Ministry of State Security
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as the Ministry of State Security (MSS), also referred to as Guoanbu, is a Chinese state‑linked intelligence service. Its headquarters are located in China, and it operates under the direct authority of the Chinese government. The MSS is routinely cited in public attributions for cyber operations that serve state interests. It conducts foreign intelligence gathering and domestic security missions as part of its mandate. The actor is recognized by analysts as a component of China’s broader state‑sponsored cyber apparatus.
Targeting patterns show a focus on governmental and diplomatic entities, defense contractors, media organizations, and large hospitality chains. Geographically, the actor has conducted operations against targets in Belgium, Australia, the United States, and within China itself. The observed objectives include gathering political and policy information, acquiring technical data on military systems, collecting personal data for counterintelligence purposes, and, in one case, attempting to suppress critical news coverage through disruption and manipulation. These goals align with traditional espionage, strategic intelligence collection, and occasional information‑control efforts. Initial access in the reported incidents frequently involved high‑volume bot traffic and attempts to deploy spyware onto victim systems. The actor has also been observed using message manipulation and denial‑of‑service tactics to interfere with online communications. Defenders have noted the use of honey‑pot configurations to study the actor’s behavior during attacks.
Representative incidents illustrate the actor’s methods. In 2019 a Belgian trade mission in China faced a high‑volume bot‑driven attack that attempted to install spyware for stealing passwords and proprietary data, with security personnel using honey‑pots to analyze the methods. The same year Australian intelligence linked the MSS to a breach of the national parliament and three major political parties, noting the exfiltration of policy documents and private communications without evidence of weaponization, and shared the findings confidentially with US and UK allies. Earlier, in 2017 the MSS was blamed for a campaign against the China Digital Times website that combined message manipulation, denial of service, and data exfiltration to silence criticism and assert dominance over information. A 2015 intrusion into a US Navy contractor yielded detailed submarine warfare plans related to a supersonic anti‑ship missile program. A 2014 compromise of a major hotel chain exposed the personal records of hundreds of millions of guests, a breach that remained undetected for years before discovery and was linked to broader intelligence‑gathering on US officials. Across these cases the actor repeatedly employed bots, spyware tools, and techniques such as message manipulation and denial of service to achieve access and exfiltration. The consistent pattern points to a state‑directed effort to collect strategic information and shape the information environment.
Incidents
Attributed incidents are available to members.
7 incidents