Skip to main content
Mallory
1 malware family

China

Also known asChinaprc

China is described in the provided content as a hostile nation-state cyber actor and, specifically, as the most strategically deliberate cyber adversary to the United States. The content states that Beijing emphasizes persistent access and pre-positioning within U.S. critical infrastructure for potential coercion, disruption, and real-world effects during geopolitical crises, rather than espionage alone. Reported target areas include U.S. critical infrastructure broadly, including energy, water, communications, and subsea cable systems, as well as election-related influence efforts. The content also states that China and Russia continue cyber operations aimed at degrading coordination and testing alliance cohesion. Tactics and operational characteristics directly mentioned in the content include persistent access, pre-positioning, embedding access across U.S. critical infrastructure, exploitation of flaws in routers and network devices, and activity affecting or targeting subsea cable infrastructure. The content further states that China is leveraging or harnessing AI and machine learning and exploring quantum computing and autonomous systems powered by cloud architectures. It also describes China as attempting to export surveillance capabilities globally and notes U.S. concern over how China uses engagement in international cable-governance bodies such as the ICPC. Aliases directly provided are "china" and "prc." No specific sub-groups are identified in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • energy
  • water
  • communications
MITRE ATT&CK

Tradecraft

33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

14 of 15 tactics43 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
3 techniques
T1590
Gather Victim Network Information
T1591
Gather Victim Org Information
T1595×6
Active Scanning
TA0042
Resource Development
4 techniques
T1583×2
Acquire Infrastructure
T1585×4
Establish Accounts
T1586
Compromise Accounts
T1587×2
Develop Capabilities
TA0001
Initial Access
6 techniques
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1190×4
Exploit Public-Facing Application
T1195×4
Supply Chain Compromise
T1195.001
Compromise Software Dependencies and Development Tools
T1199
Trusted Relationship
T1200
Hardware Additions
T1566×6
Phishing
TA0002
Execution
1 technique
T1203
Exploitation for Client Execution
TA0003
Persistence
3 techniques
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1205
Traffic Signaling
T1542
Pre-OS Boot
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
TA0005
Stealth
6 techniques
T1006
Direct Volume Access
T1036
Masquerading
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1205
Traffic Signaling
T1218
System Binary Proxy Execution
T1542
Pre-OS Boot
TA0006
Credential Access
2 techniques
T1040×2
Network Sniffing
T1552
Unsecured Credentials
T1552.001
Credentials In Files
TA0007
Discovery
3 techniques
T1040×2
Network Sniffing
T1580
Cloud Infrastructure Discovery
T1654×3
Log Enumeration
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
1 technique
T1213×5
Data from Information Repositories
TA0011
Command and Control
1 technique
T1205
Traffic Signaling
TA0010
Exfiltration
1 technique
T1048
Exfiltration Over Alternative Protocol
TA0040
Impact
4 techniques
T1485
Data Destruction
T1486
Data Encrypted for Impact
T1498×2
Network Denial of Service
T1565
Data Manipulation
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping33

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.