Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors

chinese_state_sponsored_threat_actors

Also known asChinese State-Sponsored Threat Actors

China-nexus / Chinese state-sponsored threat actors (no specific group attribution provided in the source content). The content describes Chinese state-sponsored cyber activity as a long-term, increasing strategic threat, with advanced capabilities supported by a broad civil-military ecosystem involving state organs and private-sector contractors. Operational themes and targeting noted: - Targeting: Government services and facilities; IT sector; US legal services firms; SaaS providers; business process outsourcers; technology companies. In Europe, China-nexus actors are described as conducting intelligence collection, with focus on edge devices and cloud infrastructure, and consistently targeting government, healthcare, and biotechnology sectors. - Initial access and post-compromise: Compromise of public-facing web servers followed by web shell deployment; credential theft (including service accounts); access to domain controllers and copying of Active Directory databases; use of managed service provider (MSP) credentials to reach VMware vCenter. - Malware/tooling: Deployment of BRICKSTORM (Go-based) on VMware vCenter/ESXi for persistence and lateral movement. Capabilities include virtualization-aware operation, VSOCK-based inter-VM communications and exfiltration, C2 that mimics web server traffic, SOCKS5 proxying/tunneling, filesystem browsing, and shell command execution. Reported dwell time averaged 369 days in some networks. - Use of AI: Microsoft reporting increased use of AI by China (alongside Russia, Iran, North Korea) for online deception and cyber operations, including generating fake content, translating phishing, and creating digital clones of senior officials. Anthropic is cited as reporting Chinese state-sponsored hackers using the Claude LLM for automated cyberattacks against ~30 global organizations. Ecosystem/attribution context: - China’s offensive cyber capability is described as enabled by a multilayered ecosystem aligned with Military-Civil Fusion, involving the PLA, MSS, MPS, and MIIT, plus hundreds of private cybersecurity/technology firms and universities. - Named entities linked/associated in the content: Integrity Technology Group (ITG) described as linked to Flax Typhoon and as a major state cyber contractor; other companies cited as believed to contribute include ThreatBook, Qihoo360, and Qi An Xin; i-Soon is cited as a smaller subcontractor. UK-specific note in the content: a confirmed UK Foreign Office cyber incident was under investigation with no attribution stated; media speculation about Chinese involvement is explicitly described as unconfirmed.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics1 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0008
Lateral Movement
1 technique
T1210
Exploitation of Remote Services
ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.