The People's Liberation Army (PLA) is the armed force of the People's Republic of China and a state military organization under Chinese Communist Party control. In cyber and information operations contexts, the PLA is associated with offensive preparation against strategic adversaries and with the exploitation of weaknesses in network infrastructure and communications systems. Reported activity includes leveraging flaws in routers and other network devices to establish conditions for potential wartime cyber operations, as well as research into denying satellite-based communications such as Starlink over Taiwan through large-scale electronic warfare and coordinated jamming concepts. These activities align with broader PLA interests in information dominance, disruption of command-and-control, and pre-conflict shaping of the battlespace. The PLA is widely assessed as a nation-state actor whose cyber-related activity supports Chinese military and strategic objectives, particularly in scenarios involving Taiwan and regional contingency operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Meitei separatist outfit from Manipur’s Imphal Valley described as cooperating with the Myanmar military against resistance groups in Sagaing Region.
The People's Liberation Army (PLA) is leveraging common software vulnerabilities in routers and network devices to prepare for potential large-scale cyber operations, particularly in the context of geopolitical conflict with Taiwan.
The PLA is researching and simulating large-scale electronic warfare operations to jam and deny Starlink satellite internet access over Taiwan, using distributed airborne jamming nodes such as drones, balloons, or aircraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.