A Lawfare review of the book Full Stack Spies argues that cyber operations are best understood not as isolated campaigns but as products of wider ecosystems joining hackers, companies, state institutions, and markets. The book examines cyber espionage across three interconnected levels—tradecraft, statecraft, and instability—and aims to bridge the persistent gap between technical specialists, who focus on mechanics, and policymakers, who focus on strategy.
The book's central device is an "upstairs-downstairs" split. At the top sit state and technology company leadership making strategic decisions; below them are the hackers, analysts, and engineers who translate those choices into operations. This framework helps explain why cyber capability varies: China's linked threat groups share tooling, skills, and suppliers, but not necessarily command, as techniques circulate through a labor market faster than affiliations.
The review also flags attribution problems. The book assigns Salt Typhoon to the MSS's Sichuan provincial bureau and Volt Typhoon to the PLA, but the public record is uneven. For Salt Typhoon, U.S. government reporting ties the campaign to an MSS-linked contractor but stops short of naming the Sichuan bureau. For Volt Typhoon, a 2024 NCSC publication and testimony from former officials point to the PLA, yet neither the NSC nor Microsoft has publicly made that attribution directly, even though the book presents it as an NSC determination.
These distinctions matter, the review argues, because inconsistently articulated attributions leave space for Beijing to dispute the claims. The book also devotes substantial attention to Russia, placing US-China competition within a broader strategic landscape that includes other state actors.