The Czech has officially blamed Chinese hackers APT31 for a series of targeted cyberattacks that hit both the Ministry of Foreign Affairs and critical infrastructure in the country.

According to an official statement, the malicious activity began in 2022 and targeted an organization that had been designated as “ critical infrastructure .” The Chinese cyberespionage group APT31, which has been linked to the Ministry of State Security of the People’s Republic of China , is allegedly behind the attack .
"The government of the Czech Republic condemns this malicious campaign against its critical infrastructure. These are actions that undermine China's credibility and are in complete contradiction with its public commitments to responsible behavior on the internet," the Czech government said.
See also: Chinese hackers exploit Trimble Cityworks vulnerability
Reactions from the EU and NATO
The incident did not go unnoticed by the international community. EU member states and NATO unanimously condemned the attack, calling on China to respect international law and align with UN rules on cybersecurity.
This specific complaint comes a few months after Finnish authorities confirmed that Chinese hackers APT31 were behind the leak of email accounts of members of the Finnish parliament (in 2021) .
A global pattern
APT31, along with other groups such as APT 40 , have been repeatedly blamed for global-scale attacks . In 2021 , the US and its allies blamed China for a massive campaign to compromise Microsoft Exchange servers , affecting over 250,000 systems in dozens of countries .
In a statement, the Council of the European Union said: “In recent years, we have observed increased malicious attack activity from Chinese cyberspace, targeting EU Member States. In 2021, we called on the Chinese authorities to take action to limit such attacks from their territory.”
See also: Chinese hackers target Saudi organization with MarsSnake Backdoor
Charges against APT31
The hacking group APT31, also known as Zirconium or Judgment Panda, is closely linked to the Chinese Ministry of State Security (MSS) and has a long history of espionage operations. It is responsible, among other things, for the theft and release of the EpMe NSA exploit, before it was leaked by the Shadow Brokers in 2017.

Microsoft documented APT31 attacks targeting high-profile individuals during Joe Biden's presidential campaign four years ago. At the same time, Google reported phishing attacks targeting personal email accounts of campaign staffers during the same period.
Sanctions and international reactions
In March, the Office of Foreign Assets Control (OFAC) sanctioned two APT31 executives — Zhao Guangzong and Ni Gaobin — for their work with Wuhan XRZ, a front company used by the Chinese MSS to attack critical U.S. infrastructure. Additionally, the U.S. Department of Justice charged the two hackers, along with five others, with participating in Wuhan XRZ’s operations for at least 14 years.
See also: Chinese hackers hit the drone sector
The United Kingdom has also imposed sanctions on the group, following attacks targeting MPs, the GCHQ intelligence agency and the country's Electoral Commission systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Now, the US State Department is offering up to $10 million in rewards for information leading to the identification or arrest of Chinese hackers linked to APT31 and Wuhan XRZ.
Chinese hackers pose a significant threat to organizations and governments around the world with highly adaptive techniques and use of advanced tools. To protect against these attacks, it is important for organizations to regularly update their systems, implement strong cybersecurity measures , and educate employees on security best practices.
In addition, governments must take steps to strengthen cyber defenses and work with other nations to combat this growing threat. It is vital that we remain vigilant to prevent attacks by Chinese hackers and protect our sensitive information.
Source: www.bleepingcomputer.com
