China is the broadest and most persistent cyber threat of our time, with capabilities that surpass those of any other adversary.
The scale of China's cyber program is vast, and the ruling Chinese Communist Party (CCP) shows no signs of slowing down its aggressive actions in cyberspace.
The Chinese government strategically targets a wide array of sectors—including energy, telecommunications, and transportation—to gather intellectual property and other sensitive data. Their goal is not only espionage but also to prepare for cyberattacks on U.S. critical infrastructure. Recent activities indicate that China is pre-positioning to disrupt our infrastructure during a geopolitical crisis, highlighting the urgent threat posed by Chinese cyber operations.
CCP cyber tactics
Chinese cyber actors favor stealthy techniques that enable them to maintain long-term access to U.S. networks. By blending in with normal network activities, they can bypass traditional defenses, making detection difficult for cybersecurity professionals. Techniques such as "living-off-the-land" (LOTL) allow these actors to utilize built-in services and legitimate credentials, complicating efforts to identify malicious activities.
Their capabilities also include the use of zero-day attacks, which take advantage of previously unknown software flaws before any patches are available. The Chinese government leverages a vast ecosystem of private-sector firms to find and exploit these vulnerabilities. Facing such a threat, FBI partnerships with industry are the best way to deny the adversary easy gains and raise the cost of every attack.
News and alerts
-
04.23.2026 Defending Against China-Nexus Covert Networks of Compromised Devices
-
07.08.2025 Justice Department Announces Arrest of Prolific Chinese State-Sponsored Contract Hacker
-
04.24.2025 FBI Seeking Tips about PRC Targeting of U.S. Telecommunications
-
12.03.2024 Enhanced Visibility and Hardening Guidance for Communications Infrastructure
-
09.18.2024 People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations
-
07.08.2024 APT40 Advisory: PRC MSS Tradecraft in Action
-
03.21.2024 PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders
-
02.07.2024 PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
-
01.31.2024 Malicious Cyber Actors Exploiting Insecure SOHO Routers
-
01.03.2024 Chinese Police Imposters Incorporate Aggressive Tactics to Target U.S.-Based Chinese Community