Member Login Become a Member
Advertisement

China’s Telecom Forward Base: How Military-Civil Fusion Weaponizes Global Networks

  |  
07.14.2026 at 06:00am
China’s Telecom Forward Base: How Military-Civil Fusion Weaponizes Global Networks Image

Abstract

China’s military-civil fusion (MCF) doctrine has systematically converted global telecommunications networks into a forward-operating base for the People’s Liberation Army and Ministry of State Security. By legally and technically embedding intelligence requirements into civilian carriers, edge devices, and supply chains, Beijing has achieved durable, low-and-slow access, exemplified by campaigns such as Salt Typhoon, that survives patching cycles and provides both peacetime intelligence and wartime disruption options.

Western governments and operators now face a structural asymmetry: Episodic technical fixes are insufficient against a doctrine that treats commercial infrastructure as routine intelligence preparation of the battlefield. Sustained resilience requires zero-trust segmentation, behavioral analytics, MCF-aware procurement, and multilateral cooperation before 6G deployments risk cementing the imbalance for decades.


Weaponizing Global Telecommunications Networks

In one of the most candid public assessments from a Western intelligence leader this spring, on May 27 the Director of the United Kingdom’s GCHQ, Anne Keast-Butler, warned that the West now faces a “narrowing window” to maintain superiority over China in cyber and emerging technologies, describing China as “a science and tech superpower with sophisticated capabilities across their intelligence, cyber, and military agencies.”

These remarks came just weeks after the Dutch Defense Intelligence and Security Service assessed in April that Chinese offensive cyber capabilities have reached parity with those of the United States. The report highlighted a sharp increase in campaigns targeting edge devices-routers, firewalls, and VPN concentrators – which are used by telecommunications providers worldwide. These operations, tracked in part under campaigns such as Salt Typhoon, demonstrate sustained, persistent covert access rather than one-off espionage.

What enables this persistence is not simply technical sophistication, but Beijing’s military-civil fusion (MCF) doctrine, which systematically integrates civilian telecom infrastructure, private contractors, and state-owned enterprises into People’s Liberation Army (PLA) and Ministry of State Security (MSS) requirements.

Far from a tactical tool, the MCF serves as the structural foundation that converts commercial telecom innovation into strategic capability for the PLA and the MSS. Recent PLA procurement documents reveal that China is actively seeking AI systems to fuse data from various networks, enabling faster decision-making and system-disruption operations in future conflicts.

Evidence from Public Reporting

Public reporting shows that Chinese state-sponsored actors increasingly rely on large-scale, covert networks of compromised edge devices to achieve durable access in telecommunications networks worldwide. These networks are built primarily from small office/home office routers, firewalls, VPN concentrators, and Internet of Things devices that are frequently end-of-life and lack ongoing security patches. Once inside telecommunications carrier environments, the actors use living off the land techniques, legitimate administrative tools, credential harvesting, and webshells to move laterally while minimizing detectable malware footprints.

The scope of these operations is explicitly global. Campaign tracked as Salt Typhoon/RedMike has targeted provider-edge and customer-edge routers in telecommunications infrastructure across Europe, Asia Pacific, Africa, and Latin America, including some undersea cable landing stations. They exploited vulnerabilities in backbone routers and trusted connections to pivot into other networks, often maintaining access for months or years. Some Salt Typhoon operations have maintained access for periods of 18–36 months.

Indeed, a defining feature of these campaigns is persistence. Even after vendors patching known vulnerabilities, threat actors frequently regain footholds through supply chain leverage, re-compromised devices, or abuse of legitimate remote management features. The result is low-and-slow access that survives routine maintenance cycles and provides both immediate intelligence value (communications metadata, lawful intercept interfaces) and long-term strategic optionality, underscoring that the challenge is structural rather than episodic.

For example, the Salt Typhoon campaign compromised at least nine major US telecommunications providers and targeted telecom infrastructure across Europe, the Asia-Pacific region, and dozens of other countries worldwide, granting the actors access to communications metadata belonging to millions of users. The campaign involved extensive modifications to router configurations and, in some cases, firmware-level implants to maintain long-term persistence even after device reboots.

Military-Civil Fusion: From Policy to Persistent Access

Although MCF became a major point of contention in U.S.-China relations during President Xi Jinping’s tenure, as he elevated it to a national strategy and placed it under his personal oversight, the approach has in fact been a consistent feature of Chinese strategic thinking for decades, with roots in Mao Zedong’s 1956 directives on civilian to military technology transfer and Deng Xiaoping’s 1982 “sixteen-character” policy on combining military and commercial development.

As a notable change from the 13th and 14th Five-Year Plans, which both explicitly referenced MCF, the outline of China’s 15th Five-Year Plan (2026–2030) contains no direct reference to it, but rather than abandoning its core objective of systematically integrating non-military and military technological development, Beijing is continuing the policy under alternative terminology.

MCF is overseen by the Central Military-Civil Fusion Development Commission, established in 2017. It requires civilian entities, including state-owned carriers, private contractors, research institutions, and technology firms, to support military and intelligence requirements through binding obligations in the National Intelligence Law (2017) and Cybersecurity Law (2016). These statutes effectively blur the line between commercial telecom innovation and state intelligence requirements. Article 7 of the Law is particularly explicit, obliging all Chinese organizations and citizens to support, assist, and cooperate with national intelligence efforts. This provision is widely interpreted as creating a legal obligation that could compel Chinese technology firms to provide backdoor access or data on foreign customers when requested by intelligence agencies, raising serious concerns under international law and export control regimes.

China sees cyberspace as a prime arena for asymmetric warfare, strategic deterrence, and the pursuit of information superiority. At the core of Beijing’s modern cyber thinking is the concept of ‘informationization’, which calls for the systematic embedding of information technologies throughout the economy, society, and critical infrastructure. In practice, this means embedding cyber capabilities into civilian telecommunications infrastructure during normal network deployment and maintenance, rather than as separate military systems. From the 1990s onward, Chinese strategists came to recognize that the information domain had become a decisive factor in national power and security. They observed that adversaries could now gain deep visibility into one another’s economic systems, populations, and decision-making processes. This realization prompted China’s military and political leadership to place cyber operations at the very center of national strategy.

Despite reduced public rhetoric, MCF has not been abandoned but has been rebranded and embedded more deeply into procurement and planning processes. In the cyber domain, this fusion enables the PLA Cyberspace Force and MSS contractors to leverage civilian supply chains, edge device manufacturing, and network management expertise for continuous global access. Commercial telecommunications providers supply dual-use hardware, software updates, and remote management interfaces that allow state actors to maintain footholds without constant deployment of bespoke malware. This includes concerns about major Chinese vendors such as Huawei, ZTE, and Hikvision, which dominate global 5G and surveillance infrastructure markets. Beijing deliberately integrates civilian technological advances – particularly in 5G/6G infrastructure, undersea cables, and lawful intercept systems – into PLA modernization plans.

The doctrinal driver for the PLA is “intelligentised warfare,” which treats peacetime cyber operations as routine intelligence preparation of the battlefield. Under this framework, sustained access to global telecom networks is not espionage for its own sake but a form of pre-positioning: acquiring communications metadata, mapping critical infrastructure dependencies, and preparing disruption options for future contingencies, including a Taiwan scenario. Telecommunications are ideal terrain precisely because they are dual-use by design. Carrier networks provide global transit chokepoints, lawful intercept interfaces required by host governments, and vast stores of metadata that can be harvested quietly through MCF-enabled contractors. This systemic integration helps explain why campaigns survive patching cycles and vendor changes, as private-sector entities are legally obligated to support national intelligence efforts. The result is an access architecture that is resilient, deniable, and scalable, precisely the outcome MCF was designed to produce.

Implications for Deterrence and International Norms

The institutionalized nature of MCF fundamentally complicates traditional deterrence in cyberspace. Because it legally and organizationally embeds state requirements inside civilian telecom supply chains, attribution becomes slower and disruption more politically costly. Publicly naming contractors or state-owned carriers risks escalation with commercial entities that Beijing treats as national assets, while technical takedowns of compromised devices are frequently reversed through re-entry mechanisms enabled by the same fusion architecture.

This dynamic weakens both punishment-based and denial-based deterrence strategies. Western governments cannot easily impose costs on individual campaigns when the enabling infrastructure is diffused across nominally civilian actors bound by Chinese law. Strategy must therefore adapt, and governments should treat MCF-linked vendors as a systemic risk in critical-infrastructure procurement reviews and invest in multilateral resilience standards for global telecom networks. While not every Chinese vendor carries an official MCF designation, the National Intelligence Law effectively makes major telecommunications providers and contractors available to support state intelligence requirements. Greater transparency on MCF obligations in international forums could also help shape emerging cyber norms, moving the debate from episodic campaigns to the underlying doctrinal model that sustains them. Without such adaptations, this creates an asymmetric dynamic in which operators carry the day-to-day defensive burden while Beijing gains strategic optionality.

What Must Change: Policy and Procurement Reforms

Traditional perimeter defenses and periodic patching are insufficient against MCF-enabled persistence because the threat is embedded within the supply chains and legitimate management features on which operators depend.

Adversaries routinely exploit limited visibility into east-west traffic on edge devices and management planes, allowing low-and-slow access to survive routine maintenance cycles. Global telecom operators must therefore adopt a structural shift in defensive posture.

First, implement rigorous zero-trust segmentation of management interfaces, lawful-intercept systems, and remote-access pathways, treating every edge device as potentially compromised.

Second, establish continuous behavioral analytics and east-west traffic monitoring specifically for router and VPN environments, shifting away from signature-based detection toward behavioral analysis.

Third, integrate explicit military-civil fusion risk indicators into supply chain due diligence and vendor risk-scoring processes, including country of origin assessments and contractual requirements for transparency on dual-use obligations under Chinese law. This should include mandatory disclosure of any foreign intelligence service obligations, contract clauses requiring notification of government access requests, and third-party audits of dual-use technology deployments.

Fourth, develop and regularly test rapid isolation playbooks that allow operators to quarantine compromised segments without disrupting customer service, drawing on lessons from cross-sector exercises.

Fifth, expand participation in international information sharing mechanisms, such as sector-specific Information Sharing and Analysis Centers and trusted multilateral channels, to close the visibility gap that MCF contractors exploit in third-country networks.

These measures do not eliminate the threat but raise the cost and detection risk for sustained access. Operators that treat MCF as a permanently embedded feature rather than a tactical campaign will be better positioned to protect both commercial operations and the broader critical infrastructure resilience required in an era of great power competition.

Conclusion

MCF has achieved success on a scale that remarkably few strategic doctrines manage: It has turned significant portions of the world’s commercial telecommunications infrastructure into a strategic asset for Beijing. Consequently, this is far from a fleeting cyber campaign; it is the practical expression of a doctrinal vision that has been in place for decades, one in which peacetime network access serves as routine preparation of the information domain for future conflict. This asymmetry is structural in nature, and operators must defend their networks daily, while Beijing benefits from persistent, low-cost optionality that survives patches, vendor rotations, and even public disclosures.

For global telecom operators and allied governments, the practical implication is clear: Technical remediations will never be enough, or rather, only offer temporary solutions. Real resilience means treating MCF as a permanent feature of the operating environment – redesigning networks, supply chains, and international cooperation accordingly. Only then can the West begin to reduce this asymmetry in a domain where commercial infrastructure has become part of an adversary’s extended battlespace. Without coordinated international action, likely within the next 3–5 years as 6G deployments accelerate, this asymmetry will only deepen as civilian networks become even more integrated with military command and control systems.

About The Author

  • Gerald Mako is a Research Affiliate at the Cambridge Central Asia Forum at Cambridge University. His research focuses on the military applications of AI, the governance of lethal autonomous weapons, cybersecurity, and great-power competition in Asia. He has advised governments on both AI and cybersecurity.

    View all posts

Article Discussion:

5 1 vote
Article Rating
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted