Chinese Military
Attribution profile
- Type
- Nation State
- Location
- China
- Known incidents
- 2 incidents
- Sources
- 2 sources
- First seen
- 2018-05-20
- Last seen
- 2023-03-02
- Updated
- 2026-07-30 19:52
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is publicly referenced as the Chinese Military and Chinese State‑Sponsored Actors, with operations traced to infrastructure registered to Tsinghua University in Beijing, a state‑owned academic institution. Attribution to the Chinese state is supported by the actor’s use of Tsinghua IP addresses, its alignment with national economic initiatives, and its association with Chinese military and research programs. The actor’s activities have been observed in both cyber and electromagnetic domains, indicating a dual capability for network intrusion and signal interference.
Targeting spans aviation communications and navigation systems in the western Pacific and South China Sea, as well as government, telecommunications, energy, transportation, and academic networks in Alaska, Kenya, Brazil, Mongolia, and Germany. Strategic objectives explicitly cited include disrupting flight safety systems to demonstrate capability or test equipment, and conducting network reconnaissance to gather intelligence that supports China’s Belt and Road Initiative and broader economic development goals amid trade tensions. The actor’s actions are described as serving state‑directed cyberespionage rather than financially motivated crime.
Notable tactics involve systematic port scanning of services such as PPTP, MySQL, MAMP, OpenSSH, HTTP, SSL, and VPN IKE, often originating from a Tsinghua University IP that functions as a gateway or NAT. The actor has deployed a custom Linux backdoor named “ext4,” which hides within a modified cron file, activates hourly on TCP port 443, uses specific TCP header options, and employs XOR‑encoded payloads to execute bash commands. Campaigns highlighted in open sources include the March 2023 interference with Qantas aircraft over the Pacific and the 2018 Tsinghua‑linked reconnaissance and ext4 deployment against Tibetan targets and various international entities. These activities illustrate a pattern of state‑aligned intrusion and disruption focused on strategic geographic and sectoral targets.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 2 sources.