The Beijing Institute of Electronics Technology and Application (BIETA) has been identified as a likely front organization for China's Ministry of State Security (MSS), according to multiple cybersecurity research reports. BIETA, along with its subsidiary Beijing Sanxin Times Technology Co., Ltd. (CIII), is reported to research, develop, import, and sell technologies that support intelligence, counterintelligence, military, and other national security missions for China. Publicly available evidence, including personnel links and institutional relationships, strongly suggests that BIETA is led by the MSS and acts as a public-facing entity for the MSS First Research Institute. The organization’s activities include the development of steganography methods that can facilitate covert communications and malware deployment, as well as the creation and sale of forensic investigation and counterintelligence equipment. BIETA and CIII have also been involved in acquiring foreign technologies, particularly those related to steganography, network penetration testing, and military communications, often through collaboration with Western organizations and researchers. This collaboration has sometimes occurred without the knowledge of the Western parties, who may have inadvertently supported Chinese state intelligence objectives. BIETA’s research and development focus encompasses communication technology, multimedia information processing, information security, computer and network technology, and special circuit development. The organization has existed in some form since 1983 and has developed software for covert communications, file uploads to cloud services, and network simulations. CIII, as a subsidiary, has received copyrights for software related to steganography and has developed applications for both communication and penetration testing. The links between BIETA, CIII, and the University of International Relations further reinforce the connection to the MSS, as the university is known to have ties to Chinese intelligence. While there is no public evidence that BIETA or CIII have engaged in illicit activity, their role in supporting the modernization of the MSS and the broader Chinese state security apparatus poses a challenge to foreign governments and private businesses. Security researchers recommend that export control authorities, academic institutions, and businesses exercise caution and consider restricting transactions with BIETA and CIII. The exposure of these organizations highlights the sophisticated methods used by Chinese intelligence to acquire and develop advanced cyber capabilities, often leveraging seemingly neutral research institutions as fronts for state-sponsored operations. The use of steganography and other covert techniques developed by BIETA and CIII has likely contributed to the operational effectiveness of Chinese advanced persistent threat (APT) groups, although direct operational links remain unconfirmed. The findings underscore the importance of due diligence and awareness when engaging with foreign research entities that may be connected to state intelligence services. The reports collectively provide a rare public insight into the infrastructure supporting China’s cyber-enabled intelligence operations and the risks posed by technology transfer to such entities.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On October 8, 2025, BankInfoSecurity and GovInfoSecurity further publicized the researchers' identification of BIETA and CIII as front companies tied to Chinese intelligence, extending awareness of the report's findings.
On October 6, 2025, multiple outlets reported on the new findings, emphasizing that BIETA and CIII used research partnerships and commercial channels to obtain or broker advanced Western cyber technologies for possible MSS and PLA use.
On October 6, 2025, Recorded Future published research assessing that BIETA is likely led by China's Ministry of State Security, citing personnel and institutional ties and describing BIETA and CIII as front organizations enabling MSS cyber and intelligence operations.
The Beijing Institute of Electronics Technology and Application (BIETA) has existed since 1983, later becoming part of a network of organizations assessed to support Chinese intelligence-related missions.
At an unspecified later date, BIETA's subsidiary Beijing Sanxin Times Technology Co., Ltd. (CIII) began developing and selling products such as penetration-testing tools, surveillance equipment, steganography, covert communications, and malware-deployment-related technologies that researchers say could support intelligence and military missions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcerecordedfuture.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.