Key Takeaways
- According to Mandiant's M-Trends 2023 report, Chinese APT groups like UNC4841 were responsible for 15% of all detected espionage intrusions globally in 2022
- FireEye identified APT41 (a Chinese state-sponsored group) conducting dual espionage and financially motivated attacks on 20+ countries since 2019
- Microsoft Threat Intelligence Center attributed over 40% of nation-state attacks on Taiwan in 2023 to Chinese groups like Storm-0558
- Zscaler detailed Chinese STASHedInjector malware in 22 campaigns 2023, category: APT Groups and Attribution
- In 2022, Chinese hackers targeted 80% of Fortune 1000 firms per Verizon DBIR
- US Treasury reported Chinese espionage hit 50% of financial sector in 2023
- Mandiant found 40% of healthcare breaches in US linked to China 2022
- Chinese hackers used living-off-the-land techniques in 70% of detected intrusions per Mandiant 2023
- Microsoft found Chinese groups exploiting 45 zero-days in 2023 alone
- CrowdStrike reported Chinese use of Cobalt Strike in 55% of C2 ops 2023
- Operation Aurora in 2009 by Chinese hackers exploited IE zero-day affecting 30+ corps
- OPM breach 2015 by Chinese stole 21.5M records from US gov
- SolarWinds supply chain attack 2020 partially attributed to Chinese alongside Russian, affecting 18k orgs
- Chinese cyber ops exfiltrated 100TB data from US firms 2010-2020 per NSA
- Economic loss from Chinese IP theft $225-600B annually to US per IP Commission
Chinese state-backed cyber groups conduct widespread, persistent attacks against global targets.
APT Groups and Attribution
APT Groups and Attribution Interpretation
APT Groups and Attribution, source url: https://www.zscaler.com/blogs/research/
APT Groups and Attribution, source url: https://www.zscaler.com/blogs/research/ Interpretation
Attack Methods and Tools
Attack Methods and Tools Interpretation
Impacts and Responses
Impacts and Responses Interpretation
Notable Incidents
Notable Incidents Interpretation
Targeted Sectors
Targeted Sectors Interpretation
Sources & References
- Reference 1MANDIANTmandiant.comVisit source
- Reference 2FIREEYEfireeye.comVisit source
- Reference 3MICROSOFTmicrosoft.comVisit source
- Reference 4CROWDSTRIKEcrowdstrike.comVisit source
- Reference 5CISAcisa.govVisit source
- Reference 6RECORDEDFUTURErecordedfuture.comVisit source
- Reference 7SYMANTEC-ENTERPRISE-BLOGSsymantec-enterprise-blogs.security.comVisit source
- Reference 8DRAGOSdragos.comVisit source
- Reference 9BLOGblog.googleVisit source
- Reference 10JUSTICEjustice.govVisit source
- Reference 11PROOFPOINTproofpoint.comVisit source
- Reference 12IBMibm.comVisit source
- Reference 13UNIT42unit42.paloaltonetworks.comVisit source
- Reference 14WELIVESECURITYwelivesecurity.comVisit source
- Reference 15SENTINELONEsentinelone.comVisit source
- Reference 16TRENDMICROtrendmicro.comVisit source
- Reference 17SECURELISTsecurelist.comVisit source
- Reference 18DNIdni.govVisit source
- Reference 19ATTACKattack.mitre.orgVisit source
- Reference 20CYBEREASONcybereason.comVisit source
- Reference 21DEEPINSTINCTdeepinstinct.comVisit source
- Reference 22F-SECUREf-secure.comVisit source
- Reference 23ZSCALERzscaler.comVisit source
- Reference 24ASECasec.ahnlab.comVisit source
- Reference 25RESEARCHresearch.checkpoint.comVisit source
- Reference 26FORTINETfortinet.comVisit source
- Reference 27SOPHOSsophos.comVisit source
- Reference 28DARKTRACEdarktrace.comVisit source
- Reference 29RAPID7rapid7.comVisit source
- Reference 30VERIZONverizon.comVisit source
- Reference 31HOMEhome.treasury.govVisit source
- Reference 32DOCSdocs.broadcom.comVisit source
- Reference 33GAOgao.govVisit source
- Reference 34F5f5.comVisit source
- Reference 35MSRCmsrc.microsoft.comVisit source
- Reference 36WIREDwired.comVisit source
- Reference 37WASHINGTONPOSTwashingtonpost.comVisit source
- Reference 38FTft.comVisit source
- Reference 39REUTERSreuters.comVisit source
- Reference 40UBERuber.comVisit source
- Reference 41T-MOBILEt-mobile.comVisit source
- Reference 42BLOGblog.lastpass.comVisit source
- Reference 43POLYGONpolygon.technologyVisit source
- Reference 44TAIWANNEWStaiwannews.com.twVisit source
- Reference 45ABCabc.net.auVisit source
- Reference 46NSAnsa.govVisit source
- Reference 47NIPOnipo.govVisit source
- Reference 48FBIfbi.govVisit source
- Reference 49CONSILIUMconsilium.europa.euVisit source
- Reference 50ASDasd.gov.auVisit source
- Reference 51COMPTROLLERcomptroller.defense.govVisit source
- Reference 52CYENTIAcyentia.comVisit source
- Reference 53DELOITTEwww2.deloitte.comVisit source
- Reference 54NATOnato.intVisit source
- Reference 55NCSCncsc.gov.ukVisit source
- Reference 56JAPANTIMESjapantimes.co.jpVisit source
- Reference 57CHAINALYSISchainalysis.comVisit source
- Reference 58STATEstate.govVisit source






