China’s Ministry of Public Security (MPS) conducted its 2026 HuWang (HW, “Protect the Network”) nationwide live-fire cyber exercise across July and August. The program required tens of thousands of organizations—including entities in telecommunications, finance, energy, aviation, internet services, universities, and healthcare—to defend operational environments against simulated attacks, often without advance notice, while maintaining continuous monitoring.
Marking HuWang’s tenth anniversary, the 2026 exercise reportedly placed greater emphasis on artificial intelligence and ran in multiple batches. Originally a narrower red-team/blue-team assessment of critical sectors, HuWang has become a large-scale mechanism for testing organizational readiness, evaluating offensive and defensive talent, and expanding demand for China’s domestic cybersecurity services and capabilities; participating blue-team personnel are commonly supplied through security providers under formal engagements.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
CISA's tenth Cyber Storm exercise took place during the week preceding the referenced publication; the exercise was characterized as the closest U.S. analogue to HuWang.
The 2026 HuWang exercise ran during July and August and was described as the program's tenth anniversary edition, with greater emphasis on artificial intelligence. Another source described batches beginning July 17, August 3, and August 18.
The 2025 HuWang exercise reportedly ran from July 1 through July 31.
The 2024 HuWang exercise reportedly ran from July 22 through August 30. The program was described as moving toward more routine operation beginning in 2024.
The 2023 HuWang exercise reportedly lasted approximately two weeks.
The 2022 HuWang exercise reportedly lasted approximately two weeks.
The 2021 HuWang exercise reportedly lasted approximately two weeks.
China's Ministry of Public Security reportedly initiated the HuWang (护网行动/HW) cyber attack-and-defense exercise, using red-team and blue-team participants in real operational environments.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcenattothoughts.com
Open sourcearchive.ph
Open sourcearchive.ph
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.