Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Support State Operations


China’s cyber operations now rely on a broad commercial ecosystem of private contractors, freelance hackers, data brokers, and infrastructure providers. These groups can build malware, manage botnets, steal data, and sell access or intelligence to government customers, making attribution harder than in older state-backed hacking cases.

A new analysis from BindingHook argues that many Chinese cyber campaigns should be understood through “composite responsibility,” a model where different public and private entities contribute different parts of the same operation. In this view, a single campaign may include a government customer, a contractor, a malware provider, a botnet operator, and a data broker.

The model helps explain why recent activity linked to Salt Typhoon, Flax Typhoon, Volt Typhoon, i-Soon, and APT27 often looks less like a single hacking unit and more like an interconnected market. The FBI has also warned that China’s government uses formal and informal ties with freelance hackers and information security companies to compromise networks worldwide.

Commercial Firms Are Now Part of State Cyber Operations

The clearest recent example is Salt Typhoon-related activity against telecommunications and critical networks. The UK’s National Cyber Security Centre and international partners publicly linked three China-based technology companies to a global campaign targeting government, telecommunications, transportation, lodging, and military infrastructure.

The named companies were Sichuan Juxinhe Network Technology Co Ltd, Beijing Huanyu Tianqiong Information Technology Co, and Sichuan Zhixin Ruijie Network Technology Co Ltd. UK officials said these firms provide cyber-related services to Chinese intelligence services and form part of a wider commercial ecosystem that includes information security companies, data brokers, and hackers for hire.

BindingHook said this is why older APT labels can be too narrow. A label such as Salt Typhoon may describe observed activity, but it may not fully explain who requested the operation, who built the tooling, who supplied the infrastructure, who stole the data, and who ultimately used the results.

How the Contractor Model Works

LayerRole in operationsExample from public reporting
Government customerSets intelligence priorities or buys access and stolen dataMSS and MPS bureaus named in U.S. government cases
Private contractorConducts intrusions, sells tools, or performs tasking for state customersi-Soon, also known as Anxun Information Technology
Infrastructure providerBuilds or manages botnets and covert networksIntegrity Technology Group and the Raptor Train botnet
Freelance hackerSteals data for profit and sells it to multiple buyersAPT27-linked actors Yin Kecheng and Zhou Shuai
Data brokerResells stolen information or network accessShanghai Heiying Information Technology Company

The i-Soon case gave researchers and investigators one of the clearest looks at this marketplace. SentinelOne’s analysis of the I-Soon leak said the documents showed how government targeting requirements can drive a competitive contractor market for hacking services.

The U.S. Justice Department later charged 12 Chinese nationals, including i-Soon employees, two Ministry of Public Security officers, and APT27-linked actors. The Justice Department said China’s Ministry of Public Security and Ministry of State Security used private companies and contractors to hack and steal information while obscuring the government’s involvement.

Botnets Give Operators Scale and Plausible Deniability

Botnets and covert networks are another key part of the system. The UK NCSC guidance on China-nexus covert networks says many China-linked actors have moved away from individually procured infrastructure and toward large networks of compromised SOHO routers, IoT devices, smart devices, and other internet-connected systems.

These networks help attackers hide the origin of malicious activity. They can also support scanning, malware delivery, command-and-control traffic, data exfiltration, and general browsing during reconnaissance.

The Raptor Train botnet shows how a private company can play an infrastructure role. The U.S. Justice Department said the botnet was developed and controlled by Integrity Technology Group, a Beijing-based company, and that its online application allowed customers to control infected devices.

Integrity Tech and Flax Typhoon Show the Risk

The U.S. Treasury later sanctioned Integrity Technology Group for its role in multiple intrusion incidents against U.S. victims. According to the Treasury Department, those incidents were publicly attributed to Flax Typhoon, a China-based state-sponsored group active since at least 2021.

U.S. officials said Flax Typhoon actors used infrastructure tied to Integrity Tech between summer 2022 and fall 2023. The company’s role matters because it shows how a commercial provider can become a key enabler of state-linked intrusions, even when the hands-on operators sit elsewhere.

The Raptor Train disruption also showed why compromised edge devices are so valuable. Routers, cameras, NAS devices, and other exposed systems often receive poor patching and can sit quietly inside attacker-controlled networks for long periods.

Stolen Data Has Become a Separate Marketplace

The same ecosystem also includes data brokers who profit from stolen information. The Treasury Department sanctioned Zhou Shuai and Shanghai Heiying Information Technology Company in March 2025, saying Zhou sold illegally obtained data and access to compromised networks.

U.S. officials said at least some of the data sold by Zhou came from Yin Kecheng, a previously sanctioned China-linked cyber actor. The same action described victims that included technology companies, a defense industrial base contractor, a communications service provider, an academic health system, and a local government entity.

The Justice Department charges also alleged that Yin and Zhou stole data, brokered it for sale, and provided it to various customers, only some of whom had links to the Chinese government or military. That detail is important because it shows how cyber espionage and cybercrime can overlap inside the same contractor-driven environment.

Why This Makes Attribution Harder

Security teams often want a simple answer about who carried out an intrusion. In these cases, that answer may not be enough. One company may provide malware, another may provide infrastructure, another may execute the intrusion, and another may resell the stolen data.

The NCSC Salt Typhoon advisory announcement said activity linked to China-based commercial entities had targeted nationally significant organizations around the world and partially overlapped with activity previously tracked by industry under the Salt Typhoon name.

The contractor model also gives state customers flexibility. Agencies can buy access, order collection, reuse commercial tools, or accept data stolen speculatively by profit-driven hackers. This can expand the number of victims and make defensive tracking harder.

Defenders Should Focus on Behavior, Not Just Actor Names

Organizations should not rely only on APT names or static IP blocklists. The NCSC covert network guidance warns that a single covert network may be used by multiple actors and that these networks constantly change as new devices are compromised and old nodes disappear.

Defenders should map internet-facing assets, remove unsupported devices, patch edge systems quickly, and monitor for unusual authentication and traffic patterns. High-risk organizations should also hunt for signs of activity from compromised SOHO routers, IoT devices, and other infrastructure commonly used as relays.

  • Patch internet-facing routers, firewalls, VPNs, NAS devices, and appliances quickly.
  • Remove end-of-life devices that no longer receive security updates.
  • Restrict management interfaces to trusted networks or VPN access.
  • Use multi-factor authentication for all remote access and administrator accounts.
  • Review logs for unusual VPN, RDP, SSH, and cloud access activity.
  • Monitor outbound traffic for unusual destinations, tunneling, and data transfer patterns.
  • Segment critical systems so one compromised device cannot expose the whole network.
  • Use threat hunting to detect behavior, not only known indicators.

The Bigger Picture

China-linked cyber operations now appear more distributed, commercial, and modular than older public attribution models suggest. Contractors, brokers, and infrastructure providers can each support one part of the same campaign.

The FBI public service announcement described this as a system that gives the Chinese government plausible deniability while encouraging broad, profit-driven compromise of networks worldwide.

For defenders, the lesson is clear. Treat exposed edge devices, weak credentials, and unmanaged infrastructure as priority risks. These are the systems that contractor-driven operations often exploit first, and they can provide the quiet access needed for espionage, botnet activity, and data theft.

Researchers will continue to debate how much responsibility belongs to each actor in a given campaign. However, SentinelOne’s I-Soon research, public government actions, and botnet disruption cases all point to the same trend: modern Chinese cyber operations increasingly depend on a commercial support layer.

The Integrity Tech sanctions and the Zhou Shuai data broker sanctions show that governments are now targeting not only individual hackers, but also the companies and brokers that enable them.

FAQ

What are Chinese cyber contractors?

Chinese cyber contractors are private companies, freelance hackers, information security firms, and data brokers that provide hacking tools, infrastructure, stolen data, or operational support that can be used by Chinese state agencies or state-linked actors.

Why are Chinese cyber operations harder to attribute now?

Attribution is harder because one campaign may involve several different actors. A government agency may request intelligence, a contractor may conduct the intrusion, another company may provide infrastructure, and a data broker may resell stolen information.

What is composite responsibility in cyber operations?

Composite responsibility is a framework for analyzing operations where multiple entities contribute different parts of a campaign. Instead of treating one APT name as the full answer, it separates the roles of customers, hackers, contractors, infrastructure providers, and data brokers.

What was the Raptor Train botnet?

Raptor Train was a large network of compromised devices linked by U.S. authorities to Integrity Technology Group and Flax Typhoon-related activity. It included compromised routers, IoT devices, cameras, NAS devices, and other internet-connected systems.

How can organizations defend against contractor-driven cyber operations?

Organizations should patch internet-facing devices, remove unsupported hardware, restrict management access, enforce multi-factor authentication, monitor unusual traffic, review logs, segment critical systems, and hunt for suspicious behavior rather than relying only on static indicators.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages