惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Chinese Cyber Contractors Use Malware, Botnets, and Stole...
Tushar Subhra Dutta · 2026-06-22 · via Cyber Security News

China’s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker.

Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry out espionage on behalf of its intelligence services.

The scale and sophistication of this ecosystem have surprised even seasoned security researchers.

At the center of this network are private technology firms that develop and sell hacking tools, build botnets, steal data, and resell access to government clients.

Operations attributed to groups like Salt Typhoon, Flax Typhoon, and Volt Typhoon reveal how Chinese state-sponsored campaigns now depend on a thriving commercial layer to function.

These private players supply everything from malware and network infrastructure to raw stolen data, turning cyber espionage into a marketplace.

Analysts at BindingHook identified a new framework for understanding these operations, calling it “composite responsibility.”

Rather than assigning an entire campaign to one APT label, this model recognizes that a single operation may involve multiple entities, each playing a distinct role and bearing a different level of responsibility.

BindingHook said in a report shared with Cyber Security News (CSN) details how the US and its partners attributed Salt Typhoon, one of the most damaging cyber espionage campaigns against Western telecommunications infrastructure, to at least three China-based private firms.

These companies reportedly provide cyber-related products and services to China’s intelligence services, with the UK’s NCSC stating they “enabled” the activity. Yet as of mid-2025, the tasking relationships and specific roles of these firms remain largely undescribed publicly.

The leaked internal documents from I-Soon, a Chinese private contractor tied to the Ministry of State Security and Ministry of Public Security, offered a rare window into how this model works.

I-Soon employees conducted intrusions as contractors, fed results back to government clients, and managed campaigns targeting at least 14 governments.

The leak confirmed that Chinese cyber operations are not monolithic but layered, commercially driven ecosystems.

Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data

Private-sector entities in China have become the backbone of state-sponsored hacking campaigns, supplying tools, infrastructure, and stolen data to government buyers.

The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41.

This shows that responsibility can extend to the company that commercialized malicious software, not just the hackers who deployed it.

The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model.

It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.

Both the US and UK governments sanctioned Integrity Tech for controlling a covert cyber network and providing technical assistance to those conducting attacks.

Data brokering adds yet another layer to these operations. Individuals linked to APT27, including Yin Kecheng and Zhou Shuai, conducted hacking campaigns and then sold stolen data to multiple customers, some of which were Chinese government entities.

In some cases, data stolen by Yin was resold through i-Soon, introducing additional resale layers between the original intrusion and the end consumer.

Strengthening Defenses Against These Threats

Security teams facing these layered threats should begin by mapping all network-connected devices and developing a clear understanding of normal traffic patterns.

Using multi-factor authentication, restricting access through allowlists, and adopting zero-trust architectures are all recommended steps for organizations at elevated risk. Real-time threat intelligence feeds can help defenders identify botnet activity before it enables a larger intrusion.

For high-risk environments, authorities advise actively hunting for suspicious traffic from consumer-grade devices such as SOHO routers, since these are commonly enrolled into covert networks.

Organizations should monitor network traffic flows to detect unusual behavior patterns that could indicate hidden infrastructure.

Applying network segmentation and deploying host-based intrusion detection systems further limits the damage an attacker can do once inside.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.