Geopolitical Cyber Operations & APTs
A comparative intelligence overview of nation-state military and foreign intelligence cyber commands, documenting their strategic doctrines, signature tradecraft, and primary-sourced campaign records.
Key Facts
- Comparative threat intelligence directory mapping geopolitical cyber operations to military intelligence commands.
- Contrasts distinct strategic doctrines: Chinese pre-positioning vs. Russian sabotage vs. North Korean revenue theft.
- Cross-references federal grand jury indictments, Five Eyes advisories, and OFAC sanctions designations.
- Analyzes tactical evolution toward living-off-the-land commands and residential proxy networks.
People's Republic of China (MSS & PLA)
State CommandLong-term critical infrastructure pre-positioning, commercial telecommunications wiretap access, intellectual property theft, and defense supply chain exfiltration.
Pioneered living-off-the-land techniques (zero malware artifacts), residential SOHO router botnet proxies (KV-botnet), edge VPN exploitation, and passive telco switching packet interception.
Russian Federation (GRU, SVR & FSB)
State CommandMilitary sabotage, power grid disruption, election interference, diplomatic espionage, and cloud identity infiltration.
Destructive MBR wipers (NotPetya, AcidRain, KillDisk), sophisticated build pipeline supply chain backdoors (SUNBURST), and token-replay cloud tenant abuse.
Democratic People's Republic of Korea (RGB)
State CommandState revenue generation via cryptocurrency theft, banking SWIFT manipulation, defense espionage, and retaliatory extortion.
Multi-billion dollar smart contract exploits, trojanized cryptocurrency developer software (3CX, JumpCloud), social engineering via LinkedIn job lures, and custom multi-stage loaders.
Islamic Republic of Iran (IRGC & MOIS)
State CommandRegional proxy support, psychological influence operations, critical infrastructure disruption, and retaliatory pseudo-ransomware.
Fast-moving exploitation of public 1-day edge vulnerabilities, pseudo-ransomware wiping, hack-and-leak influence operations, and spear-phishing over WhatsApp.