5 min read

The Long Wire: How Beijing Builds Access That Outlasts Its Cover Stories- 297

The Long Wire: How Beijing Builds Access That Outlasts Its Cover Stories- 297

August 12, 2026

Four episodes surfaced within days of each other in August 2026, and none of them, on its own, would have drawn much attention beyond the trade press. A congressional committee found that Chinese state carriers stripped of their US operating licenses years ago never actually left American infrastructure. A Royal Navy contractor discovered a camera on an unmanned vessel quietly checking in with an address in China. A cybersecurity firm traced a malware family built to survive, almost invisibly, inside the government networks of five Central Asian states. And a university study found Chinese-made software quietly embedded in mobile applications marketed to US military personnel. Read separately, these are four unrelated stories about routers, drones, telecom licensing, and app development. Read together, they describe a single method: China's cyber posture abroad is not organized around discrete intrusions so much as around durable, structural presence — access engineered to survive discovery, regulatory action, and even public exposure, because it is built into hardware, corporate ownership, and software supply chains rather than into any single exploit.

The clearest illustration of that method is also the most institutional. The US House Select Committee on China has just published a 49-page investigation into China Mobile, China Unicom, and China Telecom — three carriers whose US telecommunications licenses were denied or revoked by the Federal Communications Commission between 2019 and 2022 over cybersecurity concerns, and whose alleged links to the Salt Typhoon intrusions into at least nine American telecom companies triggered the fresh inquiry. What the committee found is that regulatory expulsion and physical departure are not the same thing. None of the three firms is independent of parent companies with deep ties to the Chinese state; each sits at the bottom of an ownership chain running through Hong Kong and offshore holding structures to a state-owned enterprise supervised by Beijing's State-owned Assets Supervision and Administration Commission. Losing their Section 214 authorization blocked them from offering certain regulated international services, but it did not force them to remove equipment, vacate data-center space, or sever their commercial relationships with other US telecom and technology firms. Instead, the companies quietly retained hardware, interconnection agreements, and data-center footholds that the committee describes as functioning as "trusted" backdoors, then rebuilt their American business lines around network services that sit outside core licensing rules — continuing to route customer traffic globally, lease physical space inside US facilities, manage VPN infrastructure, and broker third-party network equipment. Chinese-manufactured equipment, built by firms legally obligated to cooperate with Chinese state security services on request, kept running inside US networks throughout. The committee also documents a pattern of internet-routing incidents in which US government, corporate, and domestic traffic was misdirected through PRC-controlled networks — incidents the Justice Department and other agencies concluded were, in multiple cases, deliberate rather than accidental — and it links China Unicom, specifically, to Integrity Tech and i-SOON, two sanctioned Chinese cybersecurity firms tied to state-sponsored hacking campaigns. The committee stops short of asserting that China Mobile participated directly in Salt Typhoon, but says its technical findings tie the hacking campaign to the carrier's infrastructure regardless. All three companies initially declined to cooperate with the committee's outreach, and when subpoenaed executives were eventually interviewed in September 2025, several would not confirm even having read public reporting on Salt Typhoon.

If the telecom investigation shows how state-linked access survives at the level of corporate structure, an incident aboard a Royal Navy drone boat shows how the same vulnerability can arrive by accident, through nothing more sinister than an unvetted component. A routine cyber vulnerability sweep discovered that a camera fitted to a Kraken-built Unmanned Surface Vessel was transmitting to an IP address in China. The UK Ministry of Defence, after investigating, said it found no evidence that any MoD data or systems had been accessed or compromised; the transmission amounted to a "heartbeat" signal confirming the camera was online, sourced from a third-party component supplier rather than installed by Kraken itself or by the Ministry. There is no indication here of an operation directed against the Royal Navy — the episode is, by the MoD's own account, a benign telemetry signal rather than an intrusion. Its significance lies elsewhere: a piece of military hardware, integrated through a defense contractor's supply chain, was communicating with Chinese infrastructure without anyone along that chain having flagged it before an audit caught it. It is precisely the kind of gap that state-linked collection could exploit if a genuinely malicious component were substituted for a benign one, and it lands against a backdrop of UK concern that is anything but hypothetical — the National Cyber Security Centre warned in April about covert networks built from compromised routers and edge devices, and British reporting in January tied a China-linked group to years of surveillance against the phones of aides to multiple UK prime ministers.

Where the telecom and drone-camera cases show access embedded through infrastructure and components, a campaign uncovered by Kaspersky shows what that access is built to do once it is inside a government network abroad. Since at least January 2025, a suspected Chinese-speaking threat actor — not yet tied to any named group — has run an espionage campaign against government ministries, foreign affairs departments, law enforcement agencies, and allied research and logistics institutions across Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria. The operation is built around two previously undocumented malware families, OctLurk and SilkLurk, both engineered for long, quiet dwell time rather than smash-and-grab theft. OctLurk arrives through a lightweight loader that injects the backdoor directly into memory, checks for internet connectivity, and launches a custom traffic-routing utility called LurkProxy before establishing contact with command-and-control infrastructure; from there, it pulls down plugins that execute entirely in memory, leaving minimal trace on disk while granting the operators command execution, file manipulation, screenshot capture, clipboard and keystroke monitoring, network scanning, email collection, credential dumping, and browser password theft as needed. Once inside, the operators moved methodically — exporting Windows logon events to map user activity, extracting Active Directory password hashes with the Impacket tool secretsdump.py, disguising a keylogger as the legitimate remote-access tool AnyDesk, scanning internal networks for SSH and MySQL services with the Fscan utility, and staging collected documents with WinRAR and 7-Zip ahead of exfiltration. A second malware family, SilkLurk, achieves similar access through DLL side-loading and has been observed deploying PlugX, a backdoor with a long history in Chinese state-linked espionage operations; Kaspersky also found infrastructure overlaps with an earlier campaign involving an implant called SilentRaid, though the evidence available does not yet confirm the same operators are behind both. Both malware families derive their decryption keys from device-specific identifiers such as drive serial numbers, a design choice that complicates forensic analysis and helps the backdoors persist undetected across long operational timelines — the same emphasis on durability over speed that characterizes the telecom and hardware cases.