An analysis published by Geopolitical Monitor examined GhostNet — a covert international cyber espionage network documented by the Information Warfare Monitor in 2009 that had already compromised 1,295 computers across 103 countries, with approximately 30% classified as high-value targets containing intelligence-applicable information. Targets included diplomats, military attachés, secretaries to heads of government, personal assistants, and media organizations — a breadth and quality of access that represented a paradigm shift in low-cost, decentralized intelligence collection.
Capabilities: Total Control via GhostRAT
GhostNet's core tool, GhostRAT, gave operators comprehensive control over infected systems: remote file download, keystroke logging, and the ability to silently activate the victim's microphone or webcam. Crucially, GhostNet was also self-propagating — the malware harvested personal details and contact information from infected machines and used them to generate malicious email attachments appearing to originate from trusted sources. Recipients who executed the attachment saw a document load without error, with no visible indication of infection. This combination of full-spectrum surveillance capability and socially engineered propagation allowed GhostNet to expand its footprint across high-value networks while remaining undetected for an extended period.
Attribution: China Strongly Indicated, Not Confirmed
The Information Warfare Monitor's report identified significant circumstantial evidence pointing toward Chinese government involvement — but stopped short of definitive attribution. The intelligence profile of targeted systems (Tibetan and Taiwanese organizations, diplomatic and military personnel) aligned with PRC strategic interests. Hacker IP addresses repeatedly traced back to Hainan Island, home to the Lingshui signals intelligence facility and the Third Technical Department of the PLA. Beijing denied all involvement and suggested the findings were a propaganda campaign by the Tibetan government in exile.
The report acknowledged two alternative explanations. Chinese nationalist hacker groups — one of approximately 250 documented groups operating within China — could have conducted the operation independently, with or without state approval, and potentially with the intent to sell collected intelligence to the government. Alternatively, a non-Chinese actor could have deliberately routed operations through Chinese servers as a false flag; some command-and-control infrastructure was located in South Korea and the United States, not China.
Strategic Context: PLA Information Warfare Doctrine
GhostNet's scope and targeting align closely with established PLA doctrine, which regards cyberspace as a domain where China can offset conventional military imbalances with the United States. PLA strategic thinking frames U.S. military dependence on networked computer systems as an exploitable vulnerability, and advocates for peacetime computer network operations to build pre-emption capacity for potential future conflict. Whether or not GhostNet was a state-directed operation, its capabilities — 1,295 compromised computers across 103 countries, a significant fraction belonging to diplomatic and military personnel — demonstrate exactly the kind of persistent, low-cost intelligence collection that PLA information warfare doctrine prescribes.
Historical Significance
GhostNet's 2009 discovery marked a watershed moment in public understanding of state-level cyber espionage. The operation demonstrated that malware could replicate — at a fraction of the cost — access to sensitive government and diplomatic communications that would otherwise require expensive, high-risk human intelligence operations. The case established a template for the persistent, geopolitically targeted cyber intrusion campaigns that have since become a defining feature of great-power competition in the digital era.