The Full Stack of U.S.-China Cyber Competition
Understanding what drives cyber operations—and, just as importantly, figuring out how to respond to them—often requires looking beyond individual threat actors or campaigns to the broader ecosystems in which cyber capabilities are developed and deployed. Cyber capabilities emerge from wider networks of people, companies, state institutions, markets, and incentives, all of which shape operational behavior. Yet much of the policy debate still struggles to connect these different layers. Technical specialists often focus on the mechanics of an operation, while policymakers focus on its strategic consequences, leaving a gap between the two.
“Full Stack Spies” positions itself as a bridge across that divide. The book takes cyber espionage as its central subject and examines it across three interconnected levels: tradecraft, statecraft, and instability. Its “full stack” approach moves from the hackers and engineers carrying out operations, to the governments and institutions directing or enabling them, and ultimately to the broader strategic dynamics that determine how cyber competition unfolds. This structure suits a field where the gap between technical communities and policymakers remains difficult to span, and where the underlying ecosystems are often opaque, fragmented, and shaped by very different institutional cultures. Although the book’s central focus is U.S.-China competition, it also devotes substantial attention to Russia. I follow the same three-part structure here, moving from tradecraft to statecraft and finally to the issue of instability.
Upstairs and Downstairs
One of the book’s most useful analytical devices is its distinction between the cyber world “upstairs,” where strategic and geopolitical decisions are made by state and technology company leadership, and the “downstairs,” where hackers, analysts, and engineers translate those decisions into operations. The framework provides a way to understand cyber capability not simply as something possessed by a state, but as something produced through relationships between actors with different incentives, cultures, resources, and degrees of control.
The opening chapters build out this argument through the economics of espionage and the market for exploits and zero-days, where scarce expertise, secrecy, exclusivity, and competing incentives to buy, sell, retain, or disclose vulnerabilities shape an uneasy relationship between governments and the private sector. The discussion then moves into China’s “downstairs,” using exposed cases such as the i-SOON leaks and APT41 to trace the campaigns, commercial incentives, and networks that make up China’s cyber ecosystem, before turning to the state institutions sitting above them, particularly the Ministry of State Security (MSS) and the People’s Liberation Army (PLA).
The book’s opening “upstairs-downstairs” framework is useful for understanding tradecraft as the product of two worlds in tension: intelligence and military cultures at the top, and hacker groups, often embedded within commercial firms, operationalizing their requirements below. Over more than a decade, operations have been linked, with varying degrees of confidence, to multiple individual provincial bureaus and units scattered across the MSS, the Ministry of Public Security (MPS), and the PLA, working with multiple companies. Tradecraft is consequently not monolithic. It varies across the dozens of China-linked threat groups identified so far and is often shaped by the requirements of particular actors upstairs, even as capabilities and techniques circulate efficiently across the broader ecosystem. As Datta Fasel puts it, “Shared tooling did not mean shared command. It meant shared habits, shared suppliers, and a labour market where techniques circulated faster than affiliations.”
Command, in particular, is difficult to pin down. The author attributes Salt Typhoon—an extensive espionage campaign targeting telecommunications networks—to the MSS’s Sichuan provincial bureau, and Volt Typhoon—a campaign of pre-positioning in critical infrastructure—to the PLA. The level of public evidence supporting these claims differs. In the case of Salt Typhoon, U.S. government reporting has established an MSS connection through a Salt Typhoon-linked contractor involved in the telecommunications compromises, but it has not publicly attributed the campaign specifically to the Sichuan Provincial State Security Department.
Although the PLA is absent from the advisories that have shaped most public discussion of the Typhoon campaigns, the PLA link to Volt Typhoon has received some public support elsewhere. A 2024 publication by the U.S. National Counterintelligence and Security Center (NCSC) states that, in the Volt Typhoon campaign, “cyber threat actors from the PLA” used living-off-the-land techniques to establish persistent access to critical-infrastructure networks in the United States and Guam. Former senior U.S. officials have also publicly described Volt Typhoon as a PLA operation, though in individual testimony rather than in agency reporting. Even so, in the book’s later discussion of instability, the PLA attribution is presented as a determination by the U.S. National Security Council (NSC), emerging from collaboration with Microsoft, which first publicly reported on Volt Typhoon. The basis for that characterization is unclear, however, since neither the NSC nor Microsoft has itself publicly attributed Volt Typhoon directly to the PLA. Elsewhere, the book is similarly unclear in its presentation of public attribution statements.
These distinctions matter given the political and intelligence challenges of attributing high-stakes cyber activity and the broader information contest surrounding such claims. In the case of Volt Typhoon, the absence of a consistently articulated, visible public attribution to a specific Chinese state entity has also left space for Beijing’s counternarrative to circulate, though seemingly with limited effect.
The book’s treatment of Volt Typhoon also at times suggests a shift away from the intellectual property (IP) theft China has been accused of for over a decade toward a more unique focus on pre-positioning for disruption. That framing should not obscure the continuing importance of IP theft, which remains a significant Chinese intelligence priority alongside the growing focus on pre-positioning for disruption.
From Tradecraft to Statecraft
Having grounded the reader in the Chinese operational ecosystem, the book then widens its focus to examine how cyber capability fits into broader state strategy. This is where “Full Stack Spies” is at its most ambitious. It traces the evolution of Chinese cyber-related military doctrine and strategy, situates cyber operations within economic development and foreign policy, examines China’s emphasis on technological self-sufficiency, and then turns outward to questions of deterrence, naming and shaming, and the role of technology companies in geopolitical competition.
The treatment of Chinese strategy is useful in showing how cyber capabilities have been woven into broader economic and foreign policy objectives instead of developing as an isolated military or intelligence domain. The discussion of deterrence is also effective, especially in unpacking why public attribution and naming and shaming have struggled to produce meaningful behavioral change. Exposure can impose reputational costs, but those costs have often been too limited and inconsistently reinforced to outweigh the strategic value Beijing places on the activity. The book’s observation that “the US and its allies had pursued an immature and uncoordinated form of cyber deterrence” lands well after the tradecraft details of Part I, since the reader now better understands what is being deterred (or not).
One gap in the otherwise thorough doctrinal discussion is the “Science of Military Strategy,” an influential PLA text that has addressed cyber issues since at least 2013 and provides an important window into Chinese military thinking. Its inclusion would have helped connect the book’s discussion of institutional reform and strategic concepts more directly to authoritative PLA debates about the role of cyber capabilities in warfare.
The discussion of Operation Aurora, the 2009-2010 cyber-espionage campaign targeting Google and other major companies, is less convincing because it appears to compress distinct periods in the evolution of China’s cyber ecosystem. The book links Google’s decision to withdraw its search engine from mainland China following the 2009-2010 campaign to retaliation by patriotic hackers, citing the Green Army—described as a collective of hacker groups—as evidence of Beijing’s losing control over an increasingly unruly hacker ecosystem. But the Green Army—which was in fact a single group—had disbanded in 2000, and by the time Operation Aurora occurred the first generation of China’s patriotic hacker ecosystem had changed substantially. Many prominent groups had disbanded or fragmented, while hackers and groups increasingly commercialized, entered cybersecurity firms, or were drawn into state-linked structures.
Trust as Currency and the Limits of Empathy
The final part of the book moves beyond the production and direction of cyber capabilities to ask what persistent cyber competition does to relationships between states, companies, and other actors. Its most useful conceptual device is trust as a form of volatile currency that can be accumulated, depleted, hedged, or exploited. The book develops this through a simplified game-theoretic model in which an overt game of cooperation on cyber norms runs alongside a covert game of espionage and coercion. States can therefore continue to cooperate where preserving trust and stable relationships serves their interests while simultaneously pursuing intelligence and strategic advantage below the surface. Ambiguity becomes useful because it allows them to preserve deniability, limit escalation, and retain room to maneuver. At this point, Datta Fasel argues that China disrupted this schema by effectively acknowledging responsibility for Volt Typhoon, presenting the episode as evidence of a potentially significant shift in the dynamics of cyber competition.
From there, Datta Fasel introduces the concept of “strategic empathy,” understood as an effort to model an adversary’s fears, incentives, and constraints without simply accepting its stated position, alongside the concept of “not war,” a condition in which persistent hostile activity remains below the threshold of armed conflict. These ideas are applied across a wide range of cases, from multinational corporations navigating U.S.-China competition to smaller states balancing relationships with Washington and Beijing.
The trust-as-currency concept is a useful device because trust itself cannot be directly observed. The framework instead asks what actors fear losing and what costs they are prepared to accept to preserve a relationship. This offers a way to compare behavior across actors that would otherwise be difficult to place within a common framework. The book’s idea of “not war” also provides a useful way of conceptualizing hostile activity that remains below the threshold of armed conflict. The concept sits close to what cybersecurity scholar Lucas Kello has termed “unpeace,” a condition of persistent and damaging competition that is neither peace nor conventional war. It is particularly applicable to activities such as Volt Typhoon, where the strategic concern lies partly in capabilities being positioned today for effects that may only be realized during a future crisis.
The argument becomes less persuasive when it turns to strategic empathy. The concept works intuitively for multinational corporations and smaller states that retain room to hedge between competing powers, but its implications for U.S. strategy remain underdeveloped. Datta Fasel suggests that Washington could use strategic empathy to identify when the Chinese Communist Party’s resolve is brittle, when it is bluffing, or when it improvises under pressure, yet the book never fully explains how this insight should alter concrete U.S. policy. A concrete contemporary example or more developed policy prescriptions would have helped demonstrate how strategic empathy changes what policymakers should actually do.
The treatment of an alleged Chinese “admission” of responsibility for Volt Typhoon is also too categorical. The public basis for the claim appears to rest primarily on a single Wall Street Journal report stating that Chinese officials made remarks during a December 2024 meeting that U.S. participants interpreted as a tacit acknowledgement of responsibility—a characterization that the report itself described as indirect and ambiguous. This should also be considered against the backdrop of Beijing’s continued public rejection of the Volt Typhoon allegations and its consistent counternarrative portraying Volt Typhoon as the work of a criminal group. While the reported exchange may suggest a subtle shift in signaling, it falls short of an explicit admission. Building a claim of a fundamentally new paradigm in cyber competition on such ambiguous evidence therefore seems premature.
The Whole Stack
“Full Stack Spies” succeeds in bringing together layers of cyber competition that are too often examined separately. Its “upstairs-downstairs” framework provides a useful organizing device, and its effort to connect operational ecosystems to statecraft is ambitious. Yet that ambition also exposes the book’s main weakness. It moves quickly across a very large number of actors, cases, concepts, and historical episodes, at times compressing developments that require greater historical distinction or drawing broader conclusions from evidence that remains incomplete or contested. At points, this breadth also makes the argument difficult to follow, as shifts between cases, periods, and levels of analysis leave some of the connections insufficiently developed.
For readers already immersed in cyber threat intelligence or Chinese cyber operations, some of the book’s interpretations will invite debate, particularly where public attribution remains uncertain or where historical examples are used to sustain broader claims about the evolution of China’s cyber ecosystem. These tensions are most visible in the book’s treatment of attribution, where its own emphasis on ambiguity and incomplete information makes some of its broader conclusions harder to sustain.
The book’s value lies primarily in providing a broad analytical architecture through which readers can connect operational activity, institutions, and strategic competition. Its central contribution is the argument that understanding cyber competition requires following the whole stack, from the individuals and markets that produce capabilities, through the institutions that direct them, to the strategic environment in which their effects are ultimately felt. For policymakers and scholars seeking to understand how cyber capabilities connect to statecraft more broadly, the book therefore offers a useful point of departure.
