China Cyber Hacking Capabilities: Global Concerns
China’s Cyber Operations: Intelligence Gathering over Disruption, Experts Say
Table of Contents
Singapore – Historically, China’s cyber activities have primarily focused on intelligence collection rather than disruptive attacks, according to cybersecurity experts. This approach contrasts with the more aggressive tactics sometimes employed by nations like Russia or Iran.
The Nature of Chinese Cyber Espionage
Proofpoint’s Mr. Kelly explained that China’s cyber espionage encompasses traditional objectives such as gathering military and political intelligence. However, it also extends to advancing economic interests, especially in countries possessing technologies China aims to develop domestically. Moreover, these operations are used to monitor dissidents residing abroad.
“The vast majority of activity we see from them is intelligence collection,” Mr. kelly stated. “So they will gain access to a network or a device, and they will maintain that access over a long period of time to gather intelligence, and not necessarily use that to overtly disrupt that particular network.”
Beijing’s Response to Allegations
In response to media reports linking the threat group UNC3886 to Beijing, a spokesperson for the Chinese Embassy in Singapore issued a statement on July 19. The embassy expressed “strong dissatisfaction” and “resolutely oppose[d] any unwarranted smearing against China.”
The statement continued, “In fact, China is one of the main victims of cyber attacks. We reiterate that China resolutely opposes and combats any form of cyber attacks in accordance with the law, and will not encourage, support or condone hacker attacks.”
Attribution and Geopolitical Context
Mr. Muhammad Faizal Abdul Rahman, a research fellow at the S. Rajaratnam School of International Studies in Singapore, noted that some Asian governments, particularly those closely aligned with the US and sharing similar geopolitical threat perceptions, have shown a greater willingness to directly attribute cyber attacks to China.
However, Singapore’s approach differs.”Singapore is different as the authorities focus on attributing cyber attacks to a threat group instead of pointing to any country… The link to a particular country, in this case China, was made by Western cyber-security companies for past incidents,” Mr. Faizal explained.
The Impact of Attribution
Mr. Faizal suggested that the persistence of cyber attacks indicates that public attribution may have limited impact on altering the behaviour of threat actors.
“But attribution can be useful to demonstrate to the domestic audience that the government has the capabilities to respond and is doing what it should do to respond to threats,” he added.”It also educates the public that the threat is real and not imagined, and that they should do their part for their country’s digital defense.”
