Amid growing tensions over Taiwan’s reunification with China, Beijing has directed its intelligence forces to target Taiwan and leverages its cyber power to pre-posit threat groups deep within essential networks to cause destruction and disruption in the event of conflict. Geopolitical events have been a clear driver for an increase in reported cyberattacks against Taiwan, including the May 2024 inauguration of Taiwanese President Lai Ching-te, who China has branded a “"separatist."
Case study: Cyberattacks against Taiwan
In 2024, Taiwan experienced a daily average of 2.4 million cyberattacks, double the average of the year prior. Chinese state-affiliated hackers mostly used conventional TTPs against Taiwan’s public sector and favored living-off-the-land (LOTL) techniques. Chinese hackers also targeted third-party service providers of internet service providers (ISPs) and the defense supply chain companies to move laterally.
Chinese state-linked cyberattacks against Taiwan’s telecommunications industry rose by 650% in 2024, and attacks against the transportation and defense industries rose by 70% and 57%, respectively. Conversely, attacks against energy, water resources and media entities decreased by 75%, 67% and 18%, respectively. The shift in targeting focus reveals China’s use of offensive cyber methods in alignment with its national strategies. China targeting Taiwan’s telecommunications industry also aligned with its cyber threat activity in the U.S. and other regions.
It is possible China would go to great lengths to ensure its strategic position in Asia, specifically Southeast Asia because it sees it as the stabilizing force and hub for explosive growth in the region. The two have deep historical interconnectedness established through centuries of trade and migration. Beijing has leveraged its Belt and Road Initiative, creating a Chinese-centric economy in the Indo-Pacific region.
By leaning more into Southeast Asia as being economically indispensable, China likely seeks to use this position to bend the region to its will. Its reaction to previous geopolitical events impacting the region allows us to curate predictive case studies that assess future actions we would expect to see if Beijing sought to exert its influence to maintain a strategic upperhand.
Case study: Conflict in Southeast Asia
In a hypothetical scenario where China attacks the Indo-Pacific region or a Southeast Asian country, we would likely observe several key maneuvers. Covert influence operations and mobilizing the offensive and defensive capabilities from its private information security vendors would be among the primary characteristics of any such attack. The latter would be tapped to supply malware, tools and access to its collection of information about zero-day vulnerabilities.
Collectively, these strategies aim to give the state-backed cyber threat groups an upper hand when conducting destructive attacks against critical infrastructure. Pre-positioning themselves on the target networks almost certainly will remain a top priority for these groups, who would conduct ruthless and calculated attacks to cause as much damage as possible and induce widespread panic.
After assessing the strategic elements that drive China’s increased threat posturing and maneuvering, we can look at what’s happening at a tactical level. The strategic knowledge informs us how China may mobilize its offensive capabilities to carry out very specific types of attacks against select entities and sectors in its areas of interest. To operationalize geopolitical intelligence, we can start to look at the specific adversary and the types of attacks they conduct, using insights into behaviors that illuminate opportunities to hunt.
Threat group profiles
The Chinese government drives a large hacking ecosystem in which APT and private companies. We have chosen to highlight Violet Typhoon aka APT31 and Volt Typhoon based on the breadth and scope of their respective operations.
The Violet Typhoon group supposedly is made up of a collection of Chinese intelligence officers, private information security contractors — such as Wuhan Xiaoruizhi Science and Technology Co. aka Wuhan XRZ — and administrative staff that carry out attacks on behalf of the Hubei State Security Department. The group has primarily targeted the U.S., but also Southeast Asia, Hong Kong, Europe and the U.K. in the defense industrial base, information technology (IT), healthcare and energy sectors. Key objectives include stealing diplomatic intelligence and trade secrets and exfiltrating sensitive information about critical infrastructure personnel. These events often coincided with periods of heightened geopolitical tensions between China and the U.S..
The Volt Typhoon group primarily seeks to pre-position itself on critical IT networks for disruption and destruction in the event of conflict with China’s adversaries. This access also can enable the attackers to move laterally to operational technology (OT) assets. The group exhibits only minimal activity within the compromised environments and stays burrowed deep within target networks for years. It has primarily targeted the U.S., particularly the manufacturing, utilities, transportation, government, IT and education industries. The group is considered technically sophisticated and well organized and executes every campaign with intention and in-depth knowledge of its targets. It will attack the same entities repeatedly over extended periods to validate and enhance its unauthorized access.
Trending tactics, capabilities and infrastructure
The transparency in government and private sector reporting of previous campaigns attributed to these groups has played a part in the groups’ emphasis on stealth and changing initial access and persistence tactics. Three tactics stood out.
Edge devices and services such as firewalls and VPN gateways have become popular targets. They are not only internet facing and provide critical services to remote users, but also not easily monitored by network administrators due to a lack of endpoint detection and response (EDR) solutions installed. Several high-profile and high-impact cyberattacks in the past few years were the result of alleged Chinese state-sponsored threat actors and/or groups exploiting flaws in network edge devices. Additionally, it was estimated that 85% of known zero-days Chinese nation-state groups exploited since 2021 were against public-facing appliances.
LOTL techniques use legitimate tools, features and functions available in a target environment to traverse networks and hide within normal network activity. Chinese APTs, including Volt Typhoon, use built-in Windows utilities (wmic, PowerShell, netsh, reg.exe) for stealth, persistence, and lateral movement. China-affiliated threat actor groups have been observed using NetCat shells and modifying the victim registry to enable remote desktop protocol (RDP). Adversaries increasingly use living-off-the-land binaries (LOLBins) such as reg.exe and expand.exe within a batch file on the compromised machine to achieve stealth.
ORB networks are global infrastructures of virtual private servers (VPSs) and compromised smart devices and routers. The extensive network of proxy devices allows their administrators to scale up and create a constantly evolving “mesh network” to conceal espionage operations. Each of China’s ORBs is maintained by other private companies or state-sponsored entities and facilitates multiple threat clusters, enabling large-scale, evasive campaigns by proxying traffic through compromised devices. The Violet Typhoon group and several other actors with a China nexus used the FLORAHOX network to proxy traffic from a source and relay it through a Tor network and numerous compromised router nodes to obfuscate the source of the traffic for espionage attacks.
Thanks to extensive tagging of hunt packages in the HUNTER library, we’re able to quickly identify a collection of hunts for TTPs known to have been used by Violet Typhoon aka APT31 and Volt Typhoon. Adversaries do evolve TTPs when they become widely detected, but don’t change them as easily or often as indicators of compromise (IOCs), such as IP addresses or file hashes. Tagging allows us to build campaigns consisting of multiple hunts that can be assigned to several analysts in the HUNTER hunt management module and executed concurrently on the organization’s EDR, XDR or SIEM platform. If you'd like to learn more, you can view our on-demand workshop exploring how geopolitical intelligence can strengthen your threat-hunting processes.
We’ve selected nine Volt Typhoon-tagged hunt packages (see below) covering Privilege Escalation. Discovery, Defense Evasion, Execution, Command And Control, Credential Access, and Lateral Movement tactics. The hunt packages are available to HUNTER subscribers, but our team of threat hunters have provided expert tips to isolate data worth pivoting on during an investigation.
Here we’ll look at the HUNTER package Powershell Encoded Command Execution, which is built to detect widely used defense evasion and execution tactics (Obfuscated Files or Information T1027 and PowerShell T1059.001). This hunt package is a good place to start because it’s easy to capture and the technique is used by many adversaries and malware families. Besides Volt Typhoon, these include APT40, APT42, BlackTech, Charming Kitten, Deep Panda, FIN6, Mango Sandstorm, Mint Sandstorm, Mustang Panda and OilRig.