In 2025, the US and its partners attributed Salt Typhoon, one of the most significant cyber espionage campaigns against Western telecommunications infrastructure, to multiple China-based entities, including at least three private firms. The cybersecurity advisory stated that these firms ‘provide cyber-related products and services to China’s intelligence services’; the UK NCSC said they ‘enabled’ the activity. As of mid-2026, there is still limited public information about the specific role of these three entities and their government customers in Salt Typhoon operations.
Early public attributions of Chinese cyber operations were more clear-cut. APT1’s 2014 attribution to People’s Liberation Army (PLA) Unit 61398 showed a single state entity conducting intrusions aligned with a defined mandate. The 2017 indictment of individuals linked to private-sector company Boyusec (APT3), which allegedly contracted for Ministry of State Security (MSS) entities in Guangzhou, marked an early indication of the growing complexity of Chinese state-sponsored cyber activity, while involving only one state contractor.
Salt Typhoon exemplifies how Chinese state-sponsored cyber operations now take place in an interconnected ecosystem, extended by a burgeoning private sector and complicated by networks of direction and commercial relationships. This complexity makes the monolithic ‘advanced persistent threat’ (APT) concept increasingly insufficient, demonstrating the need for a more granular frame.
A suitable framework is composite responsibility: a model of Chinese cyber activity in which a single operation or campaign may involve multiple distinct public and private sector entities, each contributing different functions, and therefore bearing different, non-equivalent responsibility. By differentiating tasking relationships and respective roles in a campaign, composite responsibility helps policymakers apply more targeted responses.
Defining tasking relationships
Three forms of tasking can be distinguished: direct (formal), indirect (commercial), and proactive action, drawing on Jason Healey’s spectrum of state responsibility.
Direct, or formal, tasking entails an institutional relationship and direct oversight. A clear example might be a PLA unit, whose activity broadly equates to its specific mandate or area of responsibility, such as RedFoxtrot’s targeting of Central and South Asia, consistent with its possible attribution to Unit 69010 in Ürümqi, Xinjiang, under the PLA’s Western Theatre Command.
Similarly, APT40, attributed to the Ministry of State Security (MSS), allegedly consists of Hainan State Security Department officers operating through a network of front companies, and focuses primarily on intelligence collection related to the South China Sea and Asia Pacific, consistent with Hainan’s geographic remit.
Indirect, or commercial, tasking involves the cascading of objectives, targets, or priorities from government entities to outside contractors.
It can involve clear direction, such as in the 2020-21 case of Xu Zewei, an individual involved with HAFNIUM, a cyberespionage group and APT. The MSS Shanghai State Security Bureau (SSSB) directed Xu to conduct specific activity. Tasking came from the SSSB via the company Xu co-founded, Shanghai Powerock Network Co. Ltd. (Powerock). Staff conducted operations as contractors and fed results back to the SSSB.
In other cases, tasking can be framed around broader intelligence requirements, including ones related to overarching strategic objectives. For example, APT41 targeted sectors aligned with China’s five-year economic development plans, while also collecting intelligence before time-sensitive developments, including mergers and acquisitions and political events.
Proactive action encompasses Chinese private-sector companies conducting compromises without prior tasking (formal or commercial), as evidenced by the indictment of staff linked to i-Soon, which has been linked to three different threat groups: RedAlpha, RedHotel, and POISON CARP. i-Soon not only conducted cyber activity under commercial tasking by the MSS or Ministry of Public Security , but also – and differently to previous contractors like APT3 or APT10 – independently compromised targets before attempting to sell access or stolen data to government customers across multiple Chinese provinces.
These distinctions carry clear implications for attribution and response. Direct PLA tasking involves a military entity, raising the escalation stakes; disrupting infrastructure attributable to a PLA unit could theoretically be characterised as an attack on military assets. However, the same action against an MSS contractor’s botnet is less likely to trigger a government response.
Commercial tasking introduces further ambiguity. Whether a government contractor’s activity produces destructive effects and whether it reflects deliberate tasking or contractor recklessness has significant implications for how a victim state should respond. Where no prior tasking is evident, direct state accountability is harder to establish; activity conducted on private initiative calls for different framing and response than a state-directed campaign.

Ascertaining roles
While early Chinese cyber operations often involved a single unit or group conducting an intrusion, more recent cases involve multiple actors contributing distinct functions to the same campaign. As with tasking, the distinction matters; identifying which role a given entity played shapes what an appropriate government or industry response, if any, looks like, and whether it should target an operator, enabler, or the state.
Private-sector entities in China have provided capabilities such as malware and tooling that have been used across multiple state-linked and contractor-led operations. The privately-developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and was shared with entities including Chengdu404, whose staff was charged for activity attributed to APT41. Therefore, responsibility for an operation may extend to the entities commercially developing and distributing malicious software, not just those deploying it.
Data brokers may also be held responsible. Indictments against two individuals linked to APT27, Yin Kecheng and Zhou Shuai, describe hacking campaigns in which stolen data was subsequently sold to multiple customers, only some of which were Chinese government entities. In some cases, data stolen by Yin was reportedly sold by Zhou through i-Soon, introducing additional layers of resale between intrusion and the end customer.
There is also evidence that the Chinese cyber operations ecosystem includes initial access brokers, who compromise targets and sell access to interested parties: public reporting and government assessments on UNC5174, for example, outline activity consistent with an MSS contractor conducting initial access operations. Cybersecurity company Trend Micro has also described the phenomenon of ‘premier pass-as-a-service’: cases where one Chinese state-sponsored threat group shares established, persistent access to a critical asset on a victim network with another Chinese threat group. This introduces a second actor at a late stage inside an already-active intrusion, further complicating attribution.
Finally, private-sector entities may also provide customers with network infrastructure to run hacking campaigns, such as the Raptor Train botnet, which the United States disrupted. Raptor Train was attributed to Chengdu-based Integrity Technology Group (Integrity Tech), which was found to be responsible for developing the botnet, and therefore, ‘at least in part, for the computer intrusion activities collectively attributed to Flax Typhoon’, and sanctioned. The UK government similarly sanctioned Integrity Tech for ‘controlling and managing a covert cyber network and providing technical assistance for others to carry out cyberattacks’, implying that Integrity Tech may not have directly conducted the intrusions.
Why composite responsibility matters
The cases above point to a model of composite responsibility in modern Chinese cyber operations, in which different entities contribute different functions, and bear different, non-equivalent responsibility for distinct components of the same campaign. Applying the composite responsibility model means, where available evidence allows, identifying the intelligence customer, tasking relationship, executor, and any enablers, and treating each as a distinct analytical and policy question.
This sharpens attribution: rather than assigning a campaign to a single APT label, it clarifies the underlying web of relationships and responsibilities. It also enables more calibrated responses, allowing policymakers to differentiate between those who direct, execute, or enable cyber operations. They can apply measures, from takedowns to diplomatic signalling to sanctions, commensurate with the role played.
Salt Typhoon is perhaps the most consequential case in point: as of early 2026, the tasking relationships and specific roles of the named firms remain publicly undescribed, leaving the question of appropriate response open. As Chinese cyber operations grow more interconnected, the frameworks used to understand and respond to them must keep pace.






