CSIDB logo
Threat actor

China

Attribution profile

Type
Nation State
Location
China
Known incidents
4 incidents
Sources
1 source
First seen
2019-08-01
Last seen
2024-12-01
Updated
2026-08-28 16:25
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is commonly referenced by the aliases China, Chinese APT groups, and China state‑sponsored APT actors, with its operational base located in China. Observed targeting spans government entities such as the U.S. Treasury Department, telecommunications providers like Taiwan Mobile, media outlets including The National newspaper in Scotland, and activist communities associated with the Uyghur diaspora. These incidents demonstrate a focus on espionage through the theft of unclassified documents and credential harvesting, as well as disruption via website inaccessibility and the deployment of pre‑installed trojans on consumer devices.

The actor’s tactics include compromising third‑party vendors to obtain digital keys that enable remote access to victim networks, exploiting cloud‑based technical support services as an initial entry point. In surveillance campaigns against Uyghur‑related websites, the actor has used the Scanbox framework for visitor profiling and deployed Android exploits that deliver 64‑bit ARM executables to mobile users. Doppelganger domains mimicking legitimate services such as Google, the Turkistan Times, and the Uyghur Academy have been employed to facilitate credential theft, while Google OAuth has been abused to gain unauthorized access to Gmail accounts and contact lists. Additionally, the actor has leveraged supply‑chain compromises by embedding trojan malware in smartphones manufactured by Chinese partners during production.

Attribution to a state‑sponsored origin is consistently indicated in public reporting, linking the activity to the Chinese Communist Party and describing the responsible entities as China‑linked APT groups. Notable campaigns include the 2024 breach of the U.S. Treasury via a compromised vendor key, the 2021 distribution of trojan‑infected smartphones to Taiwan Mobile subscribers, the 2020 cyber attack that rendered The National newspaper’s website inaccessible for over an hour, and the prolonged 2019‑2020 surveillance operation targeting Uyghur‑related sites that combined Scanbox profiling, Android malware, doppelganger domains, and OAuth‑based email access. These examples illustrate the actor’s reliance on trusted‑third‑party abuse, mobile‑focused exploits, and credential‑stealing infrastructure to achieve its intelligence‑gathering and disruptive objectives.

Incidents

Attributed incidents are available to members.

4 incidents

Sources

Sources available to members: 1 source.

CSIDB