← All Actors

Hafnium / PRC MSS-Linked Groups

China, Ministry of State Security (MSS) and affiliated entities (including MSS contractors such as Sichuan Juxinhe Network Technology designated in January 2025 for Salt Typhoon)

Mission Type

Strategic espionage, intellectual property theft, critical infrastructure pre-positioning for contingency operations

Primary Sectors

GovernmentTechnologyTelecommunicationsCritical Infrastructure

Operational Period

2009 – present

Attributed Cases

7

Attributed Cases

Activity Timeline

  1. 2015OPMEspionage
  2. 2018Cloud HopperEspionage
  3. 2021Exchange/HafniumEspionage
  4. 2023Taiwan TelecomEspionage
  5. 2023Storm-0558Espionage
  6. 2024Volt TyphoonEspionage
  7. 2024Salt TyphoonEspionage

Attribution Basis

How firmly each operation is tied to this actor, and by whom. Confidence reflects the weight of public evidence, not intelligence-community ground truth (see methodology §08).

OPMHigh Confidence

Attributed by US Government, Academic/Private Sector, US Government · Consequences: Public Naming Only

Cloud HopperConfirmed

Attributed by Academic/Private Sector, UK Government, US Government, Allied Coalition · Consequences: Indictment, Public Naming Only

Exchange/HafniumHigh Confidence

Attributed by US Government, EU, Allied Coalition, Academic/Private Sector · Consequences: Indictment, Public Naming Only

Taiwan TelecomModerate Confidence

Attributed by US Government, Allied Coalition, Academic/Private Sector · Consequences: Public Naming Only

Storm-0558High Confidence

Attributed by US Government, Academic/Private Sector · Consequences: Public Naming Only

Volt TyphoonHigh Confidence

Attributed by US Government, UK Government, Allied Coalition, Academic/Private Sector · Consequences: Public Naming Only

Salt TyphoonConfirmed

Attributed by Academic/Private Sector, US Government, US Government, Allied Coalition · Consequences: Sanctions, Public Naming Only

TTP Pattern Summary

PRC-linked groups demonstrate proficiency in zero-day exploitation of public-facing applications, mass exploitation campaigns, and living-off-the-land techniques for persistent access. Volt Typhoon's use of legitimate system tools to avoid detection in critical infrastructure networks represents the most advanced form of this approach. Groups routinely target cloud identity infrastructure and authentication mechanisms.

Initial Access (9)Persistence (4)Credential Access (3)Command and Control (3)Defense Evasion (3)Exfiltration (1)

Behavioural Signature

PRC-linked operations span a wide spectrum from targeted espionage (Storm-0558) to indiscriminate mass exploitation (Hafnium Exchange campaign) to strategic pre-positioning (Volt Typhoon). The willingness to shift from targeted to mass exploitation, and the Volt Typhoon pre-positioning pattern, distinguishes PRC operations from the more restrained SVR approach. Target selection reflects both traditional intelligence priorities and preparation for potential military contingencies.

Governance Footprint

Subject to the broadest multilateral attribution coalition to date (July 2021, including NATO's first attribution to China). Hafnium prompted the broadest international attribution coordination. Volt Typhoon generated the most significant Five Eyes joint advisory. PRC operations have driven major US legislative and regulatory responses including EO 14028 and proposed critical infrastructure legislation.