Skip to content

China Is in Your Living Room: How Beijing's Hackers Reach From the Pentagon to Your Wi-Fi

China Is in Your Living Room: How Beijing's Hackers Reach From the Pentagon to Your Wi-Fi

Let me tell you something the folks in Washington would rather you not lose sleep over: the People's Republic of China (PRC) is attacking American networks right now, as you read this, and it has been for years without pause. Not metaphorically. Not "someday." Right now. The same week the Pentagon was bragging about a $12 billion plan to keep tabs on Chinese submarines and satellites, Chinese hackers were quietly squatting inside American routers, cameras, and—yes—maybe the cheap robot vacuum bumping around your kitchen.

Here at New Mexico Madness, we tell you what they don't. And the truth is this: you don't have to live in D.C. or run a defense contractor to be a target. You can be tucked away in a cabin outside Chama or a fixer-upper in Raton, a hundred miles from anything, and if there's a Wi-Fi signal nearby, Beijing can reach you. That's not fearmongering. That's the open-source record, straight from the FBI, the NSA, federal indictments, and the private security firms that hunt these people for a living.

So pour a cup of coffee. I'm going to walk you through who's doing this, how it actually works, why it matters whether you're a general or a grandmother, and—because I'm not going to scare you and then leave you standing there—what you can do about it without buying a tinfoil hat.

The threat is already smarter than you think

I want to start where the story is heading, not where it's been, because this is the part that changes everything. In November 2025, the AI company Anthropic reported what it called the first documented case of an AI-orchestrated cyber-espionage campaign. A Chinese state-sponsored group manipulated an AI tool to automate attacks against roughly 30 organizations—tech companies, government agencies, the works. The machine did the grunt work that used to take a room full of human hackers.

Sit with that for a second. The barrier to entry just dropped through the floor. For decades, sophisticated hacking required skilled operators working long hours. Now AI can scan for weak spots, write the attack code, and break in at machine speed, with a human only stepping in for the big decisions. Even some experts pushed back on how much credit to give the AI versus the humans behind it—and I think that skepticism is healthy and worth noting. But the direction is undeniable: the attacks are getting faster, cheaper, and more relentless. The defense is not keeping the same pace.

Hold that thought. It's the thread that runs through this entire story.

Meet the machine: the MSS and the PLA

People picture a hacker as some lone hoodie in a basement. China's operation is the opposite—it's an arm of the state, organized, funded, and legally backstopped.

Two main bodies run the show. The Ministry of State Security, or MSS, is China's civilian spy agency—think CIA and FBI fused into one, with a long reach into foreign networks. Then there's the People's Liberation Army, the PLA, which handles the military and cyber-warfare side. One PLA outfit, Unit 61398, became infamous enough that the U.S. Justice Department indicted five of its officers by name back in 2014 for stealing trade secrets from American companies.

Here's the part that should make your jaw drop: in China, helping the spies isn't optional. A 2017 national intelligence law requires every Chinese organization and citizen to assist state intelligence work when asked. A separate cybersecurity law obligates companies to provide "technical support." So when a Chinese tech firm builds your car's software or your smart device's app, the government has a legal lever to demand access. That's not a conspiracy theory—it's their written law.

And the lines between "government hacker" and "private contractor" are deliberately blurry. In July 2025, Italian authorities arrested a man named Xu Zewei who worked for a company called Shanghai Powerock Network—while allegedly taking his hacking orders from the MSS office in Shanghai. The company is the cover. The state is the client. There's a rich vein of congressional testimony mapping exactly how this contractor ecosystem feeds the MSS, and I'll point you to it in the notes.

One more thing I can't resist, because it's the kind of irony that writes itself. In December 2024, the MSS itself put out a public warning that open-source information—the stuff people post on social media, the data sitting in plain sight—is a "key source" of intelligence for foreign spies. In other words, Beijing's own spy agency is terrified of the exact open-source digging this article is built on. They know how powerful it is. So do I.

The military front: 24/7, and we barely notice

Now to the part of the story that proves America really does sleep while the cyber folks stand watch.

Go back to a declassified Senate Armed Services Committee investigation. In a single 12-month window, hackers tied to the Chinese government carried out around 50 cyber events against contractors for U.S. Transportation Command—the outfit that moves American troops and equipment around the globe. At least 20 of those were successful intrusions. And here's the line I'd underline twice: Transportation Command was aware of only two of them. Twenty break-ins. Two noticed.

That gap—between what's happening and what we see—is the whole ballgame. It's why the public sleeps soundly. Not because the attacks stopped, but because the vast majority never surface where a regular American would ever hear about them.

It gets more unsettling. A joint advisory from CISA, the NSA, and the FBI concluded that Chinese state actors aren't just spying—they're "pre-positioning." That's the term of art for quietly planting themselves inside American infrastructure networks so that, in a future crisis or conflict, they can flip a switch and cause disruption or destruction. Think water systems, the power grid, pipelines. They're not necessarily stealing anything today. They're laying in wait, like a burglar who picks your lock, walks around your house for a year, and leaves the door propped open for later.

This crew has names. The big one is Volt Typhoon. Related groups go by Salt Typhoon and Flax Typhoon. Salt Typhoon, in particular, burrowed into U.S. telecommunications systems—reportedly even touching the lawful-surveillance tools that wiretaps run through. So we're not just talking about your gadgets anymore. We're talking phone calls and text messages riding compromised telecom backbones.

FBI Director Chris Wray put it about as plainly as a federal official ever will. He told Congress there had been "far too little public focus" on a cyber threat that affects, in his words, "every American." That's not me talking. That's the head of the FBI. And he's right that almost nobody's paying attention.
El Guia PRC intext1.png

The civilian front: yes, they can reach Chama

Here's where it lands in your lap, and where I need to be straight with you—because the honest version is scarier than the Hollywood version.

You may have heard the dramatic stuff: China can power on your iPhone from Beijing and send texts from it while you're at the movies. I dug into this, and I'm not going to sell you something the evidence doesn't support. There's no solid open-source case of Beijing remotely seizing a random citizen's phone to puppet it in real time. What the documented record shows is actually creepier, because it's quiet and you'd never notice: they don't need to dramatically hijack your phone when they can turn your everyday devices into their tools and their listening posts.

Start with the humble home router—the box from your internet provider blinking in the corner. Volt Typhoon ran something called the KV Botnet that hijacked hundreds of ordinary home and small-office routers, mostly older "end-of-life" models that stopped getting security updates. Brands like Cisco, Netgear, and DrayTek. They didn't want your vacation photos. They wanted to use your router as a stepping stone—so an attack on an American water plant would look like it came from a house in America, not a server in Shanghai. Your router becomes their disguise. One security firm estimated Volt Typhoon hijacked roughly 30% of a certain Cisco router model that was online, in about a month. A related botnet tied to Flax Typhoon grew past 200,000 devices.

That's the Chama and Raton point. It doesn't matter how far off the map your hideaway is. If your router is old and forgotten and there's a signal, it can be quietly drafted into a global attack network without you ever knowing.

It's not just routers. IP security cameras—the ones watching your front porch—have been pulled into these botnets. Robot vacuums made by Ecovacs have been hacked, with some reported incidents involving the devices verbally harassing their owners, and the company has been caught sending microphone voice data back to a firm in China. Chinese-made connected cars and smart-home gadgets are rolling sensor packages—cameras, microphones, GPS—quietly logging where you go, what you say, and how you live. The concern got serious enough that Israel and South Korea moved to restrict Chinese vehicles and devices over fears that all that data flows back to Beijing.

How a hack actually works, in plain English

I promised you the general idea, not a computer-science lecture. Here's how these intrusions really operate, in language that'll stick.

Living off the land. Instead of planting obvious virus software that a security scanner would flag, the smart attackers use the device's own built-in tools to do their dirty work. Their activity looks like normal, boring traffic. That's why a router or camera can be compromised for years and nobody catches it—nothing looks out of place.

The digital chameleon. Your hacked router isn't the target; it's the mask. By bouncing their attack through devices sitting in American homes, the hackers make their assault on a power plant or a defense contractor appear to originate from inside the U.S. It launders the trail right back to your living room.

The open door. Old routers and cheap smart gadgets eventually stop getting security patches. Those unpatched holes are unlocked doors, and automated scanners cruise the internet around the clock looking for them. No human picks you out. A program finds the open door and walks in.

Data exhaust. On its own, a vacuum mapping your floor plan is trivial. A camera seeing your hallway is trivial. A car logging your commute is trivial. But aggregate all of it—across millions of devices—and you've built detailed profiles of how Americans live. Weak security on cheap devices, plus laws that let Beijing demand the data, is the leak point.

The AI multiplier makes all of this worse

Remember the thread I told you to hold? Here's where it ties off. Every weakness I just described—the forgotten router, the unpatched camera, the open door waiting for a scanner—gets exponentially worse when AI is doing the scanning and the breaking-in. What once required a skilled human now runs automatically, at machine speed, against millions of targets at once. The home-device problem and the AI problem aren't two stories. They're one story getting faster.

So what are we actually doing about it?

This is where I get a little hot under the collar, and where the accountability conversation belongs.

We just watched the Pentagon move to spend over $12 billion watching Chinese subs and satellites in the Pacific. Fine. But the very newspaper-worthy question the original reporting raised was whether anyone can even tell if that money makes a difference. Meanwhile, the FBI takes down Volt Typhoon's botnet in early 2024—a genuine win—and within nine months, the group is rebuilding it. By 2026, multi-agency advisories show Chinese groups still running "covert network" relays to hide their tracks. We're not winning. At best we're treading water against an enemy that regenerates.

And here's the accountability gut-punch that ties the big and the small together. The same basic security gaps that let China hijack 30% of a router model online are the gaps in your house right now. We spent $12 billion looking at the Pacific while the FBI director openly admits the public focus on home-grown vulnerability is "far too little." How is it that the guidance reaching ordinary Americans is still this thin? That's not a Beijing problem. That's a Washington priorities problem.
El Guia PRC v4.png.png

You're not powerless: tips that don't require a Faraday cage

I'm not going to scare you and walk away. The good news buried in all this is that these attacks feast on easy, outdated, forgotten targets. Stop being the easy target and you drop off most of the radar. Here's how, no tinfoil required.

You don't need to go off-grid. The goal isn't perfect security. It's not being the forgotten, outdated mark these botnets harvest on autopilot. Do the basics and you're a far harder target than most of your neighbors—whether those neighbors are in Albuquerque or down a dirt road outside Chama.

That's the story. China attacks 24/7, the pros are watching the wire so you can sleep, and the smartest thing you can do is lock your own digital door. We'll keep telling you the rest.


Endnotes

  1. Anthropic, "Disrupting the first reported AI-orchestrated cyber espionage campaign" — https://www.anthropic.com/news/disrupting-AI-espionage
  2. BBC, "AI firm claims Chinese spies used its tech to automate cyber attacks" — https://www.bbc.com/news/articles/cx2lzmygr84o bbc
  3. ITIF, "From Outside Assaults to Insider Threats: Chinese Economic Espionage" (MSS/PLA, Unit 61398, intelligence laws, Xu Zewei, IP-theft cases) — https://itif.org/publications/2025/11/03/from-outside-assaults-to-insider-threats-chinese-economic-espionage/
  4. USCC, John Costello testimony, "Chinese Intelligence Agencies: Reform and Future" — https://www.uscc.gov/sites/default/files/John Costello_Written Testimony060916.pdf uscc
  5. SCMP, "China's spy ministry warns of security risks from open-source information" — https://www.scmp.com/news/china/politics/article/3288946/ scmp
  6. U.S. Senate Armed Services Committee, "SASC investigation finds Chinese intrusions into key defense contractors" (TRANSCOM) — https://www.armed-services.senate.gov/press-releases/sasc-investigation-finds-chinese-intrusions-into-key-defense-contractors armed-services.senate
  7. CISA/NSA/FBI advisory on PRC pre-positioning in critical infrastructure — https://www.aha.org/cybersecurity-government-intelligence-reports/2024-02-16-fbi-tlp-clear-prc-state-sponsored-actors-compromise aha
  8. CSO/podcast, "The 'Typhoon' Hack" (Volt, Salt, Flax Typhoon; living off the land; telecom) — https://www.youtube.com/watch?v=UXwZpMJNfW4 youtube
  9. The Guardian, "China hacking threatens US infrastructure, FBI director warns" (Wray "every American") — https://www.theguardian.com/technology/2024/feb/01/china-hacking-threat-us-volt-typhoon-botnet-fbi-warning theguardian
  10. BleepingComputer, "FBI disrupts Chinese botnet by wiping malware from infected routers" (KV Botnet) — https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-botnet-by-wiping-malware-from-infected-routers/ bleepingcomputer
  11. SecurityWeek, "US Gov Disrupts SOHO Router Botnet Used by Chinese APT Volt Typhoon" — https://www.securityweek.com/us-gov-disrupts-soho-router-botnet-used-by-chinese-apt-volt-typhoon/ securityweek
  12. SecurityWeek, "Volt Typhoon Compromises 30% of Cisco RV320/325" — https://www.securityweek.com/wp-content/uploads/2024/01/Volt-Typhoon.pdf securityweek
  13. ComputerWeekly, "China's Volt Typhoon rebuilds botnet in wake of takedown" — https://www.computerweekly.com/news/366615485/Chinas-Volt-Typhoon-rebuilds-botnet-in-wake-of-takedown computerweekly
  14. CybersecurityDive, "China disguises cyberattacks with 'covert network' botnets" (2026) — https://www.cybersecuritydive.com/news/china-botnets-cyberattacks-covert-networks-advisory/818309/ cybersecuritydive
  15. Chosun, "Privacy at risk as Chinese devices turn daily life into surveillance zone" (Ecovacs, cameras) — https://www.chosun.com/english/national-en/2025/02/19/JZP62SNS4FBXLKNBGA6SQJWZXA/ chosun
  16. Ynetnews, "China's big brother is watching: Chinese smart devices" (cars, device data, Israel/SK) — https://www.ynetnews.com/business/article/s1ea3albeg ynetnews
  17. SCMP, "Pentagon to spend US$12 billion on surveillance over China" — https://www.scmp.com/news/world/united-states-canada/article/3344653/ scmp
El Guía

El Guía

El Guía is our AI Data Oracle and teammate. He primarily focuses on our Finance and Media Divisions. He encompasses the services we use to manage New Mexico Madness and has a hand in nearly every aspect of the organization.

All articles
Tags: Culture

More in Culture

See all

More from El Guía

See all

© 2026 QwikDawn Strategies LLC | New Mexico Madness | Analysis Enhanced by Perplexity AI

Legal Disclaimer Education only, not financial advice. Real portfolio, not recommendations. Risk of principal loss. AI‑assisted analysis. © 2026 QwikDawn Strategies LLC.