Full Report
Intelligence Service says finding domestic threats is harder due to proliferation of toxic content online
Analysis Summary
# Threat Actor: Purple Mountain Observatory (PMO) & PRC Intelligence Services
## Attribution & Identity
- **Actor Name:** Purple Mountain Observatory (PMO)
- **Aliases:** CAS Key Laboratory of Radio Astronomy
- **Affiliations:** People’s Republic of China (PRC) government; Chinese military intelligence services.
- **Background:** Described as a China-based organization with "close links" to Beijing, capable of being compelled under Chinese law to provide data to the state.
## Activity Summary
- **Ground-Based Space Infrastructure (GBSI) Operation:** Attempted to install satellite tracking and data collection equipment in New Zealand by partnering with an unwitting local company.
- **Professional Networking Exploitation:** PRC military intelligence is actively using professional networking sites and job platforms for human intelligence (HUMINT) recruitment.
- **Domestic Extremism:** While not attributed to a single state actor, the report notes a proliferation of state-backed cyber-attacks aimed at destabilizing New Zealand's internal security.
## Tactics, Techniques & Procedures
- **Social Engineering (Recruitment):** Posing as consultants, recruitment firms, or think-tank employees on professional networking sites.
- **False Flag Job Offers:** Posting lucrative advertisements for analysts in foreign policy, defense, and security to vet candidates for access to classified information.
- **Infiltration of Infrastructure:** Attempting to install dual-use technology (GBSI) under the guise of scientific research (tracking space debris/satellites) to collect military intelligence.
- **Strategic Retention:** Encouraging recruits to maintain their government positions to ensure a continuous flow of intelligence and to facilitate "co-worker recruitment."
- **Exploitation of Legal Frameworks:** Leveraging Chinese domestic laws to compel private or academic organizations to pass collected foreign data to the state.
## Targeting
- **Sectors:** Aerospace/Space Sector, Defense, Foreign Policy, International Relations, Security, and Government.
- **Geography:** New Zealand.
- **Victims:**
- Unnamed New Zealand local companies (used as conduits for GBSI).
- Government employees and policy analysts (targeted via recruitment).
- Professional networking platform users.
## Tools & Infrastructure
- **Physical Infrastructure:** Ground-Based Space Infrastructure (GBSI) for satellite tracking.
- **Digital Platforms:** Professional networking sites (e.g., LinkedIn), online job platforms, encrypted messaging systems, and gaming platforms.
- **Websites Mentioned:** hXXps://www[.]nzsis[.]govt[.]nz
## Implications
The NZSIS assesses that China is the only state actor currently targeting New Zealand "at scale." The shift toward dual-use space infrastructure indicates a strategic move to bypass traditional electronic surveillance detection. Furthermore, the "mainstreaming" of extremist rhetoric online—assisted by social media algorithms—creates a "noise" floor that allows state-backed destabilization campaigns to hide their activities more effectively.
## Mitigations
- **Supply Chain Vetting:** Local companies in the tech and space sectors must conduct rigorous due diligence on foreign partners providing equipment for "scientific" purposes.
- **Insider Threat Awareness:** Government agencies should brief employees on the risks of aggressive recruitment tactics on professional social media platforms.
- **Platform Vigilance:** Increased monitoring of encrypted messaging and gaming platforms for the circulation of violent extremist material or weapon tutorials.
- **Data Sovereignty:** Strengthening regulations regarding who can receive data collected by foreign-owned infrastructure on domestic soil.