The People's Liberation Army (PLA) is the armed force of the People's Republic of China and operates under the control of the Chinese Communist Party. In cybersecurity and information operations contexts, the PLA is widely associated with Chinese state military doctrine covering network warfare, electronic warfare, intelligence support, and disruption of adversary communications and infrastructure in support of broader strategic and military objectives. Security practitioners most commonly refer to it as the PLA, with the full name People's Liberation Army also widely used. The PLA has been linked in open reporting to offensive cyber activity, pre-positioning in network infrastructure, exploitation of vulnerabilities in routers and other edge devices, and contingency planning for conflict scenarios involving Taiwan. Its operational approach is generally characterized by the use of practical, scalable access methods rather than reliance solely on exotic capabilities, including exploitation of known weaknesses in internet-facing systems and network appliances. The PLA is also associated with electronic warfare research and planning intended to deny or degrade communications services, including satellite-enabled connectivity that could support military resilience during conflict. In the Taiwan contingency context, the PLA has been discussed in relation to efforts to disrupt communications ecosystems, including research into distributed jamming concepts against satellite internet services such as Starlink. Such activity aligns with broader Chinese military interest in information denial, command-and-control disruption, and shaping the battlespace before or during kinetic operations. As a state military organization rather than a single intrusion set, the PLA encompasses multiple units, departments, and subordinate elements, some of which have historically been tied by public reporting and indictments to cyber espionage and network exploitation campaigns. The PLA is commonly treated as part of the broader Chinese state cyber apparatus alongside other government, intelligence, and contractor-linked entities. High-confidence characterization places it as a Chinese nation-state military actor focused on strategic intelligence collection, operational preparation of the environment, and support to military objectives through cyber and electronic warfare.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Meitei separatist outfit from Manipur’s Imphal Valley described as cooperating with the Myanmar military against resistance groups in Sagaing Region.
The People's Liberation Army (PLA) is leveraging common software vulnerabilities in routers and network devices to prepare for potential large-scale cyber operations, particularly in the context of geopolitical conflict with Taiwan.
The PLA is researching and simulating large-scale electronic warfare operations to jam and deny Starlink satellite internet access over Taiwan, using distributed airborne jamming nodes such as drones, balloons, or aircraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.