China (CN) Threat Intelligence

CN

China has 530,555 malicious IP addresses with 23,714,539 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, professional threat, moderate threat. Top attacking networks: Chinanet (165,608 IPs), CHINA UNICOM China169 Backbone (149,317 IPs), Hangzhou Alibaba Advertising Co.,Ltd. (19,552 IPs). Data collected since 2022-07-02, last activity 2026-09-06.

Threat Assessment: China is one of the most significant sources of cyber threats globally, with an exceptionally high volume of malicious IP addresses. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Chinanet and CHINA UNICOM China169 Backbone.

Total Reports
23,714,539
Unique IPs
530,555
First Seen
2022-07-02
Last Activity
2026-09-06

Top Threat Categories

Suspicious Activity 433,750
Severe Abuse 121,646
Ssh Bruteforce 29,602
Professional Threat 22,258
Moderate Threat 21,372

Top Attacking Networks

AS4134 Chinanet
165,608 IPs
AS4837 CHINA UNICOM China169 Backbone
149,317 IPs
AS37963 Hangzhou Alibaba Advertising Co.,Ltd.
19,552 IPs

Most Reported IPs in China

103.203.57.2 810 reports
218.25.89.208 801 reports
36.33.167.165 801 reports
14.29.214.161 800 reports
124.193.81.23 799 reports

Access this data via API

Get China threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/CN

View full API documentation

See how we classify and verify threats →

Check any IP from China

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS4134 Intelligence AS4837 Intelligence AS37963 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...