Beijing Institute of Electronics Technology and Application (BIETA) is a Chinese technology organization assessed to function as part of the Ministry of State Security (MSS) support ecosystem. It has been linked through personnel and institutional relationships to the MSS and is regarded as a front organization that develops, acquires, imports, and sells capabilities relevant to intelligence, counterintelligence, and military missions. A known subsidiary, Beijing Sanxin Times Technology Co., Ltd. (CIII), appears to operate in the same support role. BIETA and CIII specialize in communications technology, multimedia information processing, information security, computer and network technology, and specialized circuit development. Their documented work includes steganography, covert communications, forensic and counterintelligence equipment, network penetration testing, communication simulation, and software for data transfer and online storage uploads. They have also developed tooling for testing or penetrating websites, mobile applications, enterprise systems, servers, databases, cloud platforms, and IoT environments. Additional reported work includes mobile-phone monitoring and positioning systems capable of supporting surveillance and collection. The organization is best understood not as a publicly attributed intrusion set but as an enabling entity within China’s state security apparatus that likely provides technical capabilities to MSS departments, officers, contractors, or proxies. Public reporting indicates its research and product development are closely aligned with cyber-enabled intelligence operations, including technologies applicable to covert communications, malware deployment, surveillance, and operational support. BIETA has existed since at least the 1980s and, together with CIII, represents part of the broader ecosystem of commercial and quasi-commercial organizations that support Chinese intelligence objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.