The China-Nexus Toolkit
This is a mechanism page, not a roster, and the distinction is the whole justification for it. /country/CN already lists every China-origin group we track, with descriptions and links. Publishing that list again with an essay on top would be a filtered view of something we already ship.
What is not published anywhere is the convergence. Every actor our graph links to ShadowPad is China-origin and none is anything else. PlugX, China Chopper and gh0st RAT show the same skew at lower ratios. DLL side-loading appears on China-origin actors at several times the rate it appears on everyone else. Those are joins, not opinions, and they answer a question an incident responder actually asks: we found this implant — what does that narrow the field to, and how much?
The counts under "What these have in common" recompute on every page load, so the claim strengthens or weakens with the graph rather than with the last time someone edited this paragraph.
- Curated entries: 31
- Members in the CISA KEV catalog: 4
- 30 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Hijack Execution Flow: DLL (T1574.001) 10/16 here · 35/171 tracked
- OS Credential Dumping: LSASS Memory (T1003.001) 10/16 here · 44/171 tracked
- Deobfuscate/Decode Files or Information (T1140) 9/16 here · 38/171 tracked
- Archive Collected Data: Archive via Utility (T1560.001) 9/16 here · 39/171 tracked
- System Network Configuration Discovery (T1016) 9/16 here · 43/171 tracked
- Exploit Public-Facing Application (T1190) 9/16 here · 44/171 tracked
- Indicator Removal: File Deletion (T1070.004) 9/16 here · 47/171 tracked
- System Owner/User Discovery (T1033) 8/16 here · 39/171 tracked
- Remote System Discovery (T1018) 8/16 here · 40/171 tracked
- Command and Scripting Interpreter: Windows Command Shell (T1059.003) 11/16 here · 73/171 tracked
Shared tooling
- ShadowPad 8/15 here · 8/157 tracked
- Impacket 6/15 here · 18/157 tracked
- Cobalt Strike 7/15 here · 29/157 tracked
- China Chopper 5/15 here · 9/157 tracked
- certutil 5/15 here · 14/157 tracked
- PowerSploit 4/15 here · 9/157 tracked
- Mimikatz 8/15 here · 51/157 tracked
- NBTscan 4/15 here · 10/157 tracked
- Net 6/15 here · 33/157 tracked
- Winnti for Linux 3/15 here · 3/157 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Mustang Panda APT · China — Government and NGO targeting; a heavy side-loader.
- APT41 APT · China — Espionage and financially motivated intrusion in one group.
- Volt Typhoon APT · China — Critical-infrastructure access; living off the land.
- Salt Typhoon APT · China — Telecommunications intrusions.
- APT10 APT · China — Managed-service-provider compromise.
- APT40 APT · China — Maritime and regional espionage.
- ZIRCONIUM APT · China — Also tracked as APT31.
- HAFNIUM APT · China — Exchange Server exploitation at scale.
- APT27 APT · China — Long-running espionage set.
- UNC3886 APT · China — Virtualisation and network-appliance persistence.
- UNC5221 APT · China — Ivanti-focused; see Exploited Edge Devices.
- UNC4841 APT · China — Barracuda ESG.
- UNC5174 APT · China — Access broker with state-adjacent tasking.
- Earth Lamia APT · China — Recent designation; thin file, included for the tooling overlap.
- Earth Lusca APT · China — ShadowPad; broad regional espionage.
- Aquatic Panda APT · China — ShadowPad; academic and government targeting.
- BRONZE BUTLER APT · China — ShadowPad; long-running Japan-focused set.
- Tropic Trooper APT · China — ShadowPad; Taiwan and Philippines.
- Tonto Team APT · China — ShadowPad; regional military and diplomatic targeting.
- RedEcho APT · China — ShadowPad; thin file, included because the implant link is the point.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2021-26855 KEV · ransomware — CVSS 9.1 · EPSS 100.0% · KEV added 2021-11-03 — ProxyLogon.
- CVE-2025-0282 KEV · ransomware — CVSS 9 · EPSS 100.0% · KEV added 2025-01-08 — Ivanti Connect Secure.
- CVE-2023-2868 KEV — CVSS 9.4 · EPSS 87.4% · KEV added 2023-05-26 — Barracuda ESG.
- CVE-2024-36401 KEV — CVSS 9.8 · EPSS 99.8% · KEV added 2024-07-15 — GeoServer; commodity exploitation by this cluster.
Malware and tooling
- ShadowPad 8 groups — Malware — Every actor we link to it is China-origin, and none is anything else.
- PlugX 14 groups — Malware — The long-running staple; heavy skew, not exclusive.
- China Chopper 9 groups — Malware — Minimal web shell, wide reuse.
- gh0st RAT 11 groups — Malware — Public source code, so the weakest attribution signal of the four.
Sectors
- Telecommunications Critical Infrastructure — Where several of these groups have been reported operating; the victim-side view of the same story.
Countries
- Taiwan A recurring target across this cluster in the reporting we hold.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Hijack Execution Flow: DLL 35 groups — stealth, execution — DLL side-loading — the technique with the widest gap between this cluster and everyone else.
Our coverage
The 12 most recent of 30 briefings that mention a member of this collection.
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14
- China-linked hackers grow a covert router relay with new backdoors 2026-07-07
- New Citrix NetScaler flaw leaks memory from VPN gateways 2026-06-30
- Chinese hackers hit Southeast Asian energy grids with a new backdoor 2026-06-26
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24
- Leaked attacker server reveals an advanced intrusion campaign across Mexico 2026-06-17
- Chinese cyberspies hit governments with a stealthier Windows backdoor 2026-06-17
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10
- Hackers Hijack Palo Alto Firewalls With Unpatched Root Flaw 2026-06-06
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16
- Hive0154 (Mustang Panda) Deploys Toneshell9 with Proxy-Blended C2 and SnakeDisk USB Worm Targeting Thailand Amid Cambodia Border Crisis 2026-02-16
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16
How this list was chosen. Membership is by attributed origin plus a shared-tooling filter, and the attribution is inherited from vendor naming rather than independently established: threat_actors.origin is free text with no confidence field and no source URL, so read every "China-nexus" label here as an assessment we are repeating, not one we are making. The incident block is switched off for this collection on purpose — the five incident rows attached to these groups come from a backfill that labelled named US telecommunications firms and a National Guard unit as claimed victims, four of the five on placeholder month-start dates, and publishing that under "recent activity" would be wrong in a way that matters. Shared tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities alongside bespoke implants.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.