Browse by domain

PRC cyber activity by domain

Each domain holds a dated chronology of named, unclassified reporting. Every entry links back to the originating advisory or research publication.

Critical Infrastructure Pre-Positioning

4

Access to water, energy, transport and communications networks held for disruption in a crisis rather than for collection.

Open chronology

Telecommunications Collection

3

Intrusions into carriers, ISPs and lawful-intercept systems supporting a global espionage collection system.

Open chronology

Edge Devices and Covert Networks

4

Compromised routers, SOHO gear and IoT stitched into botnets that obscure attribution and stage onward operations.

Open chronology

Government and Diplomatic Espionage

6

Collection against government agencies, defense organizations, law enforcement and research institutions.

Open chronology

Managed Providers and Supply Chain

2

Exploitation of trust relationships between service providers and their customers to reach many victims at once.

Open chronology

Exploited Vulnerabilities

3

Publicly known CVEs and living-off-the-land tradecraft that PRC actors rely on for initial access and persistence.

Open chronology

Sourced events

Search and filter every dated entry by domain, country and date range.

to
22 of 22 entries
  1. Jul 9, 2026
    highoperationalGovernment and Diplomatic Espionage

    Suspected China-nexus implants in Pakistani law enforcement web applications

    SentinelLABS tracked sustained espionage against Pakistani law enforcement from February 2024 to April 2026. A suspected China-nexus actor planted implants in a Balochistan Police web application handling criminal and biometric records, reaching both police staff and citizens.

    Suspected China-nexus actor
    SentinelLABS
  2. Apr 23, 2026
    criticalstrategicEdge Devices and Covert Networks

    Joint advisory on China-nexus covert networks of compromised devices

    CISA and partners published tactics, techniques and indicators for covert networks built from compromised SOHO routers, IoT and smart devices. The advisory describes large-scale botnet infrastructure used to obscure attribution and enable reconnaissance and intrusion.

    Volt TyphoonFlax Typhoon
    CISA AA26-113A
  3. Aug 27, 2025
    criticalstrategicTelecommunications Collection

    Countering PRC state-sponsored compromise of networks worldwide

    NSA, CISA, FBI and partners detailed a deliberate and sustained campaign by PRC state-sponsored actors compromising networks worldwide to feed a global espionage system.

    PRC state-sponsored APT actors
    CISA AA25-239A
  4. Dec 18, 2024
    highoperationalTelecommunications Collection

    Mobile communications guidance issued after telecom espionage

    CISA released mobile communications best practice guidance in direct response to identified PRC-affiliated espionage against commercial telecommunications infrastructure.

    PRC government-affiliated actors
    CISA guidance
  5. Dec 4, 2024
    criticaloperationalTelecommunications Collection

    Hardening guidance after PRC compromise of major carriers

    CISA and partners warned that PRC-affiliated actors compromised networks of major global telecommunications providers in a broad cyber espionage campaign, and published visibility and hardening guidance for communications infrastructure.

    PRC-affiliated threat actors
    CISA guidance
  6. Jul 8, 2024
    highoperationalGovernment and Diplomatic Espionage

    APT40 tradecraft in action

    CISA and partners outlined the current threat APT40, tied to the PRC Ministry of State Security, poses to Australian networks, drawing on ASD ACSC incident response investigations.

  7. Mar 19, 2024
    highstrategicCritical Infrastructure Pre-Positioning

    Fact sheet: actions for critical infrastructure leaders

    CISA warned critical infrastructure leaders of urgent risk from Volt Typhoon and set out specific actions to prioritize protection of their organizations.

    Volt Typhoon
    CISA fact sheet
  8. Feb 7, 2024
    criticalstrategicCritical Infrastructure Pre-Positioning

    PRC actors maintain persistent access to US critical infrastructure

    CISA, NSA and FBI assessed that PRC state-sponsored actors are pre-positioning on IT networks for disruptive or destructive attacks against US critical infrastructure in the event of a major crisis or conflict with the United States.

    Volt Typhoon
    CISA AA24-038A
    mediumtacticalExploited Vulnerabilities

    Joint guide on identifying and mitigating living off the land techniques

    Detection information and mitigations for living off the land activity, which remains effective because many organizations lack the logging and baselining needed to spot abuse of built-in tools.

    Volt TyphoonMultiple actors
    CISA joint guide
  9. Jan 31, 2024
    mediumstrategicEdge Devices and Covert Networks

    Secure by design alert for SOHO device manufacturers

    CISA and the FBI urged SOHO router manufacturers to build security into design and maintenance, citing ongoing targeting of small office and home office routers by Volt Typhoon.

  10. Sep 27, 2023
    highoperationalEdge Devices and Covert Networks

    BlackTech actors hide in router firmware

    NSA, FBI, CISA and Japanese partners detailed BlackTech tradecraft against branch routers, and urged multinationals to review subsidiary connections and consider zero trust to limit lateral movement.

  11. May 24, 2023
    criticaloperationalCritical Infrastructure Pre-Positioning

    PRC actor living off the land to evade detection

    The first joint advisory on Volt Typhoon described abuse of tools already present in victim environments to maintain anonymity inside critical infrastructure IT networks.

    Volt Typhoon
    CISA AA23-144A
  12. Oct 6, 2022
    hightacticalExploited Vulnerabilities

    Top CVEs actively exploited by PRC state-sponsored actors

    CISA, NSA and FBI published the top Common Vulnerabilities and Exposures used by PRC state-sponsored actors since 2020, most of them in internet-facing network devices and services.

    PRC state-sponsored actors
    CISA AA22-279A
  13. Jun 7, 2022
    highoperationalEdge Devices and Covert Networks

    PRC actors exploit network providers and devices

    CISA, NSA and FBI described continued exploitation of publicly known vulnerabilities in telecom and network service provider equipment to build a broad network of compromised infrastructure.

    PRC state-sponsored actors
    CISA AA22-158A
  14. Aug 20, 2021
    mediumtacticalGovernment and Diplomatic Espionage

    Chinese state-sponsored observed TTPs

    A baseline reference on Chinese cyber threat behavior and trends with mitigations for federal, state and local government, critical infrastructure and the defense industrial base.

    Chinese state-sponsored actors
    CISA AA21-200B
  15. Jul 20, 2021
    highoperationalGovernment and Diplomatic Espionage

    TTPs of indicted APT40 actors tied to the MSS Hainan State Security Department

    CISA and the FBI published detection and remediation guidance for APT40 intrusions alongside the Justice Department indictment of four Chinese nationals working for the Ministry of State Security.

  16. Mar 3, 2021
    criticaltacticalExploited Vulnerabilities

    Active exploitation of Microsoft Exchange Server vulnerabilities

    CISA partners observed active exploitation of Exchange Server vulnerabilities, with tactics, techniques and indicators of compromise published for defenders.

  17. Oct 1, 2020
    highstrategicCritical Infrastructure Pre-Positioning

    Potential for Chinese cyber response to heightened US-China tensions

    CISA linked the likelihood of Chinese cyber activity to the state of the bilateral relationship and published associated TTPs and mitigations for critical infrastructure owners.

    Chinese government-affiliated actors
    CISA AA20-275A
  18. Sep 14, 2020
    highoperationalGovernment and Diplomatic Espionage

    MSS-affiliated cyber threat actor activity against US government agencies

    CISA observed MSS-affiliated actors relying on publicly available information sources and common open-source tooling to target US government agencies.

    MSS-affiliated actors
    CISA AA20-258A
  19. Aug 3, 2020
    mediumtacticalGovernment and Diplomatic Espionage

    Malware analysis report on the TAIDOOR remote access trojan

    CISA, FBI and DoD described Chinese government use of TAIDOOR variants with proxy servers to maintain presence on victim networks and enable further exploitation.

    Chinese government actors
    CISA MAR-10292089
  20. Oct 3, 2018
    criticalstrategicManaged Providers and Supply Chain

    Cloud Hopper: APT activity exploiting managed service providers

    CISA alerts covering the Cloud Hopper campaign, in which actors infiltrated global managed service providers from May 2016 for espionage and intellectual property theft across IT, energy, healthcare, communications and critical manufacturing.

  21. Apr 27, 2017
    highoperationalManaged Providers and Supply Chain

    Intrusions affecting multiple victims across multiple sectors

    Chinese government actors exploited trust relationships between IT service providers and their customers, stealing intellectual property and sensitive data from companies in at least twelve countries.

    MSS-associated actors
    CISA TA17-117A