INVESTIGATION: Beijing is Spying on Moscow — Digital Treachery at the Heart of the Sino-Russian Axis
This is a story that deserves a long look, one that should be turned over every which way to measure exactly what
- This is a story that deserves a long look, one that should be turned over every which way to measure exactly what
- Introduction: The Backstabbing Ally
- A Partnership Without Limits, a Rivalry Without Scruples
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: The Backstabbing Ally
A Partnership Without Limits, a Rivalry Without Scruples
This is a story that deserves a long look, one that should be turned over every which way to measure exactly what it reveals about the profound nature of authoritarian power. Since May 2022, just weeks after Vladimir Putin launched his full-scale invasion of Ukraine, Chinese government-linked hacking groups have methodically penetrated the computer systems of Russian government agencies and Moscow's defense corporations. Not once, not twice. Repeatedly, persistently, calculatedly. This is what an investigation published by The New York Times on June 19, 2025 reveals, corroborated by analysts from numerous cybersecurity firms and confirmed in its broad strokes by the US-China Economic and Security Review Commission as early as June 17.
What this story says about the "friendship without limits" proclaimed by Xi Jinping and Putin during their February 2022 summit — just days before the invasion — is brutal in its clarity: this friendship is a diplomatic lie, a veil cast over a technological extraction rivalry of rare intensity. Beijing is using Moscow as a laboratory. While Russian soldiers die in the trenches of Ukraine, while the Russian army tests its weapons, drones, and tactics against Western systems supplied to Kyiv, Chinese intelligence services are collecting every piece of available data — sometimes with Moscow's forced complicity, often behind its back and against its will.
The Timeline of Treachery: May 2022, the Tipping Point
The first signals of Chinese intrusions into Russian networks were detected as early as May 2022, barely three months after the start of the full-scale invasion. This precociousness is telling: Beijing did not wait for the war to stabilize before launching its collection operations. It immediately understood that the initial chaos of a high-intensity war creates unique windows of opportunity — overloaded systems, relaxed security protocols, and counter-espionage resources concentrated on other priorities.
These operations never stopped. They continued while Xi Jinping and Putin met more than forty times since the start of the invasion, during public declarations of unity, during SCO summits, and during joint military parades. The facade of friendship has never publicly cracked — and that is precisely what makes this story so chilling. The double game lasted for years before being brought to light.
Operation Entente-4: When the FSB Names Its Enemy
The Document That Changes Everything
At the heart of this affair is an eight-page document, internal FSB planning note — the Russian domestic counter-intelligence service — obtained by The New York Times and authenticated by six Western intelligence agencies. This document, likely written between late 2023 and early 2024, is an extraordinary piece of evidence. It establishes in unequivocal terms that Russia has created a counter-intelligence program specifically devoted to the Chinese threat: Operation Entente-4. The name itself is a biting irony — "Entente," as if Moscow wanted to recall the alliances of the First World War while internally acknowledging that the current alliance is illusory.
What is remarkable in this document is its vocabulary. The FSB does not speak of a "strategic partner" when referring to China. It does not speak of an "ally" or a "friendly country." It uses the word "enemy" — "vrag" in Russian. It is the same word Moscow uses to designate Ukraine, NATO, and the United States. The note describes a "tense and dynamically developing" intelligence struggle between the two countries that publicly present themselves as brothers-in-arms. The FSB orders its agents to monitor users of WeChat, the Chinese messaging app, to infiltrate the phones of espionage suspects, and to continuously accumulate data on Russian citizens in contact with Chinese entities.
Entente-4: The Code Name Hiding an Admission
The choice of the name Entente-4 deserves particular attention. "Entente" refers to the alliances of the First World War — those fragile coalitions that collapsed under the weight of conflicting interests. Numbering this program "4" suggests that three others might exist, targeting other theoretically friendly powers. The FSB, in its bureaucratic neurosis as much as its operational rigor, created this program just three days before the start of the full-scale invasion — as if Moscow knew from the beginning that the war would make Russia vulnerable to espionage from its own declared allies.
According to information reported by Euromaidan Press, the FSB document was obtained by a cybercrime group called Ares Leaks, although the way this group accessed the file was not disclosed. What is remarkable is that six Western intelligence agencies have authenticated the document as credible — which gives it considerable evidentiary value. This is not Ukrainian or anti-Chinese propaganda. It is an authentic Russian document that says what Moscow has never wanted to admit publicly.
The Ghost Groups: Sanyo, Mustang Panda, and the Shadow Armies
Code Names Hiding State Operations
Cybersecurity firms tracking these intrusions have identified several groups linked to the Chinese government. One of them, dubbed Sanyo by researchers, was particularly active in 2023. According to TeamT5, a Taiwanese cybersecurity organization that discovered and documented the intrusion, Sanyo impersonated the email address of a major Russian engineering firm with the goal of obtaining information on nuclear submarines. This is a classic spear-phishing technique carried to a level of sophistication that only a state can fund. TeamT5 attributed this activity to the Chinese state with a high level of certainty.
Another group, Mustang Panda, identified by the U.S. Department of Justice as one of the primary tools for the Chinese state's political and economic intelligence collection, was spotted actively probing Russian systems, according to Rafe Pilling, director of threat intelligence at the security firm Sophos. "The targeting we've observed tends toward political and military intelligence collection," he told The New York Times. Mustang Panda had already been implicated by the U.S. DOJ in January for infiltrating more than 4,200 computers across the United States, Europe, Asia, and Chinese dissident groups.
The Genealogy of Intruders: From 2022 to Today
Recorded Future's Insikt Group had already documented Chinese cyber-espionage operations targeting Russia as early as 2022. At the time, the Tonto Team (also known as CactusPete, Karma Panda, or BRONZE HUNTLEY), Twisted Panda, and Curious Gorge groups were active against Russian government institutions and state organizations. SentinelOne corroborated these activities. These groups foreshadowed the more sophisticated operations documented later.
What the chronological progression of these intrusions reveals is a methodical increase in power. The 2022 operations were relatively opportunistic — exploiting post-invasion confusion. Those of 2023, such as the Sanyo operation targeting nuclear submarine data, testify to increased sophistication and target specificity. You don't target nuclear submarine data by accident. It is a priority assigned at the highest level of the Chinese state.
What Beijing is Really Looking For: The 21st Century War Manual
Ukraine as an Involuntary Military Laboratory
Why is China taking this considerable diplomatic risk of spying on its declared partner? The answer is both simple and staggering. the Chinese military suffers from a glaring lack of real combat experience. China has not fought a large-scale conventional war since 1979, during its brief and humiliating border conflict with Vietnam. Since then, the People's Liberation Army has modernized at spectacular speed — but on paper. It has hypersonic missiles, aircraft carriers, and advanced drones. But it has never confronted its doctrines with the reality of trenches, HIMARS missiles, FPV drones, or Western-made electronic warfare systems.
Ukraine therefore represents for Beijing what no military exercise can replace: a real-time conflict between a Russian army equipped with modernized Soviet hardware and Ukrainian forces backed by the best NATO technologies. According to Che Chang, a researcher at TeamT5, "China is likely seeking to collect intelligence on Russia's actions, including its military efforts in Ukraine, its defense advances, and its other geopolitical strategies." Western experts add that Beijing wants to understand how Western weapons perform against a Russian-equipped adversary — valuable information if Taiwan ever becomes the next theater of conflict.
The PLA Facing the Wall of Inexperience: A Strategic Vulnerability
Chinese generals know it better than anyone: an army that hasn't fought in decades is an army whose doctrines rely on untested hypotheses. The People's Liberation Army (PLA) has seen meteoric modernization — multiplied budgets, renewed equipment, rewritten doctrines — but without ever facing an enemy capable of resisting. Russia, meanwhile, is learning in blood and ruins these lessons that Beijing cannot afford to ignore.
Military experts have noted that Chinese officers complain internally about this combat experience deficit. The war in Ukraine offers an unparalleled mine of information: how FPV drones saturate defenses, how HIMARS missiles destroy logistics depots, how electronic warfare disrupts communications, and how integrated anti-aircraft systems resist massive strikes. Every battle in Ukraine is a lesson from which Beijing extracts the substance for its Taiwan scenarios.
Drone Technology: The Most Coveted Bounty
Tomorrow’s War is Being Played Out Today in Ukraine
Discover
INVESTIGATION: Epstein a Foreign Agent? The Letter That Moves…
On July 21, 2026 , Jamie Raskin, Ranking Member of the…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
Among the most actively sought-after information by Chinese cyberspies is data on drone technology and guidance software. This is no coincidence. The war in Ukraine has revealed that drones — from small $500 FPV devices to long-range Shahed or Lancet-type drones — have transformed contemporary military doctrine. Russia and Ukraine now operate in an environment where drone superiority can compensate for considerable human or material deficits. These lessons interest Beijing to the highest degree, particularly in the prospect of a potential conflict around Taiwan.
The Council on Foreign Relations documented in July 2025 that Ukrainian officials found an overwhelming proportion of components made in China in Russian drones captured on the front — notably in a Russian V2U drone dismantled near Sumy, which contained a Chinese Leetop A203 minicomputer, Chinese motors and servos, solid-state hard drives, and rangefinders of Chinese origin. Cruel irony: China simultaneously supplies the components to the Russians and spies on the results of their combat use. It is a double game of formidable efficiency — and absolute cynicism.
The War of Software and Embedded Artificial Intelligence
Beyond physical components, Chinese hackers also target the guidance software and embedded artificial intelligence algorithms in Russian weapons systems and in drones captured on the Ukrainian front. The Russian V2U drone dismantled by Ukrainian services apparently used artificial intelligence to select its targets autonomously — a capability that Beijing seeks to study and eventually surpass in its own developments.
This software dimension is perhaps even more important than the data on conventional weapons. autonomous decision-making algorithms in a combat context represent the frontier of the war of the future. An army that understands how opposing algorithms work can develop specific countermeasures, decoys, and jammers. Chinese cyber espionage is not just looking to copy — it is looking to surpass. And in the 21st-century arms race, information is often more precious than metal.
Moscow's Silence: A Strategic Capitulation
Why Putin Cannot Complain
What makes this situation particularly extraordinary is Moscow's official silence. Despite the accumulated evidence of Chinese espionage, despite the Entente-4 program, and despite the internal FSB notes that treat China as an enemy, Vladimir Putin continues to publicly celebrate Sino-Russian friendship. In June 2025, during a phone call after the G7 summit, Xi and Putin agreed to meet in person in August and September, boasting about the state of their relations. Russian Defense Minister Andrei Belousov praised relations with China as being "at an unprecedented level."
The reason for this silence is obvious and painful for Moscow: Russia is economically and technologically dependent on China to a degree it would never have accepted before 2022. Western sanctions have closed Russian access to financial markets, semiconductors, and advanced industrial equipment. China has filled this void with electronics exports, purchases of discounted Russian hydrocarbons, and diplomatic cover at the UN. According to the Council on Foreign Relations, bilateral Sino-Russian trade has increased by 66.7% since 2021. Putin cannot afford to bite the hand that feeds him — even if that hand is simultaneously stealing his most sensitive military secrets.
Technological Dependency: A Trap Closed on Itself
Russian dependence on China extends far beyond hydrocarbons. Studies conducted by Ukrainian and Western researchers have revealed that components Chinese-made components represented as much as 80% of those found in Russian drones by early 2025. This electronic dependency means that any halt in Chinese exports would paralyze a significant part of Russian military production capacity. Beijing knows it. Moscow knows it. And this equation gives China considerable leverage.
Worse still for Moscow: according to the Council on Foreign Relations, an investigation conducted by the Kyiv Independent into the Russian Votkinsk missile plant — which produces Iskander-M ballistic missiles as well as intercontinental missiles — revealed that Russia had imported over $11 million in mostly Chinese machinery. This plant is on the international blacklist due to sanctions. China bypasses these sanctions to keep the Russian war effort on life support — and in doing so, it ensures privileged access to Moscow's greatest military industrial secrets.
The Doctrine of "Active Neutrality": A Smoke Screen
What Beijing Says vs. What Beijing Does
Officially, China presents itself as a neutral actor seeking to facilitate peace in Ukraine. In June 2025, the Chinese Foreign Ministry spokesperson stated several times that Beijing was not providing weapons to Russia and was playing a "constructive role" in resolving the conflict. In June 2025, China even appointed a new special representative for Eurasian Affairs, Sun Linjiang, replacing Li Hui, whose mediation had been deemed insufficient. This facade diplomacy maintains the illusion of a responsible China.
But the facts reported by Ukrainian intelligence, cybersecurity firms, and the FSB document paint a radically different portrait. According to the spokesperson for the Main Directorate of Intelligence of Ukraine (HUR), Oleh Aleksandrov, China provides Russia with extensive support for drone production, carefully navigating between export controls and sanctions. Ukraine has asked its Western partners to put more pressure on Beijing during the June 2025 NATO summit, where Zelensky himself claimed that Chinese companies were helping Russia continue its war. NATO Secretary General Mark Rutte echoed these concerns a day later.
The Chinese Response: Denials and Calibrated Counter-Accusations
Faced with every accusation, Beijing has responded with a proven mechanism: total denial, counter-accusations of Western escalation, and the invocation of its own good faith. Lin Jian, spokesperson for the Chinese Foreign Ministry, stated he was unaware of The New York Times' revelations about Chinese hackers targeting Russia. It is the minimal diplomatic response, calculated not to escalate while acknowledging nothing.
This communication strategy is itself revealing. Beijing never disputes technical facts with alternative evidence — because it cannot. It merely denies everything globally, labels the accusations "irresponsible," and recalls its position as a peace mediator. This posture works because the burden of proof in cyber espionage is extremely difficult to establish irrefutably before international public opinion. Ambiguity is a strategic tool for Beijing, and it uses it with consummate mastery.
The Axis of Autocracy: An Alliance of Convenience, Not Conviction
What the USCC Understood Before Everyone Else
The 2025 annual report of the US-China Economic and Security Review Commission (USCC) — the primary U.S. Congressional body responsible for analyzing Sino-American economic and security relations — identifies China as "the decisive enabler" of a revisionist axis including Russia, Iran, and North Korea. But the same report emphasizes that this "axis of autocracy" is not a NATO-style alliance based on trust and shared values. It is a transactional partnership based on a common adversary: the United States and the democratic West.
This distinction is vital for understanding Chinese espionage operations against Russia. Beijing is not Moscow's ally — it is its boss and predator simultaneously. China buys Russian oil at fire-sale prices, supplies electronic components essential to the Russian war effort, and blocks anti-Russian resolutions at the UN Security Council. In exchange, it discreetly extracts the most valuable Russian military secrets. It is a profoundly asymmetrical exchange, and Moscow is in no position to refuse it. The USCC emphasized on June 17, 2025, in its follow-up update on the Chinese position regarding the Russian invasion, that these Beijing-linked hacking groups have repeatedly targeted Russian government agencies and defense corporations to obtain information on the weapons and tactics deployed in Ukraine.
What the U.S. Congress Understood: The USCC as a Watchtower
The USCC — created by the U.S. Congress in 2000 to monitor and analyze the security and economic implications of Sino-American relations — plays a crucial role by putting into writing what diplomatic chancelleries often prefer to keep quiet. Its 2025 annual report, adopted unanimously by the 12 commissioners appointed by both Republicans and Democrats, is the clearest signal that le consensus bipartisan sur la menace chinoise est maintenant total in Washington.
What the USCC documents goes beyond operations against Russia alone. The 2025 report describes a China has fundamentally changed its strategic nature: it no longer seeks to integrate into the existing world order; it seeks to reshape it in its favor. This revisionist ambition — parallel to Russia's in Eastern Europe — justifies a systemic response from the West, not just ad hoc responses to specific incidents. Espionage against Russian systems is only one piece of a much larger and more disturbing geopolitical picture.
TeamT5 and the Researchers Who Dared to Name China
Cybersecurity as a Tool for Geopolitical Truth
On the same topic
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
TeamT5, the Taiwanese cybersecurity firm that discovered and documented the Sanyo group's operation targeting Russian nuclear submarine data, embodies an important trend in the global cybersecurity community: the growing willingness to publicly attribute cyberattacks to states, including China. For a long time, private firms hesitated to point directly at Beijing, fearing economic or diplomatic reprisals. TeamT5, based in Taiwan — which lives daily under the threat of a Chinese invasion — does not have that luxury of caution.
The combination of reports from firms like TeamT5, Sophos, Recorded Future, and SentinelOne now creates a coherent and troubling overall picture. Recorded Future's Insikt Group had already documented as early as 2022 that several Chinese groups — RedDelta, Curious Gorge, Tonto Team — had conducted cyber-espionage operations targeting Russia after the invasion of Ukraine. These activities have intensified and become more sophisticated since. CSIS (Center for Strategic and International Studies) maintains a database of significant cyber incidents documenting the inexorable progression of these operations.
The Difficult Task of Attribution: Between Certainty and Limits
Attributing a cyberattack to a state is a technically complex and politically sensitive exercise. State hackers use sophisticated techniques to blur their tracks — bounce infrastructure, open-source tools, imitating the methods of other groups. This is why the work of firms like TeamT5 and Recorded Future is so valuable: they combine technical analysis of malware, the study of used infrastructures, and correlation with known activities of state actors to build solid attributions.
In the case of Chinese operations against Russia, the body of evidence is exceptionally robust. It combines technical analyses from several independent firms, an internal FSB document authenticated by six Western agencies, cross-corroborations between reports published over several years, and the consistency of targets with Beijing's confirmed strategic interests. It is not a debate over evidence — it is a factual observation that only awaits political will to be fully addressed.
The Arctic Peril and Silent Territorial Revisionism
Beyond Cyber: China's Territorial Ambition
Chinese espionage against Russia is not limited to military data linked to Ukraine. The FSB document reveals a deeper and older concern: Beijing's territorial ambitions over areas that Russia considers its own. The internal FSB note warns of Chinese academic efforts aimed at finding "ancient Chinese peoples" in the Russian Far East, and spreading revisionist narratives about the history of these territories. A 2023 memo mentions that a Chinese map labeled Russian zones with historical Chinese names — a subtle but geopotilitically charged gesture.
FSB agents are instructed to investigate these activities and restrict access to the foreigners involved. The note also highlights Beijing's growing interest in the Northern Sea Route and Russian Arctic development, with espionage operations conducted under the cover of mining companies and academic research institutions. This is a long-term card Beijing is playing: if Russia emerges weakened from the war in Ukraine, its vast Asian territories could one day be the subject of renewed Chinese claims. The history of the 19th-century unequal treaties has never been digested by Beijing, and Moscow knows it.
Researchers, Maps, and Narratives: Academic Espionage
The FSB document describes a dimension of Chinese espionage that is rarely discussed: the use of academic institutions and mining companies as cover for intelligence operations. Chinese researchers studying Siberian geology, mining companies obtaining contracts in the Russian Far East, doctoral students conducting research stays in Russian universities near sensitive installations — all vectors allowing for the discrete collection of strategic information.
The FSB believes this academic approach is particularly effective because it exploits the openness reflexes of scientific institutions. A low-paid, frustrated Russian nuclear physicist is a vulnerable target for a Chinese agent presenting as an academic colleague wishing to collaborate. The FSB has issued specific directives for its agents to meet face-to-face with Russian citizens in contact with Chinese entities and warn them about Beijing's real intentions to exploit Russia and acquire its advanced scientific research.
The Ukrainian Lesson: How the West Must Respond
Not Repeating the Mistake of Complacency
Ukraine's heroic resistance to the Russian invasion has already provided the West with invaluable military lessons. It has demonstrated that technological superiority combined with the will to fight can hold a numerically superior military power in check. Zelensky, as a courageous warlord and peerless communicator, has been able to maintain Ukrainian national cohesion and Western solidarity in the face of a war of attrition designed to break both. But Ukraine has also revealed the limits of the West — notably the slowness of weapon deliveries and the hesitation to supply long-range weapons systems in the early years of the conflict.
Faced with China, the West cannot afford such hesitation. The USCC recommends the creation of a unified Economic Statecraft Agency to consolidate sanctions and export control authorities — currently scattered among the Departments of Commerce, Treasury, State, and Defense — in order to counter Beijing's systematic bypassing of restrictive Western measures. Taiwan, observing every lesson of the war in Ukraine closely, has already begun adapting its military doctrine — developing low-cost naval drones and kamikaze drones modeled on Ukrainian systems.
Taiwan Reads the Lessons of Ukraine: A Vital Adaptation
The Council on Foreign Relations documented that after the Ukrainian operation Spider's Web on June 1, 2025 — which successfully struck forty-one Russian bombers on their bases — Taiwan analyzed the implications of this operation for its own defense strategy. The finding is simple and telling: the lessons of the Ukrainian drone war are, in the words of Auterion CEO Lorenz Meier, "applicable one-for-one" to the Taiwanese situation.
Taiwan has signed an agreement with Auterion — a drone software manufacturer used in Ukraine — to deploy these systems in millions of Taiwanese drones. Taiwan's Defense Minister also announced new civil defense guidelines in case of an imminent aerial attack. These rapid adaptations testify to a strategic intelligence that the West should encourage and support at all levels — material, intelligence, and training. Because if China succeeds in invading Taiwan, it will have learned the lessons of Ukraine as much as Ukraine itself.
Volt Typhoon, Salt Typhoon: The Cyber War Against the West
Chinese Espionage Knows No Borders
If Chinese operations against Russia reveal an unexpected dimension of Beijing's strategy, we must not lose sight of the direct threat China poses to the West in cyberspace. The Volt Typhoon and Salt Typhoon campaigns — documented by U.S. intelligence agencies and their counterparts in 13 countries in a joint advisory in September 2025 — illustrate an unprecedented pre-positioning strategy in Western critical infrastructure.
Volt Typhoon is not a classic espionage operation. Its stated objective, according to the 2025 USCC report, is to pre-position malware in American water, electricity, and transportation networks in order to trigger chaos during a future crisis — particularly around Taiwan. Salt Typhoon, for its part, succeeded in infiltrating virtually all major American telecommunications companies, accessing metadata from personal communications and judicial surveillance systems. These operations demonstrate that China is simultaneously waging an espionage war against Russia and a pre-positioning war against the West — two fronts, the same strategy of informational dominance.
RedNovember, Silk Typhoon: The Permanent Expansion of Operations
Code names multiply as researchers discover new Chinese operations. RedNovember — which Recorded Future's Insikt Group linked with a high degree of certainty to the Chinese state — compromised government and intergovernmental organizations as well as U.S. defense contractors. Silk Typhoon focused on targets at the U.S. state and local government levels. The 2025 USCC annual report also notes that Linen Typhoon and Violet Typhoon exploited vulnerabilities in Microsoft's SharePoint platform, used by many government agencies.
This staggering taxonomy of Chinese groups is not just a matter of academic classification. It testifies to a plural and compartmentalized operational capacity that China has built over decades. Each group has its specialty, its preferred targets, and its own methods. Together, they form an offensive cyber ecosystem of an unparalleled scale in the world. Neither Russia, nor Iran, nor North Korea have such strategic depth in their digital arsenal. That is why China is threat number one.
China, Threat Number One: A Consensus Taking Hold
Beyond Diplomatic Euphemisms
Only a few years ago, publicly naming China as the number one threat to Western security was considered excessive or counterproductive. Today, it is no longer the viewpoint of a hawkish minority — it is the consensus emerging from U.S., British, Australian intelligence services and their partners. The Office of the Director of National Intelligence stipulates in its 2025 threat assessment that China "remains the most active and persistent cyber threat to U.S. government, private sector, and critical infrastructure networks."
The operations described in this article — targeting Russian defense agencies, Volt Typhoon, Salt Typhoon, RedNovember, Mustang Panda — are not isolated incidents. They constitute the visible manifestations of a coherent and long-term strategy of global information extraction orchestrated from Beijing. This strategy aims to comble le fossé technologique et expérientiel de l'armée chinoise, to prepare disruption capabilities against potential adversaries, and to maintain a position of informational superiority over all geopolitical actors — including its own allies. China has no allies. It has only tools.
What to Do Now: The Urgency of a Coordinated Strategy
Faced with this observation, complacency is no longer an option. The West has real assets that Beijing cannot easily reproduce: an open culture of innovation, a solid alliance capacity, a competent defense industrial base, and intelligence agencies that operate with transparency and republican accountability. But these assets only translate into strategic advantage if political will mobilizes them. The case of Chinese operations against Russia must serve as a catalyst, not an anecdote.
Concrete recommendations are well-known: strengthen critical infrastructure protection programs, impose targeted sanctions on Chinese entities that bypass export controls, support partner governments facing Chinese pressure, and massively invest in training cyber defense specialists. This is not a Cold War response. It is a response to war as it is fought today — in networks, servers, phones, and scientific laboratories. Cybersecurity is the first line of defense of the 21st century.
Conclusion: Predation at the Heart of the System
A "Friendship Without Limits" That Exists Only in Speeches
This investigation confronts us with an uncomfortable but essential truth: the world is not divided between democracies and cooperating autocracies. It is divided between powers that respect a rules-based order — imperfect, certainly, but stabilizing — and powers that instrumentalize that order for their own predatory ends. China resolutely belongs to the second category. It spies on its adversaries as it spies on its allies. It supplies the components that allow Russia to bomb Ukrainian civilians, and simultaneously it steals performance data from those same weapons. It presents the face of a peaceful mediator at the UN while its hacker groups pierce Moscow's digital defenses.
The Urgency of a Coherent Western Response
Ukraine resists. Zelensky holds on. NATO grows stronger. These signals are encouraging. But they are not enough against a power that operates on time horizons of decades. The West must unambiguously recognize China's predatory nature — not to trigger a new full-scale Cold War, but to calibrate its response to the level of the real threat. This means strengthening the cybersecurity of critical infrastructure, tightening export controls on sensitive technologies, unfailingly supporting Ukraine on the ground, and building solid coalitions with Indo-Pacific allies who daily face Chinese expansionism. Beijing's predation on Moscow is not a sign of Russian weakness — it is a warning of what China would do to any state that lowers its guard.
Signed Maxime Marquette, columnist
Sources
Primary Sources
Secondary Sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). INVESTIGATION: Beijing is Spying on Moscow — Digital Treachery at the Heart of the Sino-Russian Axis. MadMax. https://mad-max.co/en/article/enquete-pekin-espionne-moscou-la-trahison-numerique-au-c-ur-de-l-axe-sino-russe-2
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.