China — Cyber Threat Profile
China's cyberspace governance model is state-centric and highly regulated. The Cyberspace Administration of China leads cyber policy, supported by the Cybersecurity Law framework mandating data localization, critical infrastructure protection, and content controls. National strategy emphasizes "cyberspace sovereignty," integrating cyber governance into national security doctrine. China invests heavily in cyber defense, AI security, and surveillance technologies. State-linked actors conduct extensive cyber operations globally, while domestic companies must comply with stringent security and data governance regulations.- National CERT/CSIRT: CNCERT/CC
- Data protection authority: Cyberspace Administration of China (source: CNIL)
- World Cybercrime Index 2024 (origin significance): 27.86 / 100, #3 worldwide
- Secure Internet servers per 1M people (2024): 1,413.3 (source: World Bank)
- Internet users (2025): 91.6% of population (source: World Bank)
Latest China coverage
- AtlasRAT looks factory-built, not like one gang's private tool 2026-07-30 · Cyber Incidents
- Patchwork hackers deploy a stealthy new in-memory RAT in China-themed attacks 2026-06-17 · Nation-State
- Malicious Steam wallpapers hijack gamers' accounts and drop backdoors 2026-06-16 · Cyber Incidents
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10 · Nation-State
- OnePlus Websites Compromised via Abandoned AWS S3 Bucket — Stored XSS Active Across Multiple Domains 2026-03-17 · Vulnerabilities
- SOE-phisticated Persistence: How Flax Typhoon Turned ArcGIS Into a Year-Long Backdoor 2026-02-16 · Nation-State
- Hive0154 (Mustang Panda) Deploys Toneshell9 with Proxy-Blended C2 and SnakeDisk USB Worm Targeting Thailand Amid Cambodia Border Crisis 2026-02-16 · Nation-State
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16 · Nation-State
- Salt Typhoon Targets European Telecom: CVE-2025-5777 Citrix NetScaler Exploit, SNAPPYBEE/Deed RAT via Antivirus DLL Sideloading, and Dual HTTP/TCP C2 via LightNode VPS 2026-02-16 · Nation-State
- Mustang Panda Targets Vietnamese Organizations with forfiles.exe Abuse, DLL Sideloading, and RC4 MAC Address Exfiltration in Dual-Campaign Espionage Operation 2026-02-16 · Nation-State
- Volt Typhoon CISA Malware Analysis: FRPC Reverse Proxy, FRP NAT Traversal, and ScanLine Port Scanner Recovered from Compromised US Critical Infrastructure 2026-02-16 · Nation-State
- Mustang Panda Deploys Nim-Written DLL Loader with Custom RC4 to Target Taiwanese Government and Diplomats Using 2024 Presidential Election Lure 2026-02-16 · Nation-State
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16 · Nation-State
- Mustang Panda Targets Australian Trade Minister in AUKUS-Motivated Campaign: SolidPDFCreator DLL Sideloading and PlugX Stager with Microsoft Host Header Masquerade 2026-02-16 · Nation-State
- Deep Panda Exploits Log4Shell in VMware Horizon to Deploy Milestone Backdoor and Novel Kernel Rootkit 2026-02-16 · Nation-State
Threat actors targeting China
- APT32 APT
- BITTER APT
- Patchwork APT
- RansomHouse Ransomware · 12 incident(s)
- LockBit Ransomware · 11 incident(s)
- DragonForce Ransomware · 8 incident(s)
- Qilin Ransomware · 6 incident(s)
- Cl0p Ransomware · 4 incident(s)
- The Gentlemen Ransomware · 4 incident(s)
- Akira Ransomware · 3 incident(s)
- Blackwater Ransomware · 3 incident(s)
- KillSec Ransomware · 3 incident(s)
- Hunters International Ransomware · 2 incident(s)
- Krybit Ransomware · 2 incident(s)
- ALP-001 Ransomware · 1 incident(s)
- ALPHV/BlackCat Ransomware · 1 incident(s)
- Audit Team Ransomware · 1 incident(s)
- Barracuda Ransomware · 1 incident(s)
- Beast Ransomware · 1 incident(s)
- BianLian Ransomware · 1 incident(s)
- BlackSuit Ransomware · 1 incident(s)
- Coinbase Cartel Ransomware · 1 incident(s)
- CRPxO Ransomware · 1 incident(s)
- Deadlock Ransomware · 1 incident(s)
- Global Secret Group Ransomware · 1 incident(s)
- Handala Hacktivist · 1 incident(s)
- L Group Ransomware · 1 incident(s)
- NightSpire Ransomware · 1 incident(s)
- Play Ransomware Ransomware · 1 incident(s)
- RansomHub Ransomware · 1 incident(s)
- Space Bears Ransomware · 1 incident(s)
- Termite Ransomware · 1 incident(s)
- Trigona Ransomware · 1 incident(s)
- APT-C-60 APT
- Daggerfly APT
- Darkhotel APT
- Equation Group APT
- knaithe APT
- Sidewinder APT
Most targeted sectors
- Technology 22 incident(s)
- Manufacturing 15 incident(s)
- Business & Professional Services 7 incident(s)
- Healthcare 5 incident(s)
- Energy & Utilities 4 incident(s)
- Financial Services 4 incident(s)
- Agriculture & Food 1 incident(s)
- Construction 1 incident(s)
- Government & Public Sector 1 incident(s)
- Hospitality & Tourism 1 incident(s)
- Retail & Consumer 1 incident(s)
- Telecommunications 1 incident(s)
Recent claimed incidents
- HONGHE-TECH.COM 2026-08-12 · Technology
- laticrete.com.cn 2026-08-07 · Manufacturing
- MINDRAY.COM 2026-08-07 · Healthcare
- RS Automation Co., Ltd. 2026-08-06 · Manufacturing
- Baicizhan 2026-08-03 · Technology
- TUI China 2026-08-03 · Hospitality
- JD Young 2026-07-27
- Uniview Technologies 2026-07-26 · Technology
- Momenta 2026-07-14 · Technology
- Atcom 2026-07-14 · Telecommunication
- Road Ahead Technologies Consultant 2026-07-14 · Business Services
- txdkj.com 2026-07-10
- AMHWA Biopharm Co., Ltd. 2026-07-09 · Healthcare
- xuerong.com 2026-07-08 · Technology
- drwu.com 2026-06-20