GEOPOLITICAL THREAT INTELLIGENCE

Geopolitical Cyber Operations & APTs

A comparative intelligence overview of nation-state military and foreign intelligence cyber commands, documenting their strategic doctrines, signature tradecraft, and primary-sourced campaign records.

Key Facts

  • Comparative threat intelligence directory mapping geopolitical cyber operations to military intelligence commands.
  • Contrasts distinct strategic doctrines: Chinese pre-positioning vs. Russian sabotage vs. North Korean revenue theft.
  • Cross-references federal grand jury indictments, Five Eyes advisories, and OFAC sanctions designations.
  • Analyzes tactical evolution toward living-off-the-land commands and residential proxy networks.

People's Republic of China (MSS & PLA)

State Command
Intelligence Org: Ministry of State Security (MSS) & PLA Strategic Support Force
Attributed APT Clusters: Volt Typhoon, Salt Typhoon, APT41 (Barium), APT10 (Stone Panda), Flax Typhoon
Geopolitical Doctrine & Goals:

Long-term critical infrastructure pre-positioning, commercial telecommunications wiretap access, intellectual property theft, and defense supply chain exfiltration.

Signature Tradecraft:

Pioneered living-off-the-land techniques (zero malware artifacts), residential SOHO router botnet proxies (KV-botnet), edge VPN exploitation, and passive telco switching packet interception.

Documented Primary Case Dossiers:

Russian Federation (GRU, SVR & FSB)

State Command
Intelligence Org: Main Intelligence Directorate (GRU Units 74455 & 26165), Foreign Intelligence Service (SVR), FSB (Center 16/18)
Attributed APT Clusters: Sandworm (Seashell Blizzard), Cozy Bear (APT29 / Midnight Blizzard), Fancy Bear (APT28), Turla
Geopolitical Doctrine & Goals:

Military sabotage, power grid disruption, election interference, diplomatic espionage, and cloud identity infiltration.

Signature Tradecraft:

Destructive MBR wipers (NotPetya, AcidRain, KillDisk), sophisticated build pipeline supply chain backdoors (SUNBURST), and token-replay cloud tenant abuse.

Documented Primary Case Dossiers:

Democratic People's Republic of Korea (RGB)

State Command
Intelligence Org: Reconnaissance General Bureau (RGB Lab 110 & Unit 121)
Attributed APT Clusters: Lazarus Group (Hidden Cobra), Kimsuky, Andariel, BlueNoroff
Geopolitical Doctrine & Goals:

State revenue generation via cryptocurrency theft, banking SWIFT manipulation, defense espionage, and retaliatory extortion.

Signature Tradecraft:

Multi-billion dollar smart contract exploits, trojanized cryptocurrency developer software (3CX, JumpCloud), social engineering via LinkedIn job lures, and custom multi-stage loaders.

Documented Primary Case Dossiers:

Islamic Republic of Iran (IRGC & MOIS)

State Command
Intelligence Org: Islamic Revolutionary Guard Corps (IRGC) & Ministry of Intelligence and Security (MOIS)
Attributed APT Clusters: Cotton Sandstorm, Charming Kitten (APT35), MuddyWater, Agrius
Geopolitical Doctrine & Goals:

Regional proxy support, psychological influence operations, critical infrastructure disruption, and retaliatory pseudo-ransomware.

Signature Tradecraft:

Fast-moving exploitation of public 1-day edge vulnerabilities, pseudo-ransomware wiping, hack-and-leak influence operations, and spear-phishing over WhatsApp.

Documented Primary Case Dossiers: