Great Firewall of China
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor referenced by the alias "Great Firewall of China" is not a traditional cybercriminal group but rather a label applied to China's extensive internet censorship apparatus. This alias is commonly used in open‑source discussions to refer to the collective system of technical controls known as the Great Firewall (GFW). The system is situated within the People's Republic of China, with its operational infrastructure distributed across multiple provincial and national network nodes. Public sources describe the GFW as a state‑run initiative managed by various Chinese government ministries and telecommunications regulators. No credible reporting identifies the alias as denoting a separate, independent threat actor engaged in offensive cyber operations.
The Great Firewall employs a range of technical measures to filter and block traffic deemed undesirable by the authorities. These measures include IP address black‑holing, DNS spoofing or injection, URL keyword filtering, deep packet inspection, and reset‑packet injection. By manipulating routing and protocol responses, the system can prevent access to specific foreign websites, services, and protocols. The stated objectives of the GFW are to uphold national laws, preserve social stability, and control the flow of information across China's borders. These functions are defensive in nature and are not characterized as tools for financial gain, espionage, or disruption of external targets.
Attribution of the Great Firewall to the Chinese state is well documented in academic literature, government white papers, and reputable news outlets. The apparatus is understood to be operated jointly by entities such as the Ministry of Public Security, the Cyberspace Administration of China, and major telecommunications carriers. Because its purpose is internal content regulation, there is no public evidence linking the GFW to campaigns of data theft, ransomware, or other financially motivated cybercrime. Consequently, threat‑intelligence reports that treat the alias as an offensive actor typically note the absence of corroborating indicators of compromise or malware families. The available information describes the Great Firewall of China as a state‑controlled censorship system rather than a conventional threat actor engaged in malicious cyber operations.
Incidents
Attributed incidents are available to members.
0 incidents