A new threat intelligence assessment from cybersecurity firm Cyfirma paints a detailed picture of the challenges facing Chinese organisations amid a rapidly changing digital risk environment.
The report, titled ‘China Cybersecurity Threat Intelligence Report’, covers the period 2025-2026 and identifies a convergence of criminal ransomware operations, exploitation of outdated systems, supply chain compromises, and sophisticated state-sponsored espionage campaigns originating from several countries.
Ransomware remains one of the most disruptive forces affecting Chinese entities. No single group dominates the landscape. Instead, multiple actors including LockBit, World Leaks, and TheGentlemen conduct parallel campaigns targeting telecommunications, energy, information technology, and manufacturing sectors. Secondary groups such as Warlock, Sinobi, Crypto24, Devman, RansomHouse, and Beast also feature prominently. Recent examples include LockBit5 posting stolen data from a Chinese IT service provider and a water production company in February 2026, alongside RansomHouse activity against a major manufacturer in December 2025.
Legacy software flaws continue to provide easy entry points for attackers. The report notes that vulnerabilities dating back as far as 2014 remain actively exploited alongside more recent ones from 2024 and 2025. Commonly targeted weaknesses include CVE-2019-12780 affecting Belkin devices, CVE-2017-17215 in NETGEAR routers, and CVE-2014-8361 related to Realtek software. Outdated WordPress installations, GeoServer services, and various networking devices from vendors such as Netgear, Huawei, and Zyxel are also highlighted as frequent points of failure due to poor patching practices.
Supply Chain Compromises Amplify Impact
Threat actors increasingly focus on managed service providers, software-as-a-service platforms, and third-party ecosystems to reach multiple victims simultaneously. Examples cited include infiltration of Chinese software firms serving government and defence clients, as well as compromises of overseas telecommunications providers that enabled access to national time synchronisation systems. Such breaches carry the potential for widespread disruption across finance, energy, telecommunications, and defence sectors.
Critical Infrastructure Remains Vulnerable
The report draws attention to alleged compromises of China’s National Time Service Center, which relied on trusted third-party access and involved the deployment of 42 specialised cyber tools for persistence and data extraction. Iranian-linked APT33 has been observed targeting energy infrastructure including refineries and pipelines, while other state actors direct attention towards artificial intelligence and semiconductor research facilities.
Foreign Espionage Campaigns Intensify
Multiple advanced persistent threat groups from Iran, Russia, North Korea, Vietnam, and India are conducting long-term intelligence-gathering operations against Chinese government, technology, energy, and defence targets. Notable actors include APT34, APT43, APT29, APT28, Lazarus Group, Turla, OceanLotus, and Sidewinder. Techniques range from malware deployment to GitHub repository poisoning aimed at cybersecurity researchers.
Artificial intelligence tools are accelerating both the speed and precision of attacks, enabling more effective phishing campaigns in Mandarin and faster identification of exploitable weaknesses.
The assessment concludes that cyber risk has become systemic and interconnected. Organisations are advised to adopt zero-trust architectures, strengthen supply chain oversight, implement continuous monitoring, and prioritise timely vulnerability management.
The core message emphasises assuming compromise and building resilience rather than relying solely on prevention.
Source: Cyber Security Intelligence
Cyfirma