china-cyber-espionage

Describe Chinese state-sponsored cyber espionage actors, campaigns, and infrastructure.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill china-cyber-espionage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: china-cyber-espionage
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/china-cyber-espionage
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill china-cyber-espionage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides a structured, up-to-date knowledge cell detailing Chinese state-sponsored cyber espionage operations, actors, campaigns, and infrastructure to support threat research and defense planning.

Core Features & Use Cases

  • Comprehensive Actor & Campaign Profiles: summarizes APT groups (e.g., APT41, Volt Typhoon, Salt Typhoon, Mustang Panda) and their attribution, targets, and activity.
  • Historical Context & TTP Evolution: outlines major campaigns, techniques like LOTL, and operational patterns.
  • Reference & Source Synthesis: aggregates credible references for rapid citation and reporting.

Quick Start

Read the executive summary and use the actor/campaign tables to inform threat modeling and reporting.

Frequently Asked Questions about china-cyber-espionage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the primary targets and techniques of Chinese state-sponsored cyber espionage groups like Volt Typhoon?

Chinese state-sponsored cyber espionage groups like Volt Typhoon primarily target critical infrastructure using living-off-the-land (LOTL) techniques. This Skill provides structured profiles outlining their operational patterns, historical campaigns, and infrastructure to support threat modeling and defense planning.

How do I map APT41 campaigns to threat intelligence workflows for investigative analysis?

You can map APT41 campaigns to threat intelligence workflows by leveraging this Skill's comprehensive actor and campaign tables. It synthesizes attribution data, targets, and activity patterns to directly inform research reports and investigative analyses.

What is the historical context of Mustang Panda cyber espionage operations?

The historical context of Mustang Panda operations includes major campaigns and the evolution of their tactics, techniques, and procedures. This Skill outlines these operational patterns and historical campaigns to provide rapid citation for threat intelligence research.

Does this threat intelligence resource cover Salt Typhoon actor mappings and current activity?

Yes, this threat intelligence resource covers Salt Typhoon actor mappings and current activity. It aggregates credible references and up-to-date information on actors, campaigns, and infrastructure specifically focusing on groups like Salt Typhoon.

Can I use this for rapid citation and reporting on Chinese cyber espionage infrastructure?

Yes, you can use this for rapid citation and reporting on Chinese cyber espionage infrastructure. The Skill synthesizes credible references and aggregates source data to support the creation of research reports and threat intelligence documentation.

When do I need a structured knowledge cell for Chinese APT groups?

You need a structured knowledge cell for Chinese APT groups when planning cyber defense or conducting threat research. It provides a concise executive summary and actor tables to quickly inform threat modeling and reporting workflows.