Research presented at Black Hat and a Booz Allen report describe China’s Great Cannon as an offensive cyber system that hijacked unencrypted HTTP traffic and injected malicious JavaScript into users’ browsers, turning them into temporary bots for distributed denial-of-service attacks. The capability was described as separate from, but colocated with, the Great Firewall on China Unicom infrastructure, and was notably used against GreatFire-related infrastructure on CloudFront and GitHub, where international visitors were silently redirected into flooding selected targets with repeated requests.
The reporting places the Great Cannon within a broader pattern of PRC cyber operations used to advance state interests around censorship, sovereignty, and political control. Alongside the GitHub and GreatFire incidents, the broader campaign history cited includes attacks on media outlets, petition platforms, and Hong Kong democracy-related services such as Telegram, LIHKG, Apple Daily, and PopVote, using tactics including DDoS, defacements, and data leaks. The sources assess likely Chinese state involvement while noting overlapping roles across entities including the PLA, MSS, MPS, and CAC, and they highlight HTTPS, HSTS, certificate protections, and behavioral monitoring as key defenses against traffic-injection attacks.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
On November 24, 2019, another DDoS attack against LIHKG used the Great Cannon.
On August 31, 2019, a DDoS attack against LIHKG used the Great Cannon, according to the report.
On June 12, 2019, a DDoS attack against Telegram measured 200 to 400 Gbps and mostly used IP addresses geolocated to China.
In 2019, PRC-attributed social media influence operations attempted to portray Hong Kong protesters as violent mobs in order to discredit the protest movement.
Beginning in April 2017, coordinated inauthentic Twitter campaigns targeted Guo Wengui and continued for at least two years.
In 2017 and 2018, Great Cannon DDoS attacks targeted MingJing News after it publicized interviews with Guo Wengui alleging corruption among PRC elites.
The Black Hat presentation states that Great Cannon attacks were observed from March 3, 2015 through April 7, 2015. During this campaign, the system injected malicious JavaScript into HTTP traffic to conscript browsers into DDoS activity.
On March 3, 2015, the Great Cannon campaign began, using hijacked traffic loading a Baidu analytics script to launch DDoS attacks against GreatFire. The first attack targeted GreatFire's mirror-hosting on Amazon CloudFront and reached 2.6 billion requests per hour.
In March 2015, a second Great Cannon attack targeted GitHub pages belonging to GreatFire and a mirror host of The New York Times. GitHub described the incident as the largest DDoS attack it had experienced up to that point.
In September and October 2014, DDoS attacks targeted Apple Daily, Next Media, and HKGolden during Hong Kong's Umbrella Revolution. CloudFlare reported that attacks against Hong Kong entities in October 2014 reached about 500 Gbps, and the activity was linked to the PRC-aligned Hurricane Panda cluster.
In October 2014, an adversary breached the personal email account of the academic who organized the Hong Kong referendum and leaked correspondence to pro-Beijing media.
In June 2014, massive DDoS attacks repeatedly targeted PopVote, the electronic voting system used in Hong Kong’s unofficial referendum on electoral reform. The attacks exceeded 300 Gbps, and Apple Daily and related Hong Kong media assets were also targeted during the same period.
In April 2011, large DDoS attacks originating in China targeted Twitition and Change.org after petitions demanded the release of Ai Weiwei. The report says all bot IP addresses used against Change.org were China-based and linked to China Unicom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.