{"id":13779,"date":"2026-06-22T10:03:55","date_gmt":"2026-06-22T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/22\/chinese-cyber-contractors-use-malware-botnets-and-stolen-data-to-enable-state-operations\/"},"modified":"2026-06-22T10:03:55","modified_gmt":"2026-06-22T10:03:55","slug":"chinese-cyber-contractors-use-malware-botnets-and-stolen-data-to-enable-state-operations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/22\/chinese-cyber-contractors-use-malware-botnets-and-stolen-data-to-enable-state-operations\/","title":{"rendered":"Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations"},"content":{"rendered":"<p>    Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">China\u2019s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. <\/p>\n<p class=\"wp-block-paragraph\">Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry out espionage on behalf of its intelligence services. <\/p>\n<p class=\"wp-block-paragraph\">The scale and sophistication of this ecosystem have surprised even seasoned security researchers.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">At the center of this network are private technology firms that develop and sell hacking tools, build botnets, steal data, and resell access to government clients. <\/p>\n<p class=\"wp-block-paragraph\">Operations attributed to groups like Salt Typhoon, Flax Typhoon, and Volt Typhoon reveal how Chinese state-sponsored campaigns now depend on a thriving commercial layer to function. <\/p>\n<p class=\"wp-block-paragraph\">These <a href=\"https:\/\/cybersecuritynews.com\/malware-analysis\/\" id=\"82355\" target=\"_blank\" rel=\"noreferrer noopener\">private players supply everything from malware and network infrastructure<\/a> to raw stolen data, turning cyber espionage into a marketplace.<\/p>\n<p class=\"wp-block-paragraph\">Analysts at\u00a0BindingHook\u00a0identified a new framework for understanding these operations, calling it \u201ccomposite responsibility.\u201d <\/p>\n<p class=\"wp-block-paragraph\">Rather than assigning an entire campaign to one APT label, this model recognizes that a single operation may involve multiple entities, each playing a distinct role and bearing a different level of responsibility.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" id=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BindingHook said\u00a0in a report<\/a>\u00a0shared with Cyber Security News (CSN) details how the US and its partners attributed Salt Typhoon, one of the most damaging cyber espionage campaigns against Western telecommunications infrastructure, to at least three China-based private firms. <\/p>\n<p class=\"wp-block-paragraph\">These companies reportedly provide cyber-related products and services to China\u2019s intelligence services, with the UK\u2019s NCSC stating they \u201cenabled\u201d the activity. Yet as of mid-2025, the tasking relationships and specific roles of these firms remain largely undescribed publicly.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The leaked internal documents from I-Soon, a Chinese private contractor tied to the Ministry of State Security and Ministry of Public Security, offered a rare window into how this model works. <\/p>\n<p class=\"wp-block-paragraph\">I-Soon employees conducted intrusions as contractors, fed results back to government clients, and managed campaigns targeting at least 14 governments. <\/p>\n<p class=\"wp-block-paragraph\">The leak confirmed that Chinese cyber operations are not monolithic but layered, commercially driven ecosystems.<\/p>\n<h2 id=\"h-chinese-cyber-contractors-use-malware-botnets-and-stolen-data\" class=\"wp-block-heading\"><strong>Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Private-sector entities in China have become the backbone of state-sponsored hacking campaigns, supplying tools, infrastructure, and stolen data to government buyers. <\/p>\n<p class=\"wp-block-paragraph\">The privately developed ShadowPad backdoor was sold to multiple suspected PLA units, including RedFoxtrot and Tonto Team, and shared with entities like Chengdu404, whose staff were charged for activity attributed to APT41. <\/p>\n<p class=\"wp-block-paragraph\">This shows that responsibility can extend to the company that commercialized malicious software, not just the hackers who deployed it.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. <\/p>\n<p class=\"wp-block-paragraph\">It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon. <\/p>\n<p class=\"wp-block-paragraph\">Both the US and UK governments sanctioned Integrity Tech for controlling a covert cyber network and providing technical assistance to those conducting attacks.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/microsoft-brokering-file-system-vulnerability\/\" id=\"137353\" target=\"_blank\" rel=\"noreferrer noopener\">Data brokering adds yet another layer to these operations<\/a>. Individuals linked to APT27, including Yin Kecheng and Zhou Shuai, conducted hacking campaigns and then sold stolen data to multiple customers, some of which were Chinese government entities. <\/p>\n<p class=\"wp-block-paragraph\">In some cases, data stolen by Yin was resold through i-Soon, introducing additional resale layers between the original intrusion and the end consumer.<a href=\"https:\/\/bindinghook.com\/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-strengthening-defenses-against-these-threats\" class=\"wp-block-heading\"><strong>Strengthening Defenses Against These Threats<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Security teams facing these layered threats should begin by mapping all network-connected devices and developing a clear understanding of normal traffic patterns. <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/microsoft-multi-factor-authentication-issue\/\" id=\"88334\" target=\"_blank\" rel=\"noreferrer noopener\">Using multi-factor authentication, restricting access through allowlists<\/a>, and adopting zero-trust architectures are all recommended steps for organizations at elevated risk. Real-time threat intelligence feeds can help defenders identify botnet activity before it enables a larger intrusion.<a href=\"https:\/\/www.linkedin.com\/pulse\/global-cyber-agencies-warn-expanding-china-linked-hooge\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">For high-risk environments, authorities advise actively hunting for suspicious traffic from consumer-grade devices such as SOHO routers, since these are commonly enrolled into covert networks. <\/p>\n<p class=\"wp-block-paragraph\">Organizations should monitor network traffic flows to detect unusual behavior patterns that could indicate hidden infrastructure. <\/p>\n<p class=\"wp-block-paragraph\">Applying network segmentation and deploying host-based intrusion detection systems further limits the damage an attacker can do once inside.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-cyber-contractors-use-malware-botnets-and-stolen-data\/\">Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-cyber-contractors-use-malware-botnets-and-stolen-data\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations China\u2019s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13779","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13779"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13779"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13779\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}