China’s military modernisation since the start of the twenty-first century has been nothing short of astonishing. In little over three decades, it has built thousands of modern combat aircraft, created a fearsome arsenal of missiles, and fielded the world’s largest navy, radically changing Australia’s strategic circumstances. But amid all the discussion of air power, rocketry, and maritime power, there is a more silent but nonetheless critical element of its modernisation: China’s cyberwarfare capabilities.
In a networked world where everything from banking to missile telemetry is supported by cyberspace, capability in this domain is a critical enabler for all other kinds of national power. Moreover, cyber operations are the only kinds of attacks from which Australia’s geography provides no natural defence.
China’s cyber capabilities are sophisticated and bolstered by an interesting combination of state-employed hackers and civilian researchers. The former are contracted by the government. The latter openly participate in international “bug bounty” programs (which reward ethical hackers for finding and reporting security vulnerabilities in an organisation's systems) and identify “zero-day vulnerabilities” for foreign companies including Google and Microsoft.
Civilian researchers hone their skills by supporting international corporations: between 2017 and 2023, 27% of vulnerabilities submitted to bug bounty program run by Apple, Google Android, and Microsoft came from Chinese researchers. Until 2018, these researchers also participated and excelled in international hacking contests such as Pwn2Own in Vancouver. China established a domestic version of this competition, the Tianfu Cup, held in Chengdu.
This allows China to produce elite researchers who can test their skills in a competitive environment while also ensuring a tight grasp on the research and the researchers. In 2021, China implemented legislation which requires researchers to inform the government of any security vulnerabilities they find within 48 hours of discovery. The government is under no obligation to reveal these vulnerabilities and so has effectively created a stockpile of exploits which could be used in any number of cyber operations.
This is a robust pipeline, enabling world-leading research into cyber operations while ensuring that the primary beneficiary of such research is the Chinese government.
The People’s Liberation Army Cyberspace Force (CSF), which has only existed in its current form since April 2024, occupies an interesting place in this ecosystem. The CSF conducts cyber espionage and targeting and attack functions, mainly against military targets rather than civilian ones. It appears that responsibility for cyber operations against civilian targets is more the purview of intelligence organisations such as the Ministry of State Security and the Ministry of Public Security, including the curious public-private partnership it has struck with Chinese cyber researchers.