Executive Summary
Over the past decade, China’s cyber espionage and offensive operations have undergone a sweeping transformation. What began in the early 2000s as a loosely connected network of military reconnaissance units and patriotic hackers has grown into a highly organized, commercialized state enterprise. Operating under Beijing’s Military-Civil Fusion (MCF) strategy, this complex ecosystem seamlessly connects private contractors, academic institutions, and commercial cybersecurity firms directly to the strategic priorities of the Ministry of State Security (MSS), the Ministry of Public Security (MPS), and the restructured People’s Liberation Army (PLA)1.
Unprecedented public leaks from private intelligence contractors—most notably I-SOON and KnownSec—alongside sweeping military restructuring in 2024, offer a clear view into how this system functions5. The division of labor is straightforward: the central government sets broad intelligence goals and stockpiles zero-day vulnerabilities using strict regulations like the 2021 Vulnerability Management Regulations (RMSV). Meanwhile, a competitive marketplace of private contractors handles the heavy lifting—executing global espionage campaigns, stealing intellectual property, and tracking dissidents abroad5.
At the same time, Beijing’s operational focus has fundamentally shifted. While economic cyber theft remains a core pillar of its national strategy, Chinese state actors are increasingly prioritizing the pre-positioning of malware inside foreign critical infrastructure10. Advanced hacking clusters—such as Volt Typhoon, Salt Typhoon, and Flax Typhoon—are establishing persistent access inside essential civilian networks, including power grids, water systems, and telecommunications10. In a major geopolitical crisis, particularly around Taiwan, these access points could be triggered to disrupt military deployments, paralyze public utilities, and deter international intervention10. This report examines the structure, tactical evolution, and long-term implications of China’s expanding cyber ecosystem.
Part I: The Doctrinal Imperative: Information Dominance and Military-Civil Fusion
To understand China’s cyber capabilities, one must first look at the strategic principles driving them. Beijing’s focus on digital operations began in the late 20th century after observing how crucial information dominance was to U.S. military success3. Today, this philosophy is operationalized through Military-Civil Fusion (MCF)—a core national initiative elevated by President Xi Jinping to erase the boundaries between civilian technological innovation and military defense modernization4.
The Mechanics of Military-Civil Fusion (MCF)
Unlike Western defense models that rely on voluntary partnerships with private industry, MCF legally obligates Chinese technology companies to support state defense and intelligence efforts15. The policy mandates the joint development of dual-use technologies, ensuring that commercial breakthroughs in artificial intelligence, microchips, quantum computing, and telecommunications immediately enhance military capabilities4.
A key element of MCF is acquiring foreign technology—often through intellectual property theft and network intrusions—and rapidly absorbing it into domestic defense programs17. Oversight is managed through joint military-civilian bodies, including the Central Military Commission’s Equipment Development Department (EDD) and the State Administration for Science, Technology, and Industry for National Defence (SASTIND). This structure allows Beijing to exploit open academic research and international business partnerships, turning global technological advancements directly toward military modernization4.
This framework is backed by national legislation, including the National Intelligence Law and the 2021 Data Security Law (DSL)8. These laws mandate that all citizens and companies assist in state intelligence work upon request, effectively giving the government unrestricted access to corporate data when national security is invoked8.
From “Informatized” to “Intelligentized” Warfare
MCF serves as the foundation for what Chinese military strategists call “intelligentized” warfare. Evolving from earlier concepts of “informatized” warfare—which focused on networked data sharing—intelligentized warfare incorporates AI, machine learning, and quantum technology to accelerate decision-making, automate target selection, and disrupt an enemy’s digital networks during conflict7.
This approach is closely tied to the doctrine of “system destruction warfare,” which asserts that victory depends on crippling an opponent’s operational systems while protecting one’s own1. Consequently, cyber operations are no longer viewed merely as intelligence-gathering tools. Instead, they are treated as primary assets intended to neutralize enemy communications, logistics, and command networks before kinetic force is ever used3.
Part II: The Evolution of State Organs: PLA Restructuring and the Quest for Joint Operations
To support these strategic goals, Beijing has repeatedly reshaped its military and intelligence organizations. Historically, military units, such as the regional Technical Reconnaissance Bureaus (TRBs) highlighted in Mandiant’s 2013 exposure of APT1, directly spearheaded cyber operations. However, that legacy structure suffered from rigid silos, bureaucratic friction, and poor cross-unit coordination7.
The Rise and Fall of the Strategic Support Force (2015–2024)
To solve these coordination issues, President Xi established the Strategic Support Force (SSF) in 2015. The SSF was designed to unite China’s space, cyber, and electronic warfare capabilities under a single command structure, fostering better joint operational support2. Hacking groups were consolidated under its Network Systems Department to create a unified information warfare arm1.
Despite significant funding, the SSF struggled with administrative inefficiency, internal rivalries, and corruption. In practice, legacy units often continued operating in isolation rather than truly integrating across domains1. High-profile corruption investigations within SSF leadership between 2023 and 2024 further accelerated the decision to disband it7.
The 2024 Reforms: Specialization and Direct Command
In April 2024, Xi Jinping officially dissolved the SSF and reorganized its components into distinct, independent services reporting directly to the Central Military Commission (CMC)1. This restructuring established two main bodies responsible for digital and network operations:
This restructuring signifies a critical evolution in the PLA’s approach to cyber warfare, yielding two primary organs relevant to the cyber domain:
- The Cyberspace Force (CSF): Formed from the SSF’s former Network Systems Department, the CSF handles offensive and defensive cyber operations, electronic warfare, and digital intelligence collection6. With direct CMC oversight, the CSF aims to respond faster and integrate AI tools more fluidly into operational planning6.
- The Information Support Force (ISF): Tasked with building and protecting the military’s underlying communications architecture, the ISF ensures secure data sharing across all military branches during joint operations6. During its official launch, Xi highlighted the force as a central component of China’s modern military strategy20.
| Historical Era | Organizational Structure | Primary Characteristics | Strategic Deficiencies / Rationale for Change |
| Pre-2015 | PLA Technical Reconnaissance Bureaus (TRBs) | Decentralized, regional commands conducting massive, noisy IP theft. | Highly siloed, lack of joint operational capability, easily attributable. |
| 2015–2024 | Strategic Support Force (SSF) | Centralized umbrella organization combining space, cyber, and electronic warfare. | Bureaucratic inertia, failure to integrate sub-departments, and widespread procurement corruption. |
| Post-2024 | Cyberspace Force (CSF) & Information Support Force (ISF) | Independent arms reporting directly to the Central Military Commission. | Streamlined command, hyper-specialization, and integration of AI for “intelligentized” warfare. |
By giving cyber operations their own direct command line, Beijing has stressed that digital space is a frontline operational domain requiring dedicated focus and resources20.
Part III: The Contractor Industrial Complex: Outsourcing Espionage
While uniformed services guide strategy, private contractors carry out much of the day-to-day execution. Following a 2015 agreement between President Obama and President Xi to curtail state-sponsored commercial cyber espionage, China adapted its approach27. To maintain deniability, expand operations, and access specialized technical talent, state security agencies increasingly relied on commercial vendors to carry out foreign intrusions and domestic monitoring27.
The inner workings of this private contractor market were laid bare by major document leaks from two key firms: I-SOON in early 2024 and KnownSec in late 20255.
The I-SOON Disclosures: Industrialized Espionage and Internal Strife
Founded in 2010 by former hacker Wu Haibo, I-SOON exemplifies China’s network of commercial cyber proxies27. The leaked documents showed that the firm regularly bid on contracts for the MSS, MPS, PLA, and regional police bureaus27. Operating with around 70 employees across several regional offices, I-SOON often targeted foreign networks proactively, gathering sensitive datasets to pitch and sell to government clients5.
The I-SOON leak demonstrated that the PRC utilizes contractors for a dual mission set:
- Global Espionage and Data Theft: I-SOON compromised government systems in at least 14 countries across Southeast Asia, the Middle East, and Africa29. Internal records showed fixed pricing for stolen data, such as charging $55,000 for data from Vietnam’s Ministry of Economy5. Other targets included health authorities in Taiwan during the COVID-19 pandemic30.
- Domestic Surveillance and Tracking Dissidents: The firm supported MPS efforts to monitor ethnic minorities, political dissidents, and overseas diaspora communities33. Tools were developed to deanonymize users on Western social platforms, access private messages, and push state propaganda30. Additionally, airline and telecommunications records from neighboring nations were compromised to trace exiled populations33.
I-SOON’s toolset included custom Remote Access Trojans (RATs), specialized iOS tools designed to record audio without jailbreaking, and Android malware tailored to intercept messages from apps like WeChat and Telegram25. They also designed physical access hardware, such as malicious power banks, to compromise secure networks from the inside25.
However, chat logs also revealed low employee morale, modest wages, internal disputes, and intense competition among vendors5. Staff complained about pay and workplace culture, highlighting that while outsourcing provides scale, it also creates significant operational security risks and insider vulnerabilities27.
The KnownSec Leak: Vertical Integration
The 2025 leak from KnownSec demonstrated an even higher level of technical sophistication. Unlike I-SOON, which relied heavily on basic phishing, KnownSec built a structured, specialized operations ecosystem to directly support national security requirements29.
KnownSec organized specialized teams, such as the “404 Security Lab” for vulnerability research and the “Product Technology R&D Center” for network mapping6. The firm mapped international networks and maintained broad target databases across Taiwan, Japan, South Korea, India, and Western nations. The leaked records show clear project structures, dedicated funding, and clear operational goals—confirming that commercial contractors are fully integrated into China’s state security operations.
Part IV: The Blurred Lines of State Proxies: APT41, Dual Motivations, and Ransomware
The relationship between state agencies and private contractors is fluid and often commercialized. Firms frequently compete for contracts and even sue each other over intellectual property disputes—such as Chengdu 404 suing I-SOON31. This dynamic is clearest in APT41 (also known as Double Dragon or Brass Typhoon), a prominent threat group linked to Chengdu 404 and supervised by the Sichuan Ministry of State Security33.
The Dual-Motivation Paradigm
APT41 is unique because it conducts two distinct types of operations. On behalf of the state, it executes high-level espionage campaigns targeting telecommunications, healthcare, and technology firms37. Notable supply chain attacks include “Operation ShadowHammer” in 2018, which compromised the ASUS live update system, and a 2022 compromise of Comm100 software29. The group also deployed tools like MESSAGETAP directly onto telecommunications servers to secretly intercept SMS traffic40.
At the same time, members of APT41 carry out financially motivated cybercrime, including ransomware attacks, cryptocurrency theft, and extortion targeting the gaming industry35. These illicit activities have generated millions of dollars in personal profit22.
This dual approach reveals a pragmatic compromise: state authorities tolerate side criminal activities so long as contractors meet intelligence goals and avoid hitting domestic targets39. This serves as an informal subsidy, helping contractors retain top technical talent without relying entirely on government funding22.
The Evolution of Proxy Tactics: Liminal Panda and Dark Pink
Contractor tactics continue to evolve to evade traditional security defenses. For example, the group tracked as “Liminal Panda” targets semiconductor and material research firms across East Asia using cloud-focused methods42. Instead of relying solely on custom malware, they steal authentication tokens and leverage legitimate IT administration tools (such as AnyDesk and TeamViewer) to blend in with normal network traffic.
Similarly, groups like “Dark Pink” deploy specialized toolsets—including TelePowerBot and KamiKakaBot—to infect USB drives and access secure messaging systems inside government and military organizations across Asia and Europe43. The widespread sharing of these tools across different contractor groups points to an active internal ecosystem for operational tools and exploits22.
Part V: The Vulnerability Weaponization Pipeline: Monopolizing Zero-Days
To support its growing network of contractors and maintain an edge in digital operations, Beijing requires a steady supply of software vulnerabilities. Recognizing zero-day exploits as vital national resources, the government established a strict legal structure to collect, control, and weaponize security research discovered within the country8.
The 2021 Vulnerability Disclosure Regulations (RMSV)
In September 2021, the Cyberspace Administration of China (CAC), the MPS, and the Ministry of Industry and Information Technology (MIIT) introduced the “Regulations on the Management of Network Product Security Vulnerabilities” (RMSV)44. This law reshaped how security flaws are reported and handled across China.
Under the RMSV, any researcher or company operating in China that discovers a security vulnerability must report it to the MIIT within 48 hours8. The law strictly forbids disclosing flaws to foreign entities, publishing proof-of-concept code, or sharing details publicly before an official patch is available—unless explicit state approval is granted46.
This reporting requirement gives the state early access to software vulnerabilities before vendor patches are developed8. This contrasts with Western frameworks like the U.S. Vulnerabilities Equities Process (VEP), which generally favors public disclosure to protect broader internet infrastructure9.
The MSS 13th Bureau and the Capture of Security Talent
Vulnerability data collected by the government is shared directly with state agencies, including the National Computer Network Emergency Response Technical Team (CNCERT/CC) and the MPS45. Units like the MSS 13th Bureau work with private cybersecurity companies and researchers to convert these raw discoveries into functional exploits45.
Additionally, Chinese security researchers are now restricted from competing in global hacking contests like Pwn2Own44. Instead, Beijing established domestic competitions such as the Tianfu Cup and Matrix Cup, which serve as recruiting grounds and harvesting platforms to channel top-tier exploits into state programs21.
This organized pipeline ensures a steady supply of zero-days for state operations. Earlier groups like APT3 demonstrated the value of this approach by deploying browser zero-days with precise targeting to maximize their lifespan33. Research suggests unpatched zero-days can remain viable for several years, providing long-term capabilities for state-sponsored operations9.
Part VI: Strategic Pre-positioning and Sabotage: The “Typhoon” Paradigm
While Chinese operations once focused primarily on economic espionage and IP theft, the strategic emphasis has shifted toward maintaining long-term access inside foreign critical infrastructure10.
This posture is driven by specialized “Typhoon” threat groups focused on stealth and persistence. Intelligence assessments indicate these groups are establishing operational access points that could be leveraged during a conflict to delay military response efforts, disrupt logistics, and complicate decision-making during a geopolitical crisis.
The Operational Typology of the Typhoon Clusters
- Volt Typhoon (Infrastructure Focus): Identified in 2023, Volt Typhoon targets key critical infrastructure sectors in the U.S. and allied nations, including water utilities, energy networks, communications, and ports46. The group’s primary objective is to maintain access rather than conduct routine intelligence collection10.
- Tradecraft: Volt Typhoon relies heavily on “Living off the Land” (LOTL) techniques. To blend in with normal network activity, the group exploits vulnerable edge devices like firewalls and router networks (such as the KV Botnet) to route traffic covertly12. Inside target networks, they use built-in system tools (such as cmd and certutil) and legitimate protocols to move laterally while avoiding security alerts12. They also target Active Directory databases to obtain credentials and secure access12.
- Salt Typhoon (Telecommunications Interception): Salt Typhoon focuses on penetrating core telecommunications networks52. By compromising major routing infrastructure, the group has intercepted sensitive communications and gained access to lawful interception systems, enabling high-value monitoring and intelligence collection10.
- Flax Typhoon (IoT Proxy Networks): Flax Typhoon concentrates on compromising Internet of Things (IoT) devices to build proxy infrastructure10. These networks hide the origin of state cyber operations and support ongoing espionage activities10.
Part VII: Transnational Repression and the Export of Digital Authoritarianism
In addition to military preparation and economic intelligence, China’s cyber apparatus is used to monitor and suppress domestic dissidents and overseas exile communities. The MPS contracts commercial firms to extend surveillance capabilities internationally, targeting groups that Beijing considers threats to state stability28.
Firms like I-SOON have been involved in operations targeting activists, journalists, and minority groups28. Beyond domestic monitoring in regions like Xinjiang, state contractors have compromised telecommunications networks in neighboring countries to track refugees and dissidents abroad33.
Other campaigns, such as those conducted by SEQUIN CARP, use targeted social engineering and phishing to compromise journalists and human rights advocates, stealing credentials and tracking communications28.
Global Expansion and the Global Development Initiative (GDI)
China is also expanding its digital footprint across the Global South. Through foreign initiatives like the Belt and Road Initiative (BRI) and the Global Development Initiative (GDI), Beijing exports technology platforms and surveillance infrastructure to developing markets54.
| Geopolitical Initiative | Cyber Implementation Strategy | Intelligence Implications |
| Belt and Road Initiative (BRI) | Export of “Safe City” surveillance architectures and core telecommunications hardware. | Establishes persistent, dual-use infrastructure allowing for passive data collection on foreign populations. |
| Global Development Initiative (GDI) | Embedding dual-use technologies into economic development projects. | Fosters long-term economic dependencies and expands the logistical reach of the PLA’s intelligence networks. |
Deploying telecommunications hardware and “Safe City” surveillance systems across developing regions establishes long-term digital access59. Intelligence reports highlight repeated compromises of government networks and telecom operators in participating nations. For instance, tools like “SparroWocky” have been identified targeting government entities in Latin America, while leaked documents show routine extraction of call data records from African telecom providers29. This infrastructure network supports both political monitoring and foreign intelligence collection47.
Part VIII: Strategic Outlook and Defensive Imperatives
China’s cyber ecosystem represents an integrated, state-supported apparatus. Beijing has built a large-scale, efficient cyber operations capability by connecting military planning with commercial contractors, centralizing reporting of zero-day vulnerabilities, and keeping proxy networks running.
The shift toward pre-positioning access within critical infrastructure highlights an evolving operational focus. These activities go beyond traditional intelligence gathering and create operational options for use during broader strategic conflicts.
To address these challenges, defense strategies should focus on several practical priorities:
- Adopt Zero-Trust Architectures: Because actors use zero-day exploits and Living off the Land tactics, organizations cannot rely solely on perimeter security. Implementing zero-trust controls, network segmentation, and behavioral monitoring helps detect lateral movement early8.
- Harden Network Edge Equipment: Compromised edge devices, such as firewalls and VPNs, are frequently used to establish initial access and construct proxy networks. Prioritizing timely patching, replacing outdated hardware, and disabling unnecessary management interfaces remain critical defensive steps12.
- Strengthen Access and Identity Management: With threat groups frequently using stolen credentials, enforcing phishing-resistant multi-factor authentication (MFA) and securing directory environments are essential to prevent unauthorized lateral access8.
- Manage Supply Chain Risks: Under Military-Civil Fusion, Chinese technology providers operate under national security requirements. Protecting critical systems requires ongoing supply chain evaluation and risk management10.
Please share the link on Facebook, Forums, with colleagues, etc. Your support is much appreciated and if you have any feedback, please email us in**@*********ps.com. If you’d like to request a report or order a reprint, please click here for the corresponding page to open in new tab.
Sources Used
- A New Step in China’s Military Reform – NDU Press, https://ndupress.ndu.edu/Media/News/News-Article-View/Article/4157257/a-new-step-in-chinas-military-reform/
- China’s new Information Support Force, https://www.iiss.org/online-analysis/online-analysis/2024/05/chinas-new-information-support-force/
- China’s offensive cyber ecosystem: a complex network of actors for a, https://shs.cairn.info/article/EFRC_252_0106/pdf?lang=en
- IntelBrief: China’s Military-Civil Fusion Strategy – The Soufan Center, https://thesoufancenter.org/intelbrief-chinas-military-civil-fusion-strategy/
- A comprehensive analysis of I-Soon’s commercial offering, https://harfanglab.io/insidethelab/isoon-leak-analysis/
- THE KNOWNSEC LEAK: Yet Another Leak of China’s Contractor, https://dti.domaintools.com/research/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem
- Xi Replaces the Strategic Support Force with Three New “Arms”, https://www.platracker.com/post/operationalizing-intelligentized-warfare-xi-replaces-the-strategic-support-force-with-three-new-ar
- Chinaʼs Zero-Day Pipeline: From Discovery to Deployment, https://assets.recordedfuture.com/Executive-Insights/eir-2025-1219.pdf
- The Politics of Patch Delays: When Vulnerability Disclosure Collides, https://falconfeeds.io/blogs/the-politics-of-patch-delays-when-vulnerability-disclosure-collides-with-national-interests/
- Code red – McCrary Institute, https://mccraryinstitute.com/app/uploads/2025/10/McCrary-Institue-Code-Red-Release-Ready.pdf
- Cyber Redlines and China: Taking Advantage of the Trump-Xi Meeting, https://securityandtechnology.org/blog/cyber-redlines-and-china-taking-advantage-of-the-trump-xi-meeting/
- PRC State-Sponsored Actors Compromise and Maintain Persistent, https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
- Volt Typhoon’s long shadow, https://www.iiss.org/online-analysis/cyber-power-matrix/2026/01/volt-typhoons-long-shadow/
- A Tale of Two Typhoons: Properly Diagnosing Chinese Cyber Threats, https://warontherocks.com/a-tale-of-two-typhoons-properly-diagnosing-chinese-cyber-threats/
- Beyond Fusion: Preparing for Systems Rivalry with China, https://warontherocks.com/beyond-fusion-preparing-for-systems-rivalry/
- Military–Civil Fusion (Chapter 2) – The Fourth Industrial Revolution, https://www.cambridge.org/core/books/fourth-industrial-revolution-and-militarycivil-fusion/militarycivil-fusion/EE5FBEDB4814D131918B41DC5ABE13EC
- China’s Quest for Military Technology through Foreign and Civil, https://eh4s.eu/publication/chinas-quest-for-military-technology-through-foreign-and-civil-sources-strategic-trends-under-xi-jinping-and-tactical-adjustments-amid-geopolitical-challenges
- Myths and Realities of China’s Military-Civil Fusion Strategy – CNAS, https://www.cnas.org/publications/reports/myths-and-realities-of-chinas-military-civil-fusion-strategy
- China’s Zero-Day Pipeline: From Discovery to Deployment, https://www.recordedfuture.com/research/china-zero-day-pipeline
- The Chinese Military’s New Information Support Force – CNA.org., https://www.cna.org/our-media/indepth/2024/08/chinese-information-support-force
- The PLA’s Cyber Operations Go Dark – Lawfare, https://www.lawfaremedia.org/article/the-pla’s-cyber-operations-go-dark
- The 5×5—China’s cyber operations – Atlantic Council, https://www.atlanticcouncil.org/commentary/the-5×5-chinas-cyber-operations/
- People’s Liberation Army Strategic Support Force – Wikipedia, https://en.wikipedia.org/wiki/People%27s_Liberation_Army_Strategic_Support_Force
- Information Warfare and Military Reform in the Twenty-first Century, https://scholarspace.library.gwu.edu/downloads/cz30pt664?disposition=attachment&locale=en
- A first analysis of the i-Soon data leak – Malwarebytes, https://www.malwarebytes.com/blog/news/2024/02/a-first-analysis-of-the-i-soon-data-leak
- The PLA’s New Information Support Force – Air University, https://www.airuniversity.af.edu/CASI/Display/Article/3749754/the-plas-new-information-support-force/
- A Timely Leak Offers a Peek Into Chinese Cyberespionage Worldwide, https://mindmatters.ai/2024/03/a-timely-leak-offers-a-peek-into-chinese-cyberespionage-worldwide/
- Tall Tales: How Chinese Actors Use Impersonation and Stolen, https://citizenlab.ca/research/how-chinese-actors-use-impersonation-and-stolen-narratives-to-perpetuate-digital-transnational-repression/
- I-Soon GitHub Leak: What Cyber Experts Learned About Chinese, https://www.infosecurity-magazine.com/news-features/isoon-github-leak-chinese-cyber/
- Leaked hacking files show Chinese spying on citizens and … – PBS, https://www.pbs.org/newshour/world/leaked-hacking-files-show-chinese-spying-on-citizens-and-foreigners-alike
- Leaked documents open the lid on China’s commercial hacking, https://therecord.media/china-commercial-hacking-industry-isoon-leaks
- Unmasking I-Soon | The Leak That Revealed China’s Cyber, https://www.sentinelone.com/labs/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations/
- APT3: Gothic Panda — China’s Zero-Day Pioneers | Hedgehog, https://www.hedgehogsecurity.co.uk/blog/apt3
- What to Think About the I-Soon Chinese Hacker Contractor Leak, https://www.rstreet.org/commentary/the-download-what-to-think-about-the-i-soon-chinese-hacker-contractor-leak/
- The Hidden Network Report | Orange Cyberdefense CERT Threat, https://research.cert.orangecyberdefense.com/hidden-network/report
- Intrusion Truth – 入侵真相, https://intrusiontruth.wordpress.com/
- APT41, Wicked Panda, Brass Typhoon, BARIUM, Group G0096, https://attack.mitre.org/groups/G0096/
- APT 41 – Cyber Operations Tracker, https://www.cfr.org/cyber-operations/apt-41
- Threat actor profile: Double Dragon | Hunt & Hackett, https://www.huntandhackett.com/threats/actors/apt41
- China’s Capabilities for State-Sponsored Cyber Espionage, https://www.uscc.gov/sites/default/files/2022-02/Kelli_Vanderlee_Testimony.pdf
- Notable Ransomware Threat Actor Groups: Profiles and TTPs, https://ransomwareauthority.com/ransomware-threat-actors/
- LIMINAL PANDA: China’s Emerging Espionage Threat in the, https://brandefense.io/blog/liminal-panda-apt-group/
- Dark Pink: new APT hitting Asia-Pacific and Europe | Group-IB Blog, https://www.group-ib.com/blog/dark-pink-apt/
- New Law Will Help Chinese Government Stockpile Zero-Days, https://www.securityweek.com/new-law-will-help-chinese-government-stockpile-zero-days/
- Sleight of hand: How China weaponizes software vulnerabilities, https://www.atlanticcouncil.org/in-depth-research-reports/report/sleight-of-hand-how-china-weaponizes-software-vulnerability/
- People’s Republic of China State-Sponsored Cyber Actor Living off, https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a
- Volt Typhoon – NJCCIC – NJ.gov, https://www.cyber.nj.gov/threat-landscape/nation-state-threat-analysis-reports/china-linked-cyber-operations-targeting-us-critical-infrastructure/volt-typhoon
- Crash (exploit) and burn | Atlantic Council, https://www.atlanticcouncil.org/wp-content/uploads/2025/06/Crash-exploit-and-burn_DeSombre-Bernsen.pdf
- Cybersecurity for Innovative Small and Medium Enterprises and, https://www.atlanticcouncil.org/wp-content/uploads/2022/01/Cybersecurity-for-Innovative-Small-and-Medium-Enterprises-and-Academia.pdf
- Managed Competition: – Atlantic Council, https://www.atlanticcouncil.org/wp-content/uploads/2019/12/Meeting-Chinas-Challenges-Report-WEB.pdf
- U.S. and Partners Release Joint Cybersecurity Advisory on Volt, https://www.lawfaremedia.org/article/u.s.-and-partners-release-joint-cybersecurity-advisory-on-volt-typhoon
- United States, International Coalition Issue Joint Warning of, https://www.alstonprivacy.com/united-states-international-coalition-issue-joint-warning-of-increasing-prc-backed-threat-activity/
- FBI Announces Joint Cybersecurity Advisory Related to Salt Typhoon, https://www.fbi.gov/video-repository/salttyphoon082725.mp4/view
- China Threat Overview and Advisories – CISA, https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china
- NSA and Others Provide Guidance to Counter China State, https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/article/4287371/nsa-and-others-provide-guidance-to-counter-china-state-sponsored-actors-targeti/
- China: Freedom on the Net 2024 Country Report, https://freedomhouse.org/country/china/freedom-net/2024
- Chinese hackers targeted Uyghur activists and journalists living in, https://www.facebook.com/cnn/posts/chinese-hackers-targeted-uyghur-activists-and-journalists-living-in-the-united-s/10161860239876509/?locale=ms_MY
- China 2024 Human Rights Report – State Department, https://www.state.gov/wp-content/uploads/2025/07/624521_CHINA-2024-HUMAN-RIGHTS-REPORT.pdf
- Global Development Initiative and Military–Civil Fusion Synergy, https://www.orfonline.org/research/global-development-initiative-and-military-civil-fusion-synergy-china-s-strategy-for-global-influence
- Reflexive Accounts on Researching China’s Digital Surveillance, https://research-repository.griffith.edu.au/server/api/core/bitstreams/ae2d20a6-4bc7-41aa-b50a-116f43358650/content
- Chinese Cyber Espionage Puts Latin America’s Critical, https://dialogo-americas.com/articles/chinese-cyber-espionage-puts-latin-americas-critical-infrastructure-at-risk/
- China’s FamousSparrow hackers target Latin America with new, https://therecord.media/china-hackers-latin-america-espionage
- United States House Committee on Homeland Security, https://homeland.house.gov/wp-content/uploads/2025/03/2025-03-05-HRG-Testimony.pdf











