Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Support State Operations
China’s cyber operations now rely on a broad commercial ecosystem of private contractors, freelance hackers, data brokers, and infrastructure providers. These groups can build malware, manage botnets, steal data, and sell access or intelligence to government customers, making attribution harder than in older state-backed hacking cases.
A new analysis from BindingHook argues that many Chinese cyber campaigns should be understood through “composite responsibility,” a model where different public and private entities contribute different parts of the same operation. In this view, a single campaign may include a government customer, a contractor, a malware provider, a botnet operator, and a data broker.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
The model helps explain why recent activity linked to Salt Typhoon, Flax Typhoon, Volt Typhoon, i-Soon, and APT27 often looks less like a single hacking unit and more like an interconnected market. The FBI has also warned that China’s government uses formal and informal ties with freelance hackers and information security companies to compromise networks worldwide.
Commercial Firms Are Now Part of State Cyber Operations
The clearest recent example is Salt Typhoon-related activity against telecommunications and critical networks. The UK’s National Cyber Security Centre and international partners publicly linked three China-based technology companies to a global campaign targeting government, telecommunications, transportation, lodging, and military infrastructure.
The named companies were Sichuan Juxinhe Network Technology Co Ltd, Beijing Huanyu Tianqiong Information Technology Co, and Sichuan Zhixin Ruijie Network Technology Co Ltd. UK officials said these firms provide cyber-related services to Chinese intelligence services and form part of a wider commercial ecosystem that includes information security companies, data brokers, and hackers for hire.
BindingHook said this is why older APT labels can be too narrow. A label such as Salt Typhoon may describe observed activity, but it may not fully explain who requested the operation, who built the tooling, who supplied the infrastructure, who stole the data, and who ultimately used the results.
How the Contractor Model Works
| Layer | Role in operations | Example from public reporting |
|---|---|---|
| Government customer | Sets intelligence priorities or buys access and stolen data | MSS and MPS bureaus named in U.S. government cases |
| Private contractor | Conducts intrusions, sells tools, or performs tasking for state customers | i-Soon, also known as Anxun Information Technology |
| Infrastructure provider | Builds or manages botnets and covert networks | Integrity Technology Group and the Raptor Train botnet |
| Freelance hacker | Steals data for profit and sells it to multiple buyers | APT27-linked actors Yin Kecheng and Zhou Shuai |
| Data broker | Resells stolen information or network access | Shanghai Heiying Information Technology Company |
The i-Soon case gave researchers and investigators one of the clearest looks at this marketplace. SentinelOne’s analysis of the I-Soon leak said the documents showed how government targeting requirements can drive a competitive contractor market for hacking services.
The U.S. Justice Department later charged 12 Chinese nationals, including i-Soon employees, two Ministry of Public Security officers, and APT27-linked actors. The Justice Department said China’s Ministry of Public Security and Ministry of State Security used private companies and contractors to hack and steal information while obscuring the government’s involvement.
Botnets Give Operators Scale and Plausible Deniability
Botnets and covert networks are another key part of the system. The UK NCSC guidance on China-nexus covert networks says many China-linked actors have moved away from individually procured infrastructure and toward large networks of compromised SOHO routers, IoT devices, smart devices, and other internet-connected systems.
These networks help attackers hide the origin of malicious activity. They can also support scanning, malware delivery, command-and-control traffic, data exfiltration, and general browsing during reconnaissance.
The Raptor Train botnet shows how a private company can play an infrastructure role. The U.S. Justice Department said the botnet was developed and controlled by Integrity Technology Group, a Beijing-based company, and that its online application allowed customers to control infected devices.
Integrity Tech and Flax Typhoon Show the Risk
The U.S. Treasury later sanctioned Integrity Technology Group for its role in multiple intrusion incidents against U.S. victims. According to the Treasury Department, those incidents were publicly attributed to Flax Typhoon, a China-based state-sponsored group active since at least 2021.
U.S. officials said Flax Typhoon actors used infrastructure tied to Integrity Tech between summer 2022 and fall 2023. The company’s role matters because it shows how a commercial provider can become a key enabler of state-linked intrusions, even when the hands-on operators sit elsewhere.
The Raptor Train disruption also showed why compromised edge devices are so valuable. Routers, cameras, NAS devices, and other exposed systems often receive poor patching and can sit quietly inside attacker-controlled networks for long periods.
Stolen Data Has Become a Separate Marketplace
The same ecosystem also includes data brokers who profit from stolen information. The Treasury Department sanctioned Zhou Shuai and Shanghai Heiying Information Technology Company in March 2025, saying Zhou sold illegally obtained data and access to compromised networks.
U.S. officials said at least some of the data sold by Zhou came from Yin Kecheng, a previously sanctioned China-linked cyber actor. The same action described victims that included technology companies, a defense industrial base contractor, a communications service provider, an academic health system, and a local government entity.
The Justice Department charges also alleged that Yin and Zhou stole data, brokered it for sale, and provided it to various customers, only some of whom had links to the Chinese government or military. That detail is important because it shows how cyber espionage and cybercrime can overlap inside the same contractor-driven environment.
Why This Makes Attribution Harder
Security teams often want a simple answer about who carried out an intrusion. In these cases, that answer may not be enough. One company may provide malware, another may provide infrastructure, another may execute the intrusion, and another may resell the stolen data.
The NCSC Salt Typhoon advisory announcement said activity linked to China-based commercial entities had targeted nationally significant organizations around the world and partially overlapped with activity previously tracked by industry under the Salt Typhoon name.
The contractor model also gives state customers flexibility. Agencies can buy access, order collection, reuse commercial tools, or accept data stolen speculatively by profit-driven hackers. This can expand the number of victims and make defensive tracking harder.
Defenders Should Focus on Behavior, Not Just Actor Names
Organizations should not rely only on APT names or static IP blocklists. The NCSC covert network guidance warns that a single covert network may be used by multiple actors and that these networks constantly change as new devices are compromised and old nodes disappear.
Defenders should map internet-facing assets, remove unsupported devices, patch edge systems quickly, and monitor for unusual authentication and traffic patterns. High-risk organizations should also hunt for signs of activity from compromised SOHO routers, IoT devices, and other infrastructure commonly used as relays.
- Patch internet-facing routers, firewalls, VPNs, NAS devices, and appliances quickly.
- Remove end-of-life devices that no longer receive security updates.
- Restrict management interfaces to trusted networks or VPN access.
- Use multi-factor authentication for all remote access and administrator accounts.
- Review logs for unusual VPN, RDP, SSH, and cloud access activity.
- Monitor outbound traffic for unusual destinations, tunneling, and data transfer patterns.
- Segment critical systems so one compromised device cannot expose the whole network.
- Use threat hunting to detect behavior, not only known indicators.
The Bigger Picture
China-linked cyber operations now appear more distributed, commercial, and modular than older public attribution models suggest. Contractors, brokers, and infrastructure providers can each support one part of the same campaign.
The FBI public service announcement described this as a system that gives the Chinese government plausible deniability while encouraging broad, profit-driven compromise of networks worldwide.
For defenders, the lesson is clear. Treat exposed edge devices, weak credentials, and unmanaged infrastructure as priority risks. These are the systems that contractor-driven operations often exploit first, and they can provide the quiet access needed for espionage, botnet activity, and data theft.
Researchers will continue to debate how much responsibility belongs to each actor in a given campaign. However, SentinelOne’s I-Soon research, public government actions, and botnet disruption cases all point to the same trend: modern Chinese cyber operations increasingly depend on a commercial support layer.
The Integrity Tech sanctions and the Zhou Shuai data broker sanctions show that governments are now targeting not only individual hackers, but also the companies and brokers that enable them.
FAQ
Chinese cyber contractors are private companies, freelance hackers, information security firms, and data brokers that provide hacking tools, infrastructure, stolen data, or operational support that can be used by Chinese state agencies or state-linked actors.
Attribution is harder because one campaign may involve several different actors. A government agency may request intelligence, a contractor may conduct the intrusion, another company may provide infrastructure, and a data broker may resell stolen information.
Composite responsibility is a framework for analyzing operations where multiple entities contribute different parts of a campaign. Instead of treating one APT name as the full answer, it separates the roles of customers, hackers, contractors, infrastructure providers, and data brokers.
Raptor Train was a large network of compromised devices linked by U.S. authorities to Integrity Technology Group and Flax Typhoon-related activity. It included compromised routers, IoT devices, cameras, NAS devices, and other internet-connected systems.
Organizations should patch internet-facing devices, remove unsupported hardware, restrict management access, enforce multi-factor authentication, monitor unusual traffic, review logs, segment critical systems, and hunt for suspicious behavior rather than relying only on static indicators.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages