The 912 Special Project Working Group is an elite task force associated with the People’s Republic of China’s Ministry of Public Security and linked to transnational repression operations targeting Chinese dissidents and diaspora communities worldwide, including in the United States. Public allegations describe the group as focused on identifying, monitoring, harassing, and suppressing individuals viewed by the Chinese state as political threats abroad. The group has been associated with coordinated online influence and harassment activity using large numbers of fake social media personas to threaten dissidents, amplify official PRC narratives, and counter pro-democracy speech. Reported operations included attempts to evade platform detection, performance tracking of operators managing false personas, and efforts to recruit unwitting individuals to further state-aligned messaging. The group has also been linked to disruption of online meetings and commemorative events involving dissidents, including interference with videoconferences through threats, abusive content, and disruptive audio. Broader reporting places the group within the PRC’s overseas security and transnational repression apparatus, which has targeted communities such as Uyghurs, Tibetans, Falun Gong practitioners, Hong Kong pro-democracy activists, and other critics of the Chinese Communist Party. Associated activity aligns with efforts to identify and locate targets, build profiles on them, infiltrate communities, spread propaganda and disinformation, and suppress speech on digital platforms. The actor is best characterized as a state-linked Chinese repression and influence operator rather than a financially motivated cybercriminal or ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An elite Ministry of Public Security task force allegedly involved in operations targeting dissidents and diaspora communities abroad as part of transnational repression.
A PRC Ministry of Public Security task force allegedly conducting transnational repression against Chinese dissidents abroad, including in the United States, through fake social media personas, online harassment, propaganda dissemination, attempted recruitment of unwitting amplifiers, and disruption of dissident videoconferences.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.