Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue alert about China state-sponsored cyber attacks

Security

NCSC and partners issue alert about China state-sponsored cyber attacks

The UK and international allies have issued a new alert which shines a light on how China state-sponsored actors have evolved their techniques for launching cyber attacks.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The National Cyber Security Centre – a part of GCHQ – has issued an advisory alongside partners in Australia, the US, Canada, New Zealand, Germany, the Republic of Korea and Japan, focusing on how one China state-sponsored cyber actor has carried out attacks against Australian networks.

Advertisement
ODU RT

The threat group APT40 has embraced the trend of exploiting vulnerable small-office and home-office (SoHo) devices as a launching pad for attacks. These devices are softer targets when they are not running the latest software, or are no longer supported with security updates and they more easily conceal malicious traffic.

Two technical case studies showing how these techniques are deployed have been shared to help network defenders identify this malicious activity, which is also used regularly worldwide – including by other China state-sponsored actors.

The UK has previously attributed APT40 as being part of the Chinese Ministry of State Security. Defenders are encouraged to follow the latest advice to help detect and mitigate the malicious activity.

Advertisement
Security & Policing Rectangle

The publication of this advisory follows a warning made by the Director of GCHQ in May about the “genuine and increasing cyber risk to the UK” posed by China.   

The advisory, titled 'PRC MSS tradecraft in action', has been co-sealed by the NCSC, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the US National Security Agency (NSA), the US Federal Bureau of Investigation (FBI), the Canadian Cyber Security Centre (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), the German Federal Intelligence Service (BND), the Republic of Korea’s National Intelligence Service (NIS) and NIS’ National Cyber Security Center, and Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and National Police Agency (NPA).

It can be read on the ACSC website.

Advertisement
ECS leaderboard banner
Respect the Range access rules strengthen UK Defence

Defence Security

Respect the Range access rules strengthen UK Defence

5 March 2026

The Ministry of Defence (MoD) is reminding the public to follow safe access rules when visiting military training areas, to keep everyone safe and avoid disrupting training.

Cambridge Pixel set to introduce HPx-700

Aerospace Defence Security

Cambridge Pixel set to introduce HPx-700

4 March 2026

Cambridge Pixel has revealed that it will be introducing its new HPx-700, an ARM-based embedded Radar Input & Signal Processor, with the advanced radar system solution becoming available from next month.

Kahootz expands into Japan to enhance cybersecurity

Security Events

Kahootz expands into Japan to enhance cybersecurity

4 March 2026

As the UK and Japan draw closer as partners to strengthen collective security, Kahootz is expanding its presence into Japan to support UK-Japan collaboration and to provide the necessary software to protect against malign actors looking to attack a partner nation.

Viasat and Galaxy 1 to enhance Velaris

Aerospace Security Space

Viasat and Galaxy 1 to enhance Velaris

3 March 2026

Galaxy 1 Communications is working with Viasat to enhance delivery of Velaris, Viasat’s dedicated satellite communications service for Uncrewed Aerial Vehicles (UAVs) and Advanced Air Mobility (AAM) aircraft.

Advertisement
PTC rectangle
Cyacomb introduces Similarity Matching

Security

Cyacomb introduces Similarity Matching

3 March 2026

Edinburgh based digital triage experts, Cyacomb, today announced the availability of a new Similarity Matching capability within its Examiner Plus platform, enabling law enforcement to identify Child Sexual Abuse Material (CSAM) on mobile devices in minutes, even when images have been shared via messaging applications and altered from their ...

Atos UK&I launches Sovereign MXDR

Security

Atos UK&I launches Sovereign MXDR

2 March 2026

Atos, a specialist in AI-powered digital transformation, today launched a Sovereign Managed eXtended Detection and Response (MXDR) service specifically designed for UK government, critical infrastructure, financial services and other UK organisations requiring stringent data sovereignty and regulatory compliance.

Advertisement
ODU RT
Advertisement
ECS leaderboard banner