But does this add much security if bad actors are using VPNs ?
At any rate, blocking China and Russia isn't ever presented as a foolproof defence, it just raises the barrier to attack.
Either way, nothing is full proof. It is part of a solid defense in depth [1].
[1] https://en.m.wikipedia.org/wiki/Defense_in_depth_(computing)
But does this add much security if bad actors are using VPNs ?