Researchers said China used a network attack system dubbed the Great Cannon to divert some unencrypted traffic bound for Baidu services and silently replace legitimate responses with malicious JavaScript, turning foreign visitors’ browsers into bots for distributed denial-of-service attacks. The capability was linked to sustained attacks on GreatFire.org and later GitHub, marking a shift from domestic censorship toward using China’s Internet infrastructure to project offensive effects beyond its borders.
Citizen Lab, the International Computer Science Institute, and the University of California, Berkeley said the system appears distinct from but related to the Great Firewall, with evidence visible across multiple Chinese ISPs and consistent with state involvement. Researchers warned the same traffic-injection method could be adapted for broader payload delivery, including browser exploits or malware, while U.S. officials said attackers appeared to have leveraged infrastructure in China against U.S.-hosted sites and urged an investigation. The reports said HTTPS is the strongest practical mitigation because unencrypted HTTP traffic can be intercepted and modified in transit.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
U.S. officials publicly said the attackers appeared to have used Internet infrastructure located in China to overwhelm U.S.-based websites and called on China to investigate. The statement followed publication of research attributing the attacks to infrastructure under Chinese control.
Citizen Lab, the International Computer Science Institute, and the University of California, Berkeley published findings describing the 'Great Cannon,' a system distinct from but related to the Great Firewall that injects malicious code into unencrypted traffic. They warned the mechanism could be used not only for DDoS attacks but also potentially for exploit or malware delivery.
Attackers redirected a portion of unencrypted traffic destined for Baidu properties and replaced legitimate responses with malicious JavaScript, causing foreign visitors' browsers to flood GitHub. Researchers said the same campaign also targeted GreatFire content hosted on GitHub.
Researchers reported that GreatFire.org was subjected to a weeks-long distributed denial-of-service attack that they said marked an expansion of Chinese censorship tactics beyond simple blocking. The attack leveraged manipulated unencrypted web traffic to conscript outside users' browsers into sending attack traffic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.