TechWar

Chinese Hackers Target Russia Despite Public Alliance

Share
Share

Since the start of Russia’s invasion of Ukraine, cyber-espionage groups linked to the Chinese government have ramped up attacks against Russian government institutions and strategic companies, apparently in search of military secrets. According to cybersecurity analysts, this campaign intensified around May 2022, casting doubt on the so-called “no limits” partnership between Moscow and Beijing.

These intrusions have continued even as Presidents Vladimir Putin and Xi Jinping publicly reaffirmed their strategic alliance against the West. Experts say the cyberattacks reveal China’s perception of Russia as a weakened and vulnerable target for military intelligence gathering.

Taiwan-based cybersecurity firm TeamT5 identified the Chinese group “Sanyo” as responsible for hacking a major Russian engineering firm to obtain information on nuclear submarines. Another firm, Palo Alto Networks, reported that Chinese state-sponsored hackers targeted Rostec, Russia’s defense conglomerate, seeking data on satellite communications, radar systems, and electronic warfare.

“China isn’t just after technology,” said Che Chang, a researcher at TeamT5. “They’re also trying to learn tactical lessons from the modern warfare Russia is conducting in Ukraine.”

While the Kremlin has kept silent about these attacks, a classified FSB counterintelligence document—obtained by The New York Times—confirms growing concern within Russian intelligence circles. The document warns that China is seeking Russian defense technology and battlefield expertise, even going as far as labeling China an “enemy.”

Although it is not uncommon for allies to spy on one another, the scale of China’s cyber activities against Russia suggests deeper mistrust. Analysts believe the Kremlin’s reluctance to share its full wartime insights with Beijing may have prompted the escalation of cyber intrusions.

According to the FSB document, one of China’s main interests is drone warfare—especially the software and tactical applications involved. Experts argue that such intelligence could be critical if China faces a future conflict, particularly over Taiwan.

One of the most active groups is Mustang Panda, identified by firms like Sophos and TeamT5. Known to operate in line with China’s global Belt and Road Initiative, Mustang Panda expanded its operations after the Ukraine invasion, targeting Russian and European institutions alike.

Sophos reports that Mustang Panda is likely backed by China’s Ministry of State Security, the country’s top intelligence agency. In 2022, the group allegedly targeted Russian military and border guard units near the Siberian frontier. This January, the U.S. Department of Justice formally charged Mustang Panda with stealing data from thousands of systems, including those of Chinese dissidents and foreign governments.

Other groups, such as Slime19, have also focused on Russian targets, especially in the energy and defense sectors. According to Chang, this reflects a sustained and systematic campaign that contradicts bilateral agreements made in 2009 and 2015, in which China and Russia pledged not to hack each other.

Although those agreements were presented as goodwill gestures, analysts say they were largely symbolic. “We saw an immediate spike in activity after Russia’s full-scale invasion of Ukraine,” said Itay Cohen, a researcher at Palo Alto Networks. “Despite the public narrative of strong ties between Russia and China, the reality is a far more complex and pragmatic relationship.”

Share
Related Articles
PoliticsWar

Trump to Decide Within Two Weeks Whether U.S. Will Intervene in Israel-Iran Conflict

The White House announced Thursday that President Donald Trump will decide within...

Tech

Trump Grants TikTok Another 90-Day Reprieve as Uncertainty Lingers Over Its Future

U.S. President Donald Trump has signed a new executive order granting TikTok...

Tech

Sycom launches RTX 50 graphics cards with Noctua fans: maximum performance, minimal noise, and no special collaboration

Modern graphics cards require powerful cooling systems to dissipate the heat generated...

ViralWar

An Iranian missile strikes Israel’s largest hospital

A ballistic missile launched from Iran struck directly on Thursday at the...

ViralWar

Jamenei Issues Stern Warning to U.S. Amid Escalating Iran-Israel Conflict

On the sixth day of the ongoing conflict between Iran and Israel,...

PoliticsWar

Trump Weighs U.S. Intervention in Israel-Iran Conflict

The war between Israel and Iran has emerged as the most delicate...

Tech

Nintendo Begins Wave of Bans Over Unauthorized Cartridges on the Switch 2

Less than two weeks after the official launch of the Nintendo Switch...

ViralWar

Israel Launches Massive Airstrike on Iran’s Nuclear Facilities

On Wednesday, Israel carried out one of its most extensive aerial operations...