The China-Nexus Toolkit

This is a mechanism page, not a roster, and the distinction is the whole justification for it. /country/CN already lists every China-origin group we track, with descriptions and links. Publishing that list again with an essay on top would be a filtered view of something we already ship.

What is not published anywhere is the convergence. Every actor our graph links to ShadowPad is China-origin and none is anything else. PlugX, China Chopper and gh0st RAT show the same skew at lower ratios. DLL side-loading appears on China-origin actors at several times the rate it appears on everyone else. Those are joins, not opinions, and they answer a question an incident responder actually asks: we found this implant — what does that narrow the field to, and how much?

The counts under "What these have in common" recompute on every page load, so the claim strengthens or weakens with the graph rather than with the last time someone edited this paragraph.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Vulnerabilities

KEV marks a vulnerability CISA records as exploited in the wild.

Malware and tooling

Sectors

Countries

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Our coverage

The 12 most recent of 30 briefings that mention a member of this collection.

How this list was chosen. Membership is by attributed origin plus a shared-tooling filter, and the attribution is inherited from vendor naming rather than independently established: threat_actors.origin is free text with no confidence field and no source URL, so read every "China-nexus" label here as an assessment we are repeating, not one we are making. The incident block is switched off for this collection on purpose — the five incident rows attached to these groups come from a backfill that labelled named US telecommunications firms and a National Guard unit as claimed victims, four of the five on placeholder month-start dates, and publishing that under "recent activity" would be wrong in a way that matters. Shared tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities alongside bespoke implants.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions