APT10
APT27
MUSTANG PANDA
APT41
VOLT TYPHOON
Threat IntelligenceAPTRedactedMarch 3, 202620 min read

China APT Global Activity:
22,705 Hostile Activities Detected in 24 Hours

24-hour intelligence assessment of sustained Chinese cyber operations targeting 4 European nations from 3,321 source IPs, with behavioral attribution to APT10, APT27, Mustang Panda, APT41, and Volt Typhoon.

Scroll

On March 3, 2026, MTAC proprietary threat intelligence sensors detected 22,705 hostile activities originating from 3,321 Chinese IP addresses targeting 4 countries across Europe. This 24-hour collection window reveals sustained and geographically diverse Chinese cyber operations consistent with state-sponsored intelligence gathering, mass credential spraying, and network pre-positioning activities.

This Report Has Been Redacted

You are reading a redacted version of this intelligence report. Specific IP addresses, target details, and certain classified indicators have been obscured. The full unredacted report is available to qualified organizations and includes complete IOCs, detailed target analysis, and actionable remediation guidance.

Key Metrics

22,705
Hostile Activities
3,321
Chinese Source IPs
4
Target Countries
4,049
Credential Attacks
11
Target IPs
83
Database Probes
10.6 MB
Total Data Volume
0
Large Transfers (>1 MB)

Key Judgments

Judgment 1 — High Confidence

MTAC detected 22,705 hostile activities originating from 3,321 Chinese IP addresses targeting 4 countries globally in the past 24 hours, indicating sustained and geographically diverse Chinese cyber operations.

Judgment 2 — High Confidence

Europe is the primary target region, receiving 100% of all Chinese-origin traffic (22,705 hostile connections). This concentration is consistent with known Chinese strategic intelligence collection priorities.

Judgment 3 — High Confidence

4,049 credential attacks (SSH/RDP/Telnet/VNC/SMB) detected, indicating active brute-force campaigns originating from Chinese infrastructure against global targets. T1110

Judgment 4 — Moderate Confidence

Behavioral analysis most strongly correlates with APT10 / Stone Panda, APT27 / Emissary Panda, and Mustang Panda based on observed TTPs, port targeting patterns, and global operational footprint.

Global Targeting Landscape

Chinese cyber operations targeted 4 countries across Europe during the reporting period. The geographic distribution provides insight into Beijing's strategic intelligence collection priorities and cyber pre-positioning activities.

RegionHostile Activities% of TotalTop Target Countries
Europe22,705100.0%France (18,960), Germany (2,626), United Kingdom (1,118), Spain (1)

Country Breakdown

FR
France — 18,960 malicious connections
83.5% of all traffic

Top cities: Grenoble (16,469), Lille (1,719), Roubaix (665). Heavy concentration in Grenoble suggests targeting of research institutions, semiconductor, or defense-adjacent infrastructure.

DE
Germany — 2,626 malicious connections
11.6% of all traffic

Top cities: Koeln (2,621), Duesseldorf (1). Near-total concentration in Cologne area suggests targeting of specific hosting or enterprise infrastructure.

UK
United Kingdom — 1,118 malicious connections
4.9% of all traffic

Top cities: Islington (1,118). All UK traffic concentrated in London's Islington borough, a major data center and fintech corridor.

ES
Spain — 1 connection observed
<0.01% of all traffic

Top cities: Cacicedo (1). Single reconnaissance probe likely representing target enumeration.

Chinese Source Infrastructure

Analysis of source infrastructure identifies which Chinese ISPs, cloud providers, and telecom operators are hosting the attack infrastructure. This intelligence enables defenders to implement targeted blocking and monitoring of Chinese network ranges associated with hostile activity. T1583

Top Chinese Source Organizations (ASN)

OrganizationHostile Activities
ChinaNet6,114
China Mobile Communications2,745
China Telecom (Group)2,395
China Unicom China169 Backbone2,166
Hangzhou Alibaba Advertising1,606
China Mobile Communications1,298
China Unicom Beijing Province597
ChinaTelecom Hubei Province552
China Unicom474
Beijing Baidu Netcom Science470
UCloud Information Technology464
Shandong Mobile Communications332

Top Chinese Source Cities

CityHostile Activities
Beijing2,821
Shanghai2,648
Hangzhou2,300
Guangzhou2,088
Xicheng Qu1,338
Nanjing1,233
Wuhan954
Chongqing488
Jinan475
Zhongguancun470

Threat Attribution

MTAC correlated observed TTPs against known Chinese APT groups documented in MITRE ATT&CK and open-source intelligence. Attribution through anonymization networks is inherently limited; the following assessments represent the most probable actors based on behavioral analysis of the past 24 hours.

TTP Correlation Matrix

Observed TTPAPT10APT27Mustang PandaAPT41Volt Typhoon
Multi-country targetingMED
Database probingMEDMED
SSH brute-forceMED
Mass credential sprayHIGH
TOR infrastructure activityMED
Multi-port C2 infrastructureHIGH
SSH/credential attacksMED
SMB lateral movementMED
SMB + Auth combinationHIGH
Persistent connectionsMED

Actor Profiles

A10
APT10 / Stone Panda HIGH
MenuPass / POTASSIUM / Red Apollo / Cicada
Sponsor
China (MSS Tianjin Bureau)
Motivation
Espionage — MSPs, global IP theft, defense
Correlation Score
6/10
Key Match
Multi-country targeting, DB probing, SSH brute-force

Operation Cloud Hopper targeted MSPs globally for downstream access to government and corporate networks across 12+ countries. 2018 DOJ indictment detailed massive IP theft from aerospace, defense, healthcare, and technology sectors. Uses compromised infrastructure and proxy chains for operational security.

Cloud HopperMSP targetingIP theftmulti-year persistence
A27
APT27 / Emissary Panda HIGH
LuckyMouse / Iron Tiger / Budworm / Earth Estries
Sponsor
China (PLA/MSS-affiliated)
Motivation
Espionage — government, defense, technology
Correlation Score
6/10
Critical Match
Mass credential spray (4,049 intrusion attempts)

Active targeting of government and defense organizations across Middle East, Southeast Asia, and Central Asia. Known for HyperBro RAT, SysUpdate backdoor, and exploitation of Microsoft Exchange vulnerabilities. Uses TOR exit nodes and multi-layer proxy infrastructure for C2.

HyperBro RATSysUpdateExchange exploitsTOR C2
MP
Mustang Panda HIGH
Bronze President / Earth Preta / RedDelta / Stately Taurus
Sponsor
China (MSS/PLA-affiliated)
Motivation
Espionage — government, NGOs, diplomacy
Correlation Score
6/10
Critical Match
Multi-port C2 infrastructure (20 IPs on 5+ ports)

Extensive targeting of Southeast Asian governments, European diplomatic missions, and NGOs. Known for PlugX, TONESHELL, and custom DOPLUGS malware. Documented USB-based propagation for air-gapped network compromise. Multi-port C2 with rapid domain rotation.

PlugXTONESHELLDOPLUGSUSB propagation
A41
APT41 / Winnti MOD
Wicked Panda / BARIUM / Brass Typhoon / Earth Baku
Sponsor
China (MSS — dual espionage/financial)
Motivation
Espionage & financial — telecom, supply chain
Correlation Score
5/10
Key Match
DB probing, SSH/credential attacks, SMB lateral movement

Operation CuckooBees demonstrated multi-year infiltration of semiconductor firms. Documented backdoors include ShadowPad, Winnti, and KEYPLUG. Active targeting of managed service providers to pivot into downstream customers. ShadowPad and KEYPLUG support TOR-compatible C2 channels.

ShadowPadWinntiKEYPLUGsupply chain
VT
Volt Typhoon MOD
Bronze Silhouette / Vanguard Panda / DEV-0391
Sponsor
China (PLA SSF)
Motivation
Pre-positioning — critical infrastructure
Key Match
SMB + Auth combination (HIGH), persistent connections
Assessment
Living-off-the-land pre-positioning

Focuses on pre-positioning within critical infrastructure for potential disruption during a Taiwan contingency. Exclusively uses living-off-the-land techniques and legitimate credentials, making detection exceptionally difficult.

LotLpre-positioningcritical infrastructureSOHO routers

Technical Analysis

MTAC analyzed 22,705 hostile activities during the 24-hour collection period. All traffic originates from Chinese IP space, targeting 4 countries globally. The service-type breakdown provides insight into the operational focus of observed Chinese cyber operations.

Traffic Distribution

Traffic TypePercentage
Other (non-standard ports)80.5%
Remote Access (SSH/RDP/VNC/Telnet)15.6%
SMB / Database2.1%
Crypto / P2P1.1%
TOR Infrastructure0.6%

Top Services Targeted

ServiceHostile Activities
SSH T1021.0043,454
Non-standard high ports~9,100
SMB T1021.002482
Unknown / Ephemeral423

MITRE ATT&CK Mapping

The following table maps observed Chinese-origin network behavior to MITRE ATT&CK v16 Enterprise framework techniques.

TacticTechniqueProcedureAttributed ToConf.
Reconnaissance T1595.001 Active Scanning 20 scanner IPs, 30 port types APT10, APT27 HIGH
Initial Access T1110.001 Brute Force 4,049 credential-based intrusion attempts APT27 HIGH
Discovery T1046 Service Discovery 30 port types enumerated APT10, APT27 HIGH
Lateral Movement T1021.002 SMB Shares 482 SMB lateral movement attempts Volt Typhoon MOD
Command & Control T1090.003 Multi-hop Proxy 147 TOR ORPort connections APT27 HIGH
Collection T1119 Automated Collection 13 encrypted C2 sessions APT41 MOD

Priority Indicators of Compromise

The following IoCs were identified through behavioral analysis. P1 CRITICAL indicators represent confirmed hostile activity requiring immediate investigation. IP addresses have been partially redacted in this public version.

Full IOCs Available in Unredacted Report

The complete, unredacted indicator list with full IP addresses, CIDR ranges, and correlation metadata is available to subscribers. Contact our sales team to access the full intelligence package.

P1 Critical — Chinese Source IPs (Redacted)
  • 112.124.X.X — 250 connections, 224 ports scanned — Block; investigate
  • 121.43.X.X — 231 connections, 225 ports scanned — Block; investigate
  • 121.199.X.X — 220 connections, 220 ports scanned — Block; investigate
  • 121.41.X.X — 220 connections, 220 ports scanned — Block; investigate
  • 121.41.X.X — 218 connections, 218 ports scanned — Block; investigate
Target Organization Analysis (Redacted)

MTAC correlated observed network targeting patterns with Chinese APT attribution to identify which global organizations are being targeted. Specific organization names, targeting details, and actor-organization threat pairs are available in the full unredacted report. Contact sales@mjolnirsecurity.com for access.

Analytical Summary

Methodology

This report was compiled from MTAC proprietary threat intelligence sensors and darknet monitoring infrastructure covering a 24-hour collection window focused on Chinese-origin cyber operations. The analytical methodology employs behavioral pattern matching against documented Advanced Persistent Threat (APT) tradecraft, correlating observed network telemetry with MITRE ATT&CK v16 Enterprise framework techniques. Confidence assessments follow Intelligence Community Directive (ICD) 203 standards.

Attribution Assessment

The threat attribution model scored 5 Chinese APT groups above the relevance threshold based on this reporting period's activity. Attribution through anonymization networks carries inherent limitations — the assessments above represent the most analytically defensible conclusions given available evidence. MTAC recommends defensive measures aligned to the documented TTPs of all scored groups.

Continuous Monitoring

MTAC will continue monitoring Chinese cyber operations globally and will issue ad-hoc alerts for any significant escalation in targeting patterns, novel TTPs, or confirmed compromise indicators. This report represents a snapshot of the threat landscape; cumulative trend analysis across multiple reporting periods provides higher-confidence attribution.

Defend Against Chinese APT Operations

Mjolnir Security provides comprehensive threat intelligence and defensive capabilities specifically tailored to counter state-sponsored Chinese cyber operations.

Threat Intelligence Reports APT Hunting Incident Response Network Monitoring MDR Services IOC Feeds
  • Full Unredacted Intelligence Access the complete version of this report with all IP addresses, target organizations, and actionable indicators. Contact sales@mjolnirsecurity.com or fill out our contact form.
  • 24/7 Incident Response If you suspect Chinese APT activity in your environment, our IR team is available around the clock. Call +1 833 403 5875.
  • Threat Hunting as a Service Proactive hunting for Chinese APT indicators, including PlugX, ShadowPad, and living-off-the-land techniques within your infrastructure.
  • Strategic Advisory Executive briefings on the Chinese cyber threat landscape and tailored risk assessments for your industry vertical.
Source: MTAC Threat Intelligence Division  |  Published: March 3, 2026  |  22,705 records analyzed