Anything you do is going to impact performance on your site. It sucks, I'm sorry.
If you go the .htaccess route, every single new connection will get pattern matched against the _deny from_ patterns. It's a bit better using CIDR notation, but still, every connection will take a slight hit as the pattern match is run. I assume that Drupal does a similar pattern matching scheme to block/permit access.
A determined adversary will realize that you’re blocking by IP addresses and resort to something like TOR or a VPN to crawl your site.
Another option is to use something like IPTables with some intelligence on your server site to dynamically block anyone slurping lots of data off the site (but be certain to whitelist Google/Bing/other "friendly" crawlers).
You could try something slightly bizarre: on detecting adversarial traffic from what you suspect is a Chinese client, return the complete works of the Dalai Lama, a history of tibet, possibly treatises on Falun Gong or the true history of Tiananmen square, and put the Great Firewall to use for you. Depending on the ISP and the day’s censorship regime, you might get the GFW to block your site from access from behind the GFW. You don't care, you don't want the traffic anyway, and from the GFW's perspective your site will be marked as a "dangerous" site with inappropriate content for consumption in China.