From Vegas to Chengdu: Hacking Contests, Bug Bounties, and China’s Offensive Cyber Ecosystem

From Vegas to Chengdu: Hacking Contests, Bug Bounties, and China’s Offensive Cyber Ecosystem

Author(s): Eugenio Benincasa
Editor(s): Stefan Soesanto
Series: CSS Cyberdefense Reports
Publisher(s): Center for Security Studies (CSS), ETH Zürich
Publication Year: 2024

Reports and information disclosures by threat intelligence providers, government agencies, think tanks, and online hacktivists have exposed China’s elaborate multifaceted “hack-for-hire” ecosystem that is unlike anything we have ever seen before. The system grants Chinese security agencies exclusive access to zero-day vulnerabilities identified by China’s top civilian hackers, and allows Beijing to subsequently outsource its espionage and offensive cyber operations to private contractors. This CSS cyber defense report will look at how the Chinese cyber offensive ecosystem thrives through varying degrees of state involvement with civilian hackers by examining their participation in prominent hacking competitions and bug bounty programs.
JavaScript has been disabled in your browser