# China

> As of 2026-08-24, China is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning threat intel. ATT&CK coverage spans 23 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T0819 (Exploit Public-Facing Application), T1003 (OS Credential Dumping).

- **Tracked threats:** 2
- **Categories:** THREAT_INTEL
- **As of:** 2026-08-24

## ATT&CK techniques observed

23 techniques observed across 2 of 2 tracked threats. Tactics: Collection (3), Credential Access (3), Initial Access (3), Execution (2), Impact (2), Lateral Movement (2).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T0819](https://attack.mitre.org/techniques/T0819/) Exploit Public-Facing Application — Initial Access (ICS) — observed in 1 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 1 of 2 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 1 of 2 tracked threats
- [T1125](https://intel.threadlinqs.com/technique/T1125) Video Capture — Collection — observed in 1 of 2 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 1 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 1 of 2 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 1 of 2 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 1 of 2 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 1 of 2 tracked threats

## Tracked threats

- [Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre policy analysis, IALDF v. Rubio lawsuit, Freedom House 2026)](https://intel.threadlinqs.com/threat/TL-2026-1889) — INFO
- [NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2239) — MEDIUM

## Related CVEs

1 CVE referenced by tracked China activity.

- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/China
