China’s Cyber Espionage Relies on a Vast Network of Private Contractors
China’s state-sponsored cyber operations have evolved into a sophisticated ecosystem of private companies, contractors, and data brokers that conduct espionage on behalf of intelligence agencies. Unlike traditional models of government-led hacking, this system leverages commercial entities to develop tools, steal data, and resell access to state clients, creating a layered, market-driven approach to cyber warfare.
Security researchers, including those at BindingHook, have identified this model as "composite responsibility", where multiple private firms contribute distinct roles to a single campaign. For example, the Salt Typhoon espionage operation targeting Western telecommunications infrastructure was attributed to at least three China-based firms, though their exact relationships with intelligence agencies remain unclear. The UK’s National Cyber Security Centre (NCSC) confirmed these companies "enabled" the activity, but details of their involvement are still undisclosed as of mid-2025.
A rare glimpse into this system came from leaked internal documents of I-Soon, a contractor linked to China’s Ministry of State Security (MSS) and Ministry of Public Security (MPS). The leaks revealed that I-Soon employees conducted intrusions, managed campaigns against at least 14 governments, and fed results back to government clients, demonstrating a decentralized, commercially driven structure.
Private firms supply everything from malware to botnets and stolen data to state buyers. The ShadowPad backdoor, sold to suspected PLA units and shared with groups like Chengdu404 (APT41), illustrates how responsibility extends beyond hackers to the companies that commercialize malicious tools. Similarly, the Raptor Train botnet, developed by Integrity Technology Group, was disrupted by the U.S. and led to sanctions against the firm for enabling Flax Typhoon operations.
Data brokering further complicates attribution. Individuals tied to APT27, such as Yin Kecheng and Zhou Shuai, conducted hacking campaigns and sold stolen data to multiple buyers, including government entities. Some data was resold through i-Soon, adding layers between the original breach and end users.
This contractor-driven model presents new challenges for defenders, as attacks may originate from multiple, seemingly unrelated entities. While mitigation strategies such as zero-trust architectures, network segmentation, and real-time threat intelligence are recommended, the core shift is structural: China’s cyber operations are no longer monolithic but a fragmented, commercially integrated ecosystem.
Source: https://cybersecuritynews.com/chinese-cyber-contractors-use-malware-botnets-and-stolen-data/
Cybertec.group cybersecurity rating report: https://www.rankiteo.com/company/cybertec-group
"id": "CYB1782124232",
"linkid": "cybertec-group",
"type": "Cyber Attack",
"date": "6/2025",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': 'Telecommunications',
'location': 'Western countries',
'name': 'Western telecommunications infrastructure',
'type': 'Critical Infrastructure'},
{'industry': 'Public Sector',
'name': '14 governments',
'type': 'Government'}],
'attack_vector': ['Malware', 'Botnets', 'Backdoors'],
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Stolen data, espionage-related '
'information'},
'date_publicly_disclosed': '2025',
'description': 'China’s state-sponsored cyber operations have evolved into a '
'sophisticated ecosystem of private companies, contractors, '
'and data brokers that conduct espionage on behalf of '
'intelligence agencies. This system leverages commercial '
'entities to develop tools, steal data, and resell access to '
'state clients, creating a layered, market-driven approach to '
'cyber warfare.',
'impact': {'data_compromised': True,
'systems_affected': ['Telecommunications infrastructure']},
'initial_access_broker': {'backdoors_established': ['ShadowPad',
'Raptor Train botnet'],
'data_sold_on_dark_web': True},
'investigation_status': 'Ongoing',
'lessons_learned': 'China’s cyber operations are no longer monolithic but a '
'fragmented, commercially integrated ecosystem. The '
'contractor-driven model presents new challenges for '
'defenders due to attacks originating from multiple, '
'seemingly unrelated entities.',
'motivation': 'State-sponsored espionage',
'post_incident_analysis': {'root_causes': 'Decentralized, commercially driven '
'cyber espionage model leveraging '
'private contractors and data '
'brokers.'},
'recommendations': ['Zero-trust architectures',
'Network segmentation',
'Real-time threat intelligence'],
'references': [{'source': 'BindingHook'},
{'source': 'UK’s National Cyber Security Centre (NCSC)'},
{'source': 'Leaked internal documents of I-Soon'}],
'regulatory_compliance': {'legal_actions': ['U.S. sanctions against Integrity '
'Technology Group']},
'response': {'enhanced_monitoring': 'Recommended',
'network_segmentation': 'Recommended'},
'threat_actor': ['China-based private contractors',
'I-Soon',
'Chengdu404 (APT41)',
'APT27',
'Salt Typhoon',
'Flax Typhoon'],
'title': 'China’s Cyber Espionage Relies on Private Contractors',
'type': 'Cyber Espionage'}