The hidden network

Explore our interactive map
How China unites state, corporate, and academic assets for cyber offensive campaigns

The state of Chinese cyber threats

Between 2023 and 2024, more than 35 advisories issued by our World Watch Cyber Threat Intelligence concerned zero-day vulnerabilities exploited by Chinese threat actors. These account for 41% of all advisories with a high or very high threat level, representing a substantial portion of the critical threats potentially facing our customers.

In order to carry out successful offensive cyber activities, the Chinese state both requires capabilities and opportunities. In order to ensure both, the Chinese state relies on a complex and multi-layered ecosystem involving a broad array of state and non-state actors.

This map offers a comprehensive overview of China's cyber threat landscape and visualizes the connections among hundreds of public and private entities, spanning government, industry, and academia.

Note: The analysis cut-off date for this report was October 22, 2024.

Read the report

Graph

Graph

        orange logo

        Chinese cyber offensive ecosystem: who does what?

        Alongside this map, our World Watch team published a deep-dive article to further detail the participation of state and non-state actors in the structured cyber activities emblematic of APT groups. This report provides an overview of the key state actors involved in China's cyber threat ecosystem, including the Ministry of State Security (MSS) and the People's Liberation Army (PLA).

        It also examines the role and impact of private companies and academic institutions on the conducting of cyber operations, as well as the internal dynamics of cooperation and competition within the sector. Finally, the article covers China's software vulnerability gathering system, showcasing the cooperation between public, corporate, and academic actors.

        Read the report