All domains

Government and Diplomatic Espionage

Collection against government agencies, defense organizations, law enforcement and research institutions.

6 dated entries · all sources public and unclassified
to
6 of 6 entries
  1. Jul 9, 2026
    highoperational

    Suspected China-nexus implants in Pakistani law enforcement web applications

    SentinelLABS tracked sustained espionage against Pakistani law enforcement from February 2024 to April 2026. A suspected China-nexus actor planted implants in a Balochistan Police web application handling criminal and biometric records, reaching both police staff and citizens.

    Suspected China-nexus actor
    SentinelLABS
  2. Jul 8, 2024
    highoperational

    APT40 tradecraft in action

    CISA and partners outlined the current threat APT40, tied to the PRC Ministry of State Security, poses to Australian networks, drawing on ASD ACSC incident response investigations.

  3. Aug 20, 2021
    mediumtactical

    Chinese state-sponsored observed TTPs

    A baseline reference on Chinese cyber threat behavior and trends with mitigations for federal, state and local government, critical infrastructure and the defense industrial base.

    Chinese state-sponsored actors
    CISA AA21-200B
  4. Jul 20, 2021
    highoperational

    TTPs of indicted APT40 actors tied to the MSS Hainan State Security Department

    CISA and the FBI published detection and remediation guidance for APT40 intrusions alongside the Justice Department indictment of four Chinese nationals working for the Ministry of State Security.

  5. Sep 14, 2020
    highoperational

    MSS-affiliated cyber threat actor activity against US government agencies

    CISA observed MSS-affiliated actors relying on publicly available information sources and common open-source tooling to target US government agencies.

    MSS-affiliated actors
    CISA AA20-258A
  6. Aug 3, 2020
    mediumtactical

    Malware analysis report on the TAIDOOR remote access trojan

    CISA, FBI and DoD described Chinese government use of TAIDOOR variants with proxy servers to maintain presence on victim networks and enable further exploitation.

    Chinese government actors
    CISA MAR-10292089