Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue alert about China state-sponsored cyber attacks

Security

NCSC and partners issue alert about China state-sponsored cyber attacks

The UK and international allies have issued a new alert which shines a light on how China state-sponsored actors have evolved their techniques for launching cyber attacks.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The National Cyber Security Centre – a part of GCHQ – has issued an advisory alongside partners in Australia, the US, Canada, New Zealand, Germany, the Republic of Korea and Japan, focusing on how one China state-sponsored cyber actor has carried out attacks against Australian networks.

Advertisement
ODU RT

The threat group APT40 has embraced the trend of exploiting vulnerable small-office and home-office (SoHo) devices as a launching pad for attacks. These devices are softer targets when they are not running the latest software, or are no longer supported with security updates and they more easily conceal malicious traffic.

Two technical case studies showing how these techniques are deployed have been shared to help network defenders identify this malicious activity, which is also used regularly worldwide – including by other China state-sponsored actors.

The UK has previously attributed APT40 as being part of the Chinese Ministry of State Security. Defenders are encouraged to follow the latest advice to help detect and mitigate the malicious activity.

Advertisement
ODU RT

The publication of this advisory follows a warning made by the Director of GCHQ in May about the “genuine and increasing cyber risk to the UK” posed by China.   

The advisory, titled 'PRC MSS tradecraft in action', has been co-sealed by the NCSC, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the US National Security Agency (NSA), the US Federal Bureau of Investigation (FBI), the Canadian Cyber Security Centre (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ), the German Federal Intelligence Service (BND), the Republic of Korea’s National Intelligence Service (NIS) and NIS’ National Cyber Security Center, and Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and National Police Agency (NPA).

It can be read on the ACSC website.

Advertisement
General Atomics LB
Goldilock partners with Kite for UK distribution

Defence Security

Goldilock partners with Kite for UK distribution

15 September 2025

The NATO-backed cybersecurity specialist behind physical connection controller FireBreak, Goldilock, has today announced Kite Distribution as its primary UK distributor, to help it meet growing demand for more robust and practical ways to protect critical networks in the face of persistent cyber threats.

ADS reveals 2024 value of aerospace, defence, security and space to Scotland

Aerospace Defence Security Space

ADS reveals 2024 value of aerospace, defence, security and space to Scotland

11 September 2025

The aerospace, defence, security and space sectors added £3.7 billion to Scotland’s economy in 2024, according to new data from ADS, equating to a 55% increase between 2020 and 2024.

Prison laptop project delivers beneficial returns

Security

Prison laptop project delivers beneficial returns

10 September 2025

A service allowing prisoners to use laptops in their cells is worth £35 million a year to taxpayers, as it cuts violence and helps inmates to find work upon release, a new study shows.

Defence and security sectors

Defence Security

Defence and security sectors' value to UK doubles over a decade

9 September 2025

ADS data reveals that the defence, security and resilience sectors added £26.7 billion to the UK economy last year, an increase of 93% on the same period a decade ago.

Advertisement
Leonardo
Whitetree launches CIaaS at DSEI

Aerospace Defence Security Events

Whitetree launches CIaaS at DSEI

8 September 2025

Whitetree will unveil Competitive Intelligence as a Service (CIaaS) at this year’s DSEI – a new offering designed to help defence, aerospace and critical national infrastructure suppliers gain the edge in high-stakes bids.

ADS to host over 180 companies at DSEI 2025

Defence Security Events

ADS to host over 180 companies at DSEI 2025

8 September 2025

For Defence and Security Equipment International (DSEI), ADS - the trade association for the UK’s aerospace, defence, security and space industries - is hosting 180 organisations at the ADS Pavilion.

Advertisement
ODU RT