Every negotiation has a silent partner. The one who never sits at the table but whispers in the ear of those who do. In the intelligence world, that silent partner is information advantage, and it is obtained long before the handshake.
On March 31, President Trump may arrive in Beijing for a State Visit with President Xi Jinping. It is the first trip by an American president to China since Trump’s own visit in 2017. The agenda is massive: extending the Busan tariff truce, semiconductor export controls, rare earth access, agricultural purchases, and (always lurking) Taiwan. This weekend, Treasury Secretary Bessent and USTR Greer are meeting China’s Vice Premier He Lifeng in Paris to sketch the framework. Five prior rounds of talks (Geneva, London, Stockholm, Madrid, Kuala Lumpur) have brought us to this point.
And then there’s the war.
The Hormuz Variable
On February 28, the US and Israel launched Operation Epic Fury against Iran. Iran retaliated by effectively closing the Strait of Hormuz on March 2, with the IRGC declaring that any vessel attempting passage would be targeted. Within days, traffic through the strait dropped from roughly 153 transits per day to near zero.
For context, about 20% of the world’s daily oil supply flows through that waterway. Oil prices breached $100 per barrel. Some analysts have called it the largest supply disruption in history.
China cares. About 40% of China’s oil imports and 30% of its LNG pass through the Strait of Hormuz. China is the world’s largest crude oil importer and purchases over 80% of Iran’s oil exports. Despite early reports that Iran would allow Chinese-flagged vessels to pass, CSIS tracking data shows that since March 1, only two Chinese-flagged ships have actually transited the strait. Fifty-five Chinese vessels remain trapped inside the Persian Gulf.
Beijing has reserves (roughly a billion barrels, or a few months of supply) and options. But “more flexible” is not the same as “comfortable.” The longer the Hormuz closure persists, the more China’s energy calculus shifts from managed inconvenience to strategic vulnerability.
Three Priorities, One Summit
This brings us to the second-order implication that should be top of mind for defensive security leaders.
China’s Intelligence Services are not passive observers of the geopolitical landscape. They are active participants, likely (if history is any indication) tasked with delivering decision advantage to Beijing’s leadership ahead of the most consequential bilateral meeting in years. And right now, that task is shaped by three converging issues:
1. Energy uncertainty. The Hormuz crisis creates urgent intelligence requirements around US military intentions, conflict duration, alternative supply arrangements, and the global energy market response. Beijing needs to understand how long this lasts and what America is actually willing to do about it.
2. Shifting leverage. The Supreme Court struck down Trump’s reciprocal tariffs last month, weakening his primary negotiating tool. New Section 301 investigations launched this week are an attempt to rebuild that leverage. Meanwhile, China holds the rare earth card and controls whether American soybean farmers get their biggest customer back. Understanding the internal US negotiating posture (the real redlines, not the public ones) is the most valuable intelligence product Beijing can acquire before March 31.
3. Technology controls. Semiconductor export policy is existential for China. The trajectory of Nvidia chip access (H200, Blackwell), AI diffusion rules, and entity list designations will shape China’s technology ambitions for the next decade. Beijing needs to know how tall the fence will be and the yard’s ultimate size.
These three priorities converge at the summit, creating a peak intelligence demand signal. The PLA, the MSS, and their associated contractors will be under immense pressure to deliver. That means cyber operations targeting the institutions that shape American negotiating positions.
This isn’t speculation. It’s pattern recognition.
The Past is Prologue
In September 2025, the House Select Committee on China issued a formal warning about “ongoing” PRC cyber espionage campaigns targeting organizations and individuals involved in US-China trade policy and diplomacy. The targets included US government agencies, business organizations, DC law firms, think tanks, and at least one foreign government.
The Committee attributed the activity to APT41 and was blunt in its assessment: this was “CCP state-backed cyber-espionage aimed at influencing US policy deliberations and negotiation strategies to gain an advantage in trade and foreign policy.”
In one campaign, attackers impersonated Republican Congressman John Moolenaar (a known Beijing critic) in phishing emails sent to his trusted counterparts. The goal was to trick them into opening files that would grant unauthorized access to their systems. In January 2025, four Select Committee staffers working on a confidential investigation into ZPMC (a Chinese state-owned enterprise) were targeted with credential-stealing lures posing as a ZPMC North America representative.
This is not a new playbook. Each major inflection point in US-China relations has coincided with intensified cyber targeting of trade policy stakeholders. Busan was no different. Beijing will be no different, except the stakes are higher.
What our Telemetry Shows
Recorded Future network intelligence over the past two weeks (February 27 through March 14) reveals approximately 1,000 validated victim traffic events attributed to China state-sponsored threat actors across 15 countries.
Three distinct threat actor organizations are operating simultaneously:
RedDelta accounts for 637 events (roughly two-thirds of all activity), with heavy concentration in Vietnam and Southeast Asia. The primary target is telecom infrastructure and government agencies. PlugX backdoor is the tool of choice. RedDelta is also active against Taiwan, Hong Kong, Cambodia, Malaysia, and Bangladesh.
TAG-102 accounts for 204 events, running a parallel campaign against India and Brazil using custom tooling. The geographic targeting pattern is notable: both India and Brazil are major Hormuz-exposed economies navigating their own energy supply chain pressures. Intelligence on how these countries are responding to the Hormuz closure, and how they might align with or against China on the issue, has obvious value ahead of the summit.
RedNovember accounts for 113 events and is actively targeting the United States, deploying the Pantegana remote access trojan.
The volume trend is striking. Activity was running at 12 to 25 events per day before Operation Epic Fury launched on February 28. By March 9 and 10, it surged to 115 and 249 events per day, respectively. That is roughly a 10x increase in the two weeks since the war started, with preparatory Paris talks happening this past weekend and the Beijing summit 15 days away.
Which Industries Should Be on Alert
Based on the convergence of intelligence requirements, historical targeting patterns, and current telemetry, the following sectors face an elevated risk of Chinese cyber intrusion in the weeks ahead:
Trade policy and diplomatic infrastructure. US government agencies involved in trade negotiations (USTR, Commerce/BIS, Treasury), DC law firms advising on export controls and CFIUS, think tanks producing China policy analysis, and Congressional offices. This is the highest-value target set. Direct precedent from the 2025 APT41 campaign makes targeting here a near certainty.
Energy. Oil, gas, LNG, pipeline operators, energy trading firms, and maritime/shipping companies that are involved in Hormuz rerouting.
Semiconductors and advanced technology. NVIDIA, AMD, TSMC ecosystem companies, EDA tool providers, AI labs, and firms on or adjacent to the BIS Entity List. Chip exports are a central summit agenda item. China’s antitrust investigation against Nvidia and its antidumping probe on US analog chips are countermoves that require detailed intelligence on US industry positions.
Telecommunications. This one is persistent. RedNovember activity shows that Chinese actors aggressively rebuild access even after takedowns. The February 2026 breach of the FBI’s Digital Collection System Network (which manages court-authorized wiretaps) underscores the continued Chinese focus on surveillance infrastructure.
Agriculture and commodities. Soybean purchases are the most tangible, politically visible deliverable expected from the summit. China committed to 25 million metric tons annually through 2028, but purchases have slowed sharply after February. Understanding US farm lobby pressure on the administration gives China leverage to calibrate its commitments.
Defense and aerospace. The Iran war is placing additional strain on US defense supply chains, increasing demand for critical minerals in which China holds a dominant position. Intelligence on US defense industrial base capacity and weapons production rates serves both military and diplomatic collection priorities.
The Noise Advantage
Here is where it gets worse for defenders.
The Iran war is generating enormous cyber noise. Over 150 hacktivist incidents were claimed in the first week alone. Pro-Iran groups (Handala Hack being the most notable) are actively targeting US, Israeli, and Gulf state infrastructure. A state-backed Iranian actor tracked as MuddyWater has been pre-positioned on multiple US networks.
This noise benefits Chinese espionage operators in several ways. Defender attention and incident response resources are consumed by Iranian threats. Chinese intrusions may be misattributed to Iranian actors due to overlapping targets (energy, defense, government).
This is not coordination between Beijing and Tehran. It is opportunism.
So What. Now What?
For security leaders, the “so what” is straightforward. The two weeks between now and March 31 (assuming the meeting takes place) represent a period of heightened Chinese cyber-espionage risk, particularly for organizations whose operations, data, or relationships touch on the summit’s agenda items. The convergence of energy disruption, trade uncertainty, and technology competition creates an intelligence demand signal that Chinese actors will attempt to fill.
The “now what” is equally direct:
If your organization touches trade policy, energy, semiconductors, telecom, agriculture, or defense, treat this as an elevated threat window. Review detection rules for known Chinese APT TTPs (especially edge device exploitation and PlugX/Pantegana implants). Ensure your SOC understands the difference between Iranian hacktivist noise and Chinese espionage signals. And if you have visibility, look for low-and-slow lateral movement from existing access in your environment.
Every negotiation has a silent partner. For the next 15 days, that partner is working overtime.







