sysinternals, SoftEther VPN)
  • C2: Raptor Train botnet relay layer

APT41

MSS contractor (Chengdu 404) · since 2012

TTPs & targets

Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.

Double DragonWicked PandaBARIUMWinnti
Primary targets
  • Healthcare
  • Telecom
  • Game studios
  • Government
  • Higher education
Primary TTPs
  • Initial Access: supply-chain compromise (CCleaner, ASUS Live Update)
  • Persistence: Winnti malware family, ShadowPad
  • Lateral Movement: Cobalt Strike, custom loaders

APT40

MSS Hainan State Security Department · since 2009

TTPs & targets

Maritime, defense and naval research espionage in support of PRC modernization. 4 officers indicted by DOJ in 2021.

LeviathanKryptonite PandaTEMP.PeriscopeGADOLINIUM
Primary targets
  • Naval R&D
  • Maritime industry
  • Universities
  • Biomedical research
  • Defense contractors
Primary TTPs
  • Initial Access: spearphishing, edge-device exploits (SOHO routers as ORBs)
  • Discovery: rapid recon within hours of compromise
  • Exfiltration: web shells, custom backdoors (BADFLICK, MURKYTOP)

APT31

MSS — Wuhan State Security Bureau · since 2010

TTPs & targets

Intellectual property and political intelligence collection. Indicted by DOJ in 2024 for targeting US political dissidents, journalists, and members of IPAC.

ZirconiumJudgment PandaViolet Typhoon
Primary targets
  • Politicians
  • Journalists
  • Think tanks
  • Aerospace
  • Defense
Primary TTPs
  • Initial Access: spearphishing with tracking pixels for recon
  • Credential Access: home router compromise to harvest creds
  • Collection: targeted mailbox exfiltration

APT10

MSS Tianjin State Security Bureau · since 2009

TTPs & targets

Operation Cloud Hopper — global managed service provider (MSP) compromise enabling downstream access to thousands of client organizations.

Stone PandamenuPassPOTASSIUM
Primary targets
  • Managed Service Providers
  • Engineering
  • Aerospace
  • Healthcare
  • Government
Primary TTPs
  • Initial Access: MSP supply chain trust relationships
  • Persistence: ChChes, RedLeaves, PlugX backdoors
  • Lateral Movement: stolen credentials across customer tenants

Mustang Panda

PRC state-sponsored · since 2014

TTPs & targets

Targets NGOs, religious groups, ASEAN governments, and the Tibetan/Mongolian diaspora. Heavy use of PlugX delivered via USB and themed lures.

BRONZE PRESIDENTRedDeltaEarth PretaTA416
Primary targets
  • ASEAN governments
  • Vatican
  • Tibetan diaspora
  • European foreign ministries
Primary TTPs
  • Initial Access: spearphishing with topical political lures
  • Initial Access: USB-spreading PlugX variants
  • Defense Evasion: DLL side-loading via signed binaries

Naikon

PLA — Chengdu MR Second Technical Reconnaissance Bureau · since 2010

TTPs & targets

Focused on South China Sea regional intelligence — military, diplomatic and economic targets in ASEAN states.

Override PandaPLA Unit 78020
Primary targets
  • ASEAN militaries
  • Philippines
  • Vietnam
  • Indonesia
  • Malaysia
Primary TTPs
  • Initial Access: spearphishing with regional lures
  • Persistence: Aria-body backdoor
  • Exfiltration: long-dwell collection

Hafnium

PRC state-sponsored · since 2017

TTPs & targets

Author of the 2021 ProxyLogon Microsoft Exchange zero-day campaign that compromised 30,000+ servers worldwide.

Silk Typhoon
Primary targets
  • Defense contractors
  • Higher education
  • Law firms
  • Think tanks
  • Infectious disease researchers
Primary TTPs
  • Initial Access: Exchange Server zero-days (CVE-2021-26855 chain)
  • Persistence: web shells (China Chopper variants)
  • Collection: full mailbox exports

Brass Typhoon

PRC state-sponsored (umbrella designator) · since Pre-2019

TTPs & targets

Microsoft umbrella designation for clusters using ShadowPad, frequently overlapping with APT41 tradecraft against telecom and government.

BARIUM (legacy)ShadowPad cluster
Primary targets
  • Telecom
  • Government
  • IT service providers
Primary TTPs
  • Initial Access: public-facing exploits
  • Persistence: ShadowPad modular backdoor
  • Defense Evasion: legitimate signed binaries for DLL side-loading