China's Ongoing Cyber-Espionage Campaign Targets U.S. Trade Policy Stakeholders

As the global trade and diplomatic landscape continues to shift, the House Select Committee on the Strategic Competition Between the U.S. and the Chinese Communist Party has issued a warning about an ongoing series of highly targeted cyber-espionage campaigns linked to the Chinese Communist Party. These campaigns seek to compromise organizations and individuals involved in U.S.-China trade policy and diplomacy, including U.S. government agencies, business organizations, law firms, think tanks, and foreign governments. The committee has identified at least one instance where cyber-attackers impersonated Chairman John Moolenaar in emails to trusted counterparts, attempting to deceive recipients and gain access to their systems and information.

Key Takeaways:

  • The House Select Committee on China has concluded that an ongoing series of cyber-espionage campaigns linked to the Chinese Communist Party are targeting U.S. trade policy stakeholders, including government agencies, business organizations, law firms, think tanks, and foreign governments.
  • The campaigns seek to compromise sensitive data, including trade and diplomacy information, in an effort to influence U.S. policy deliberations and negotiation strategies.
  • Chairman John Moolenaar has stated that the incidents are "another example of China's offensive cyber operations designed to steal American strategy and leverage it against Congress, the Administration, and the American people."
  • The committee has identified at least one instance where cyber-attackers impersonated Chairman Moolenaar in emails to trusted counterparts, attempting to deceive recipients and gain access to their systems and information.
  • Highly skilled technical analysis by the committee confirms that the perpetrators abused software and cloud services to hide their activity in attempts to steal sensitive data, a hallmark of state-sponsored tradecraft.
  • The committee believes the activity to be CCP state-backed cyber-espionage aimed at influencing U.S. policy deliberations and negotiation strategies to gain an advantage in trade and foreign policy.
  • The committee will continue to share indicators with federal partners and impacted organizations and will support any necessary defensive or investigative actions.

Statistics:

  • The committee has identified at least one instance where cyber-attackers impersonated Chairman John Moolenaar in emails to trusted counterparts.
  • The campaigns have targeted U.S. government agencies, business organizations, law firms, think tanks, and foreign governments.
  • The committee believes the activity to be CCP state-backed cyber-espionage aimed at influencing U.S. policy deliberations and negotiation strategies to gain an advantage in trade and foreign policy.
  • In recent weeks, suspected Chinese cyber-attackers have impersonated Chairman Moolenaar in emails to trusted counterparts on multiple occasions.
  • The incidents follow a January 2025 spear-phishing campaign that targeted four Select Committee staff members who were working on a confidential investigation into ZPMC, a leading Chinese state-owned enterprise and manufacturer.

Sources:

  • https://selectcommitteeontheccp.house.gov/media/press-releases/committee-statement-on-ongoing-prc-cyber-espionage-targeting-us-trade-policy-stakeholders