

Making Sense of China’s Cyber Threat Landscape - Past, Present and How to Navigate the Maze of Complexity
Information
China features one of the most robust and fascinating threat ecosystems in the world. With a gigantic, thriving hacking community, numerous APT (advanced persistent threat) groups and a massive underground cybercrime scene, Chinese-speaking hackers and cybercriminals lead many notorious campaigns that affect individuals and organizations from multiple sectors worldwide.
Our understanding of this ecosystem is, nevertheless, quite deficient, as it is highly complex and mostly out of reach due to language barriers and accessibility. To map it, I shall introduce the evolution of the country’s hacking communities and analyze how they had contributed to the present-day formation of its cyber apparatus. I shall investigate some of the prominent attack groups and their activities and explain their entangled web of connections to former hacktivists, cybercriminals, private InfoSec companies, universities and government entities. In doing so, I shall refer to the challenges CTI analysts face while trying to decipher this world and show the sources and methods we use nowadays to paint a clearer picture and resolve the puzzle.