Jiangsu State Security Department is a China-linked state security entity associated with the Ministry of State Security and widely tied to advanced persistent threat activity in support of Chinese intelligence objectives. It has been publicly linked to the compromise of U.S. Office of Personnel Management systems, a major counterintelligence breach involving the theft of personnel and security-clearance background investigation data. Reporting associates the operation with state-sponsored actors operating from China and using malware-backed network access, backdoors, and stolen legitimate credentials likely obtained through social engineering. Activity attributed to this actor in the OPM intrusion included establishment of persistent access, use of malware such as PlugX and Sakula-associated tooling, and large-scale exfiltration of sensitive personally identifiable information and background investigation records. The operation demonstrated capabilities spanning initial access, credential theft, persistence, defense evasion, and post-exploitation leading to strategic intelligence collection. Targeting focused on U.S. government personnel systems and data related to federal employees, applicants, and associated individuals, consistent with espionage and counterintelligence collection rather than financially motivated crime. Jiangsu State Security Department should be understood as a government security and intelligence component rather than a conventional criminal group. High-confidence reporting in this context supports its association with Chinese state-sponsored cyber operations against U.S. government targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.