The Deniability Architecture: How Beijing Outsourced Its Cyber Footprint- 191
June 20, 2026
China's intelligence services have spent the past several years dismantling the very thing that once made state-sponsored hacking traceable: the state's own visible hand. What FBI cyber division assistant director Brett Leatherman recently described as a hacker-for-hire ecosystem that has "gotten out of control" is not a regrettable side effect of Beijing's cyber posture — it is the posture. Across three seemingly unrelated developments of April 2026, a coherent architecture emerges, one built not around a single tool or a single actor but around the systematic transfer of operational risk away from the Ministry of State Security and onto a layered, replaceable, and commercially plausible periphery: hijacked consumer routers that erase the geography of an attack, automated criminal infrastructure that may or may not be tasked by anyone in particular, and contracting firms whose employees can be indicted as individuals while the system that employed them continues operating under a different name. The throughline is not technique. It is the engineering of deniability itself, distributed across three layers that rarely appear in the same analysis but that, together, describe how a state conducts espionage and theft at scale while remaining permanently one step removed from the evidence.
The first layer is infrastructural. A joint advisory from the NCSC, CISA, FBI, and NSA documented a decisive shift: the majority of China-nexus actors — Volt Typhoon, Flax Typhoon among them — have abandoned dedicated attacker-controlled servers in favor of vast networks of hijacked consumer devices. Routers, IP cameras, NAS systems, the unglamorous hardware sitting at the edge of millions of ordinary networks, unmonitored and rarely patched. The Raptor Train botnet, linked to the infrastructure underpinning Flax Typhoon, illustrates the scale: more than 200,000 compromised devices since 2020, peaking above 60,000 simultaneously active nodes. The agencies coined a term for the defensive consequence — IOC extinction. Indicators of compromise simply stop being useful when an operator can rotate across tens of thousands of disposable nodes before a defender finishes updating a blocklist. Volt Typhoon has used this model not for immediate exfiltration but to pre-position inside Western power, water, and telecommunications networks against a future contingency — dormant, geographically invisible, waiting.

The second layer is commercial, and its analytical significance lies precisely in what cannot be established. A SOCRadar investigation documented a separate piece of infrastructure: an automated exploitation and credential-harvesting platform built around a centralized backend called paperclip and an orchestration interface called OpenClaw, running industrial-scale missions against Web3, fintech, and AI provider environments. The operation's telemetry is striking — roughly 45,000 exploitation attempts, close to 22,000 tracked cryptocurrency addresses, hundreds of webshell implants. What the investigation does not establish, and does not claim, is a confirmed link to the Ministry of State Security. The operation reads as financially motivated criminal infrastructure, Chinese-language and China-hosted. That ambiguity is architecturally deliberate: a state that benefits from harvested credentials, stolen API keys, and compromised corporate access need not have ordered any specific operation when an entire commercial ecosystem already produces these as a byproduct of ordinary cybercrime.

The third layer is organizational, and here deniability cracked. The extradition of Xu Zewei from Italy and the unsealed Silk Typhoon indictment gave investigators something the device and infrastructure layers almost never yield: a named individual, a named employer, and a documented tasking chain. Xu operated through Shanghai Powerock Network Co., one of what prosecutors describe as numerous firms contracted by the Shanghai State Security Bureau, a regional MSS component. A co-defendant, Zhang Yu, worked through a second firm, Shanghai Firetech — at least two contracting companies, two state handlers, behind a single named hacker. Xu's attributed operations include the 2021 Hafnium mass exploitation of Microsoft Exchange zero-days and intrusions against American COVID-19 vaccine researchers. Leatherman's framing of the ecosystem as "out of control" reads less like alarm at Chinese capability and more like alarm at its diffusion: contractors motivated by profit, casting wide nets, selling what they find either to the PRC government or to whoever else will pay. Prosecuting Xu damages a node, not the network — Powerock and Firetech are two among many, and Zhang Yu remains at large.

The architecture's strength is precisely that its layers do not depend on each other. A defender who maps and neutralizes the Raptor Train botnet has done nothing to the Powerock contracting model. An indictment against a Shanghai contractor does nothing to the hundreds of thousands of compromised routers still routing traffic for actors who have never been named. The question for defenders and policymakers alike is no longer which Chinese actor is responsible for a given intrusion — it is how to impose cost on a system engineered so that question has no clean answer.