VORANT. Threat Intelligence Sign in Get the full feed

Experts dissect China's state cyber-operations model

low threat government-nationaltelecommunicationstechnologydefense

An Atlantic Council expert panel analyzes how China blends state security services, contracted hackers, and private tech firms to conduct large-scale espionage and IP theft.

This Atlantic Council '5x5' piece brings together five China cyber policy experts to discuss the structure, evolution, and distinguishing features of Chinese state-linked cyber operations. Panelists highlight the 2021 Microsoft Exchange Server exploitation and the career of Tan Dailin (aka WickedRose, linked to APT41/WICKED PANDA) as illustrative of China's model: a blend of patriotic hacking talent, contracted teams, and formal ties to the Ministry of State Security (MSS) and People's Liberation Army (PLA), with operational segmentation allowing rapid, wide distribution of exploits once stealth is lost.

The discussion emphasizes that China's cyber apparatus relies heavily on non-state contractors and private tech companies (citing Huawei and Alibaba as examples) operating under legal frameworks like the 2017 Cybersecurity Law and National Intelligence Law, which compel cooperation with state security services. Experts note China's operations have grown in scale and sophistication since 2018, shifting toward supply-chain attacks, targeting of service providers, and increased focus on US critical infrastructure such as natural gas pipelines. The piece also references the historic Titan Rain campaign and the Nortel/Huawei espionage case as examples of long-running economic and political intelligence collection.

Overall, this is an analytical/policy piece rather than an incident report — it contains no new technical indicators, active exploitation details, or fresh vulnerability disclosures, but provides structural and historical context on China's cyber threat landscape, including references to APT41 and past CISA/FBI/NSA advisories on exploited CVEs.

Mentioned in this report

Threat actors APT41
Campaigns Titan Rain

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-chinas-cyber-operations

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free