China’s Cyberwarfare Capabilities and Doctrine: Systems, Intelligence and Strategic Access
An evidence-led journey through Chinese cyber power—from active defense and systems confrontation to the 2024 PLA reorganization, mass espionage, critical-infrastructure pre-positioning, telecommunications access, Taiwan scenarios, influence operations, contractors, and the limits of public attribution.
Begin with the absence of an explosion: Guam and the meaning of quiet access
Evidence cutoff: 18 September 2026. The most revealing public case in modern Chinese cyber operations did not begin with a blackout, a wiper, or a spectacular leak. Investigators found access that had been designed to look ordinary. In networks serving communications, energy, transportation, and water systems in the continental United States and its territories, including Guam, operators used valid accounts, internet-facing appliances, and commands already present in the operating system. There was no custom malware signature on which a defender could safely rely. The activity now widely called Volt Typhoon was quiet because quietness was the capability.
A February 2024 Volt Typhoon joint advisory, issued by American agencies with partners, said the actors had maintained access in some victim environments for at least five years. The advisory documented compromises in critical-infrastructure sectors and techniques for living off the land. U.S. agencies assessed with high confidence that the campaign sought to pre-position on networks so the actor could disrupt or destroy functions during a major crisis or conflict. Guam matters because it is a logistical and communications hub for possible American operations in the western Pacific.
Keep three propositions separate. First, intrusions and persistent access were observed. Second, the assessment that the access was intended for crisis-time disruption is an intelligence judgment. Third, no public record shows Volt Typhoon executing the predicted destructive campaign. China rejects the attribution. Its foreign ministry’s Chinese Volt Typhoon rebuttal says the activity was an international ransomware operation and accuses U.S. agencies and companies of manufacturing the narrative. That rebuttal establishes China’s position; it does not by itself disprove the multinational forensic assessment.
The case changes how capability should be measured. Malware sophistication is only one variable. More important may be the ability to discover vulnerable edge devices, obtain credentials, understand a victim’s normal administration, traverse trust relationships, retain access without triggering alarms, and relate a digital dependency to a military timetable. Access to a small communications provider, railway control environment, or water utility can matter more than a dramatic zero-day if it sits on a route supporting mobilization.
Volt Typhoon is therefore the doorway into this page, not its conclusion. China’s cyber power is larger than a threat-group label and more complicated than “hackers working for Beijing.” It links party-state priorities, military modernization, intelligence collection, domestic security, industrial policy, research, private or quasi-private companies, telecommunications, and preparations for joint operations. To understand it, use the practical definition of cyberwarfare: identify the authority, objective, target, mechanism, effect, and conflict context, and state what the evidence does not establish.
Read the doctrine as a journey: active defense, informationized war and systems confrontation
Chinese doctrine does not begin with “cyberwar.” It begins with the political purpose of national defense and the Communist Party’s control of the armed forces. The public strategic guideline is active defense. China’s 2015 Chinese military strategy describes a strategically defensive posture that may employ operational and tactical offensives when attacked or when leaders judge that interests require counteraction. “Defense” in this formulation is a political-strategic claim, not a promise that every military action will be reactive in time, geography, or method.
The same white paper said the PLA should prepare to win “informationized local wars,” with emphasis on maritime military struggle. Informationized warfare assumes that sensors, communications, command systems, precision weapons, logistics, space support, electronic warfare, and computer networks form an interdependent operational system. The object is not merely to damage individual machines. It is to obtain and use information faster, deny that advantage to the opponent, and cause the opposing system to lose coherence.
This leads to systems confrontation and what outside analysts often translate as “systems destruction warfare.” A modern force is a network of reconnaissance, command, fires, maneuver, protection, and sustainment. A smaller number of attacks against essential nodes or relationships may paralyze the whole more effectively than destroying every platform. Cyber operations can steal plans, corrupt situational awareness, interrupt data exchange, delay logistics, weaken air defense, or make commanders distrust their own information. Electronic warfare, space and counterspace operations, deception, psychological activity, and kinetic strikes can pursue the same operational problem from different domains.
The PLA’s later language of intelligentized warfare adds artificial intelligence, autonomous systems, big data, cloud computing, and algorithmic decision support. It does not mean China has completed an AI-driven force. The U.S. Department of Defense’s 2025 China Military Power Report says the PLA continued developing and experimenting with the underlying theory, concepts, and capabilities. Official Chinese writing likewise presents intelligentization as a direction of travel, often alongside continuing informationization and mechanization.
Four cautions keep the doctrine useful. First, aspirational writing is not proof of operational proficiency. Second, translations compress contested terms; a slogan can acquire a certainty in English that it lacks in Chinese debate. Third, articles in PLA newspapers may explore ideas rather than announce binding doctrine. Fourth, foreign defense reports interpret Chinese material through their own threat models. The strongest conclusion is structural: Chinese military thought treats cyber as one element of contesting an adversary’s information and operational system, and values it most when synchronized with other capabilities.
“Cyber sovereignty” occupies another layer. Beijing argues that states should govern their domestic networks, data, and online information according to national law and opposes what it calls internet hegemony. This language supports diplomacy and internet governance, but also domestic censorship, platform control, data access, and surveillance. It should not be confused with a battlefield doctrine. Together, however, military information dominance and political information control reveal a common concern: the Party regards control of information infrastructure and narratives as a condition of security.
The organization after 2024: a new force map with deliberate blind spots
For nearly a decade, outside descriptions of PLA cyber power centered on the Strategic Support Force, created in late 2015 to bring space, cyber, electronic, and psychological capabilities into a more coherent structure. On 19 April 2024, that map became obsolete. Xi Jinping inaugurated the Information Support Force, and the Ministry of National Defense’s 2024 reorganization announcement described a new arrangement under the Central Military Commission: the Army, Navy, Air Force, and Rocket Force as services; and the Military Aerospace Force, Cyberspace Force, Information Support Force, and Joint Logistics Support Force as arms.
Official wording matters. The Information Support Force (ISF) is a newly created strategic arm and a key support for coordinating the construction and application of the network information system. Later official accounts describe communications, data fusion, information reconnaissance, situational awareness, network offense and defense, and deep integration with other forces. A PLA Information Support Force account portrays a force linking operational elements and enabling system-wide support. This suggests responsibility for the connective tissue of joint command and operations: resilient military networks, data and information services, and force-wide information support.
The Cyberspace Force is publicly described in defensive language—protecting the cyber frontier, identifying intrusions, and defending sovereignty and information security. Foreign assessments assign it wider responsibilities derived from the former Strategic Support Force’s Network Systems Department, including cyber operations, electronic warfare, technical reconnaissance, and information or psychological missions. The exact allocation is not public. It is safer to say the force retains a central military cyberspace role than to present any outside organizational diagram as settled fact.
Theater commands and the services still matter. A cyber capability that cannot exchange data with naval, air, rocket, space, logistics, and joint-command elements is not a joint capability. The 2024 reform appears designed in part to clarify support relationships and give the central leadership tighter control over strategic enablers. Reorganization also creates friction: missions, personnel, infrastructure, authorities, training, and career paths must be redistributed while readiness continues.
Beyond the PLA, the Ministry of State Security (MSS) conducts foreign intelligence and counterintelligence. Public indictments connect MSS provincial or municipal bureaus and contractors to long-running global intrusion campaigns. The Ministry of Public Security (MPS) and local public-security organs have cyber and domestic-security responsibilities, including monitoring, investigation, and control. The Cyberspace Administration of China regulates the online environment. State-owned telecommunications firms, defense enterprises, universities, vulnerability researchers, cybersecurity companies, and independent contractors supply technology, access, talent, cover, or data.
This is an ecosystem, not a frictionless machine. A private company can work for a security organ while also seeking commercial profit. A contractor can reuse government access or conduct crime on the side. Local bureaus can procure operations through layers of intermediaries. Organizations compete for budgets and prestige. Such arrangements create scale and deniability, but also inconsistent tradecraft, exposure, corruption, and weaker command control. The safest analytic rule is simple: never turn APT labels into boxes on an official chart unless independent evidence supports the relationship.
The collection state: from steel negotiations to identity at population scale
The public story of Chinese capability is often told through a succession of breaches. Read as a journey, those cases reveal changing intelligence questions.
In May 2014, the United States charged five alleged PLA officers assigned to Unit 61398 with intrusions against companies and a labor organization. The 2014 Unit 61398 indictment alleged theft of negotiating positions, trade secrets, and business information that could benefit Chinese state-owned competitors. It was the first American criminal case against state actors for this kind of economic cyberespionage. An indictment is a formal allegation backed by a described evidentiary record, not a conviction; the defendants have not been tried in the United States.
The 2015 compromise of the U.S. Office of Personnel Management exposed deeply sensitive background-investigation and personnel data. American officials publicly described China as the leading suspect, but the United States did not issue the same kind of judicial attribution made in later cases. The analytic value lies in the data: security-clearance histories, relationships, finances, foreign contacts, and fingerprints can support counterintelligence, recruitment targeting, identity resolution, and the discovery of undercover personnel. Calling it merely a “data breach” misses its intelligence potential; calling the responsible organization proven exceeds the public attribution.
In 2020, the Justice Department unsealed charges against four alleged members of the PLA’s 54th Research Institute for the 2017 Equifax intrusion. The 2020 Equifax indictment alleges theft of personal information belonging to approximately 145 million people, as well as trade secrets. Credit records add addresses, identity fields, and financial relationships. Combined with travel, health, government personnel, telecommunications, or open-source data, separate collections become a strategic graph of people and institutions.
In 2021, the United States, European Union, United Kingdom, NATO members, Japan, and others attributed exploitation of Microsoft Exchange Server vulnerabilities to actors affiliated with the MSS. The initial espionage was followed by broad automated exploitation that left many organizations exposed to additional actors. The episode demonstrated both rapid use of newly disclosed vulnerabilities and a loss of operational discipline: an intelligence operation can create global systemic risk when exploitation scales faster than defenders can patch.
The 2024 APT31 indictment describes a fourteen-year campaign allegedly supporting MSS objectives. Targets included political critics, officials, lawmakers, companies, and dissidents. The charging document details reconnaissance emails using tracking links, later exploitation, and infrastructure intended to obscure origin. Again, the allegations have not been adjudicated. They nevertheless show how transnational repression, strategic intelligence, and technology theft can share operators and infrastructure.
In March 2025, U.S. authorities charged employees and alleged contractors connected to two Chinese public-security bureaus in global campaigns and separately described profit-motivated hackers selling stolen data or access. The 2025 contract-hacker charges illustrate a procurement model that can increase reach but blur purpose. A target may be selected for government intelligence, commercial resale, personal profit, or all three. Defenders should therefore investigate the campaign they observe, not infer intent from nationality alone.
Across these cases, the strategic asset is aggregation. Political email, source code, diplomatic plans, telecom metadata, identity dossiers, health data, and supply-chain credentials become more valuable when linked. The capacity to store, search, translate, correlate, and prioritize stolen information is as important as the intrusion itself. AI may reduce that processing burden, but public claims about automation should be distinguished from measured operational results.
From access to leverage: Volt Typhoon, routers and the crisis campaign
Espionage seeks knowledge; cyber pre-positioning preserves a future option. The same access may serve both, and its purpose can change. Volt Typhoon matters because U.S. agencies interpreted the target selection, persistence, and behavior as preparation to hold civilian infrastructure at risk during a conflict—not simply to steal information.
The operational logic is plausible. A western Pacific contingency would depend on ports, airfields, commercial transport, energy, fuel, communications, contractors, and civilian logistics across a wide geography. Disrupting a regional telecommunications provider or transport node could delay mobilization without attacking a hardened military system directly. Effects against civilian infrastructure might also create political pressure, confuse public warning, consume incident-response capacity, or signal the ability to escalate.
But access is not effect. An operator that can run commands in an IT network may not understand the physical process, safety interlocks, manual workarounds, or restoration plan. Persistence can disappear after a patch, credential reset, architecture change, or public disclosure. Multiple utilities may provide redundancy. An attempted disruption can fail, produce only a local outage, or spread beyond its intended boundary. A defender should neither dismiss the access nor convert it automatically into a national blackout scenario.
China-linked campaigns increasingly use the internet’s neglected middle layer: end-of-life routers, firewalls, VPN concentrators, cameras, and small-office devices. These systems sit at trusted boundaries, often lack endpoint monitoring, and may preserve weak credentials or known vulnerabilities. They also create covert relay networks that make malicious traffic appear to originate from an ordinary home or business near the victim.
The September 2024 Flax Typhoon disruption record says the FBI dismantled a botnet of more than 200,000 consumer devices operated by Beijing-based Integrity Technology Group. Court records linked the company to the cluster called Flax Typhoon and described an application through which customers could control infected devices. The operation is evidence of a company-linked infrastructure service and state-sponsored activity; it should not be generalized to every Chinese security firm.
During conflict, doctrine suggests that cyber action would be combined with electronic warfare, space effects, deception, intelligence, precision strike, and influence. Initial objectives could include command, control, communications, computers, intelligence, surveillance, and reconnaissance; logistics; air and missile defense; and civilian functions essential to military movement. The 2025 U.S. defense report assesses that China could at least cause localized, temporary critical-infrastructure disruptions. The 2026 Annual Threat Assessment says U.S. intervention in a Taiwan conflict would probably face significant but recoverable transportation disruption from Chinese cyberattacks.
“Significant but recoverable” is more useful than cinematic language. It identifies a serious operational problem without pretending that public evidence supports unlimited capability. Defenders should map cyber key terrain: identity providers, remote management, edge devices, telecom control planes, logistics platforms, fuel scheduling, satellite links, port systems, engineering workstations, backup dependencies, and the people who can restore them. Resilience turns an adversary’s access into a temporary incident rather than strategic leverage.
The network becomes the collection platform: Salt Typhoon and supply-chain reach
If Volt Typhoon asks what access might do in war, Salt Typhoon shows what strategic access can collect in peace. In late 2024, governments disclosed compromises of major telecommunications providers. Telecom networks carry call records, location and routing data, private communications, authentication traffic, and the administrative systems that make lawful interception possible. Access at that layer can reveal who communicates with whom, identify high-value targets, and support follow-on operations even when message content is encrypted.
A December 2024 multinational telecommunications hardening guidance described a broad and significant espionage campaign by PRC-affiliated actors. In 2025, a much wider coalition issued the 2025 global network advisory. It documented targeting of telecommunications, government, transportation, lodging, and military infrastructure around the world; long-term modification of backbone and edge routers; movement through trusted connections; and activity partially overlapping several industry names, including Salt Typhoon.
The advisory carries an important warning about names: different vendors cluster evidence differently, and Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor are not necessarily one actor or a one-to-one match with government understanding. Campaign names help defenders exchange observations. They become misleading when treated as confirmed units, permanent teams, or proof that every incident shares one sponsor.
Telecommunications access creates compounding advantage. It can support political intelligence, counterintelligence, targeting of officials and dissidents, collection on military planning, and discovery of administrator identities. A compromised provider can become a bridge to customers. Router configuration changes may survive ordinary endpoint cleanup. Network telemetry can help distinguish genuine traffic from deception and can reveal how an adversary responds after public disclosure.
Supply chains extend the same logic. Instead of breaking into every desired victim, an operator can compromise an IT provider, remote-management relationship, cloud application, software account, or administrator whose privileges cross organizations. Public reporting on Silk Typhoon and the 2025 U.S. contract-hacker cases describes targeting of IT supply-chain and cloud relationships, including stolen API keys and credentials. The strategic pattern is not a single exotic implant; it is exploitation of concentrated trust.
Defenders should respond at the architecture level. Inventory externally reachable network devices and their support status. Centralize and preserve router, identity, cloud, and administrative logs away from the system that generated them. Replace shared accounts, restrict management paths, require phishing-resistant authentication, monitor configuration changes, and examine trusted interconnections. Assume that a compromised administrator or supplier may use legitimate tools. Segment lawful-intercept, billing, subscriber, and core-routing functions. Rehearse rebuilding a device from known-good configuration rather than trusting an in-place cleanup.
This is not merely a telecom problem. Hotels reveal travel. Managed-service providers reveal customer trust. Cloud tenants expose tokens and application permissions. Transport networks reveal movement. The information value lies in relationships across sectors, which is why an enterprise-only incident model can underestimate a state collector’s objective.
Taiwan and the contested information environment: prepare without predicting
Taiwan is where doctrine, collection, pre-positioning, military signaling, and information control most visibly converge. Beijing claims Taiwan and has not renounced the use of force. The PLA rehearses joint operations around the island, while Chinese intelligence and influence activity persists below armed conflict. Yet a capability assessment must not turn exercises into a calendar. The 2026 Annual Threat Assessment says Chinese leaders do not currently plan to invade Taiwan in 2027 and have no fixed timeline, even as the PLA develops options and Beijing seeks conditions favorable to unification.
Taiwan’s National Security Bureau reported that its government internet service network saw a daily average of 2.4 million intrusion attempts in 2024, double the 2023 figure, and said most were attributable to Chinese cyber forces. The Taiwan 2024 threat analysis describes targeting of government, critical infrastructure, and high-technology manufacturing. Attempt counts are telemetry from Taiwan’s defensive system, not unique successful compromises, and the issuing agency is a party to the conflict. The report remains valuable primary-source evidence when read with those limitations.
In a coercive campaign short of invasion, cyber operations could collect decision-making, expose or manipulate political communications, harass public services, steal defense and semiconductor information, or amplify narratives about government incompetence and military inevitability. During blockade or war, likely objectives expand: disrupt command and warning, complicate mobilization, degrade communications and logistics, interfere with ports and transport, collect battle-damage information, and pressure allies or commercial providers that sustain Taiwan.
Cyber action would be only one line of effort. Jamming, satellite interference, cable damage, legal claims, economic pressure, disinformation, military movement, and precision strikes could reinforce one another. A communications outage might come from malware, a severed cable, power loss, congestion, physical attack, or operator error. Attribution and restoration teams must work while public narratives compete to define the incident.
Influence is not reducible to false social-media posts. Cyber-enabled influence operations may acquire authentic material through intrusion, selectively release it, alter context, impersonate sources, or suppress trusted communication. Pro-China networks reported by platforms and researchers have attempted to shape debate across languages and countries, but audience reach and behavioral effect often lag behind production volume. Counted accounts do not equal persuasion.
Chinese censorship and domestic surveillance are also relevant without being identical to external cyberwarfare. The Great Firewall, real-name controls, platform moderation, data regulation, police access, and content campaigns limit what citizens can see and organize around. In crisis, this machinery can suppress casualty information, control mobilization narratives, counter dissent, and reduce foreign visibility into domestic reaction. It is an instrument of regime security and information control; whether a particular censorship action constitutes a military operation depends on authority, purpose, and conflict context.
Taiwan and its partners should prepare for combined failure. Maintain alternative communications, offline procedures, distributed backups, manual logistics, trusted public-information channels, and methods to authenticate official media. Exercise outages alongside manipulated documents and false attribution. Model civilian harm and reverberating effects across hospitals, payments, water, transport, and families—not just military availability. Resilience is both technical and social: people must know what to trust when networks and narratives fail together.
The 2026 assessment: formidable scale, real constraints and a disciplined way to brief it
By September 2026, the public evidence supports a formidable but bounded assessment. Chinese state-linked actors have repeatedly demonstrated global espionage, fast exploitation of exposed systems, theft of political and commercial information, compromise of identity-rich databases, use of contractors and covert relay infrastructure, persistent access to network devices, and strategic collection from telecommunications. PLA doctrine gives cyber operations a coherent place inside the contest for information dominance and joint-system effectiveness. The 2024 reorganization shows senior attention to the networks and data that connect the force.
The capability is not monolithic. PLA, MSS, MPS, local bureaus, companies, researchers, and contractors operate under different authorities and incentives. Reorganization imposes transition costs. Contracting expands capacity while producing leaks, poor operational security, criminal freelancing, and uncertain control. Public reporting reveals repeated dependence on unpatched internet-facing devices, stolen credentials, and ordinary administration tools; this is effective tradecraft, but not magical access.
Nor has China publicly demonstrated the kind of sustained destructive wartime campaign associated with Russian cyberwarfare capabilities in Ukraine. That absence does not prove inability. It means analysts should distinguish observed Chinese espionage and access from assessed wartime intent and classified military options. Comparison with United States cyberwarfare capabilities should likewise compare missions, authorities, alliances, access, resilience, and effects—not malware samples or budget totals alone.
The evidence base is adversarial. China publicly denies state-sponsored hacking allegations and describes itself as a victim of American cyber power. Western and Asian governments possess classified intelligence they cannot fully disclose. Vendors see slices of telemetry and use incompatible actor names. Criminal indictments reveal detailed evidence but contain allegations unless proved at trial. Chinese military media explains official priorities while serving political messaging. Japanese Japanese China Security Reports and the UK’s 2025 UK threat review add valuable external perspectives, not neutral omniscience.
A professional briefing should use four columns:
- Observed: the victim, access, artifact, behavior, duration, and effect directly supported by telemetry, legal records, or multiple independent sources.
- Attributed: the actor cluster, institutional link, confidence, issuing authority, and evidence that remains classified or inferential.
- Assessed: the likely intelligence or military purpose, alternatives considered, and indicators that would raise or lower confidence.
- Unknown: retained access, command relationship, wartime authorization, target knowledge, destructive reliability, collateral effects, and recovery under real conflict conditions.
For daily defense, concentrate on the terrain that repeated campaigns actually exploit. Patch and replace edge devices. Remove public management interfaces. Protect privileged and cloud identities with phishing-resistant authentication. Record network-device configuration and administrative activity. Hunt for legitimate-tool abuse and impossible account behavior. Separate corporate IT, operational technology, lawful-intercept, and recovery systems. Test suppliers and remote-support paths. Preserve evidence for attribution without delaying containment. Rehearse operating when telecommunications, identity, cloud, or logistics are unavailable.
Strategy begins after hygiene. Ask which national or organizational mission depends on each system; what information a patient collector would combine over years; which access could become coercive leverage in a crisis; how an outage would interact with propaganda or kinetic action; what legal and political authorities govern response; and which observable changes would indicate a shift from espionage to preparation for effects. Those questions convert a list of Chinese threat actors into a usable model of state power.
The final judgment should be neither complacent nor theatrical. China has built a broad cyber ecosystem capable of intelligence collection at exceptional scale and of establishing access with potential conflict value. Its doctrine seeks advantage by affecting systems and decision-making, not by winning an isolated duel between hackers. Yet access can be lost, organizations can miscoordinate, effects can fail, targets can recover, and strategic outcomes remain political. The defender’s task is to deny quiet access, reduce concentrated dependencies, preserve trustworthy information, and make disruption recoverable before a crisis gives the access meaning.
Frequently asked questions
What are China’s principal cyberwarfare capabilities?
Public evidence supports large-scale political, military, economic, and technological espionage; exploitation of internet-facing and edge devices; long-duration access to telecommunications and critical infrastructure; covert relay networks; cyber support to joint military operations; information and influence activity; and a state-linked contractor ecosystem. Foreign governments assess that China can create localized, temporary disruption during a conflict, but the most consequential wartime capabilities and accesses remain secret or untested in public.
Who conducts Chinese state cyber operations?
There is no single Chinese cyber command responsible for every campaign. Public reporting and legal records identify PLA elements, the Ministry of State Security and its provincial or municipal components, Ministry of Public Security-linked activity, state-owned or private contractors, research institutions, and other enablers. Commercial threat-actor names overlap and should never be treated as a reliable organizational chart.
What changed in the PLA’s 2024 reorganization?
China dissolved the Strategic Support Force and publicly presented a force structure under the Central Military Commission comprising the four services and four arms: the Military Aerospace Force, Cyberspace Force, Information Support Force, and Joint Logistics Support Force. Official descriptions assign the Information Support Force a central role in network information-system construction and support, while the Cyberspace Force is publicly associated with cyberspace defense and operations. Detailed command relationships and the redistribution of former Strategic Support Force missions remain incompletely visible.
Does Volt Typhoon prove China intends to attack civilian infrastructure?
The intrusions and persistent access are documented in multi-government advisories. U.S. agencies assess that the campaign pre-positioned access for disruption or destruction during a major crisis or conflict. That intent assessment is serious but is not the same as an observed destructive attack. China denies the attribution and describes Volt Typhoon as a U.S.-manufactured narrative. Analysts should record the observed access, the government assessment of purpose, the Chinese counterclaim, and the remaining evidentiary gap separately.
How does cyber fit into a possible Taiwan conflict?
Chinese doctrine treats information advantage and resilient command networks as conditions for joint operations rather than as a separate war. In a Taiwan contingency, cyber activity could support intelligence, deception, isolation, logistics disruption, attacks on command and communications, and pressure on external intervention. These are scenario-based assessments, not predictions that an invasion is imminent. The 2026 U.S. intelligence assessment explicitly says Chinese leaders do not currently plan an invasion in 2027 and have no fixed unification timeline.