Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

Rivian cuts DOE loan to $4.5 billion for Georgia plant

Sources: Anthropic Potential $900B+ Valuation Round Could Happen Within 2 Weeks

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Sources: Anthropic Potential $900B+ Valuation Round Could Happen Within 2 Weeks

    1 May 2026

    Meta says its business AI now facilitates 10 million conversations per week

    30 April 2026

    Amazon’s cloud business is growing — and so is its capital spending

    30 April 2026

    Firestorm Labs raises $82 million to bring drone factories to the field

    29 April 2026

    YouTube is testing an AI-powered search feature that shows guided answers

    28 April 2026
  • Apps

    ChatGPT Images 2.0 is a hit in India, but not a big winner elsewhere, yet

    1 May 2026

    Spotify introduces verified artist badges to distinguish humans from artificial intelligence

    30 April 2026

    Google gains 25 million subscribers in Q1, thanks to YouTube and Google One

    30 April 2026

    Meet Shapes, the app that brings humans and artificial intelligence into the same group chats

    29 April 2026

    Amazon is launching an AI-powered audio Q&A experience on product pages

    29 April 2026
  • Crypto

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025
  • Fintech

    Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

    1 May 2026

    Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

    30 April 2026

    Steve Ballmer slams founder he backed, who pleaded guilty to fraud: ‘I was cheated and I feel stupid’

    25 April 2026

    Salmon raises $100 million in equity and debt to bring digital credit to unbanked Filipinos

    24 April 2026

    Cash App targets a new type of customer: children aged 6 to 12 years

    22 April 2026
  • Hardware

    As Tim Cook departs, Apple hits record sales — but chip shortage looms

    1 May 2026

    More Gemini features are coming to Google TV

    30 April 2026

    OpenAI could be building a phone with AI agents that replace apps

    28 April 2026

    SpeakOn’s dictation device is a good idea marred by platform limitations

    27 April 2026

    What Tim Cook Built | TechCrunch

    27 April 2026
  • Media & Entertainment

    Roku’s $3 streaming service Howdy hits 1 million subscribers, per recent report

    29 April 2026

    Australia forces Big Tech companies to pay for news or face 2.25% tax.

    28 April 2026

    India’s app market is booming — but global platforms are raking in most of the profits

    23 April 2026

    YouTube extends its AI similarity detection technology to celebrities

    21 April 2026

    Deezer says 44% of songs uploaded to its platform every day are created with artificial intelligence

    20 April 2026
  • Security

    Hackers are actively exploiting a bug in cPanel, which is used by millions of websites

    30 April 2026

    Sri Lanka reveals another missing payment, days after hackers stole $2.5 million from its finance ministry

    29 April 2026

    The US Supreme Court appears divided on the controversial use of ‘geofence’ search warrants.

    29 April 2026

    Paragon is not cooperating with Italian authorities investigating spyware attacks, the report said

    28 April 2026

    Critical infrastructure giant Itron says it was breached

    28 April 2026
  • Startups

    Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

    1 May 2026

    Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

    30 April 2026

    BCI startup Neurable wants to license ‘mind reading’ technology to wearable consumer devices

    29 April 2026

    Founder of Shark Tank-backed startup Sholly sues buyer Sallie Mae

    29 April 2026

    Lachy Groom to back Indian startup Pronto at $200m valuation, sources say

    26 April 2026
  • Transportation

    Rivian cuts DOE loan to $4.5 billion for Georgia plant

    1 May 2026

    Uber is now in the hospitality industry, thanks in part to artificial intelligence

    29 April 2026

    TechCrunch Mobility: Elon’s Acceptance | TechCrunch

    27 April 2026

    Production of the Rivian R2 has begun despite tornado damage at the factory

    25 April 2026

    Porsche is adding an all-electric Cayenne coupe to its lineup

    24 April 2026
  • Venture

    The climate tech IPO window could finally open

    30 April 2026

    Sources: Anthropic Could Raise New $50B Round at $900B Valuation

    30 April 2026

    BMW i Ventures Has a New $300M Fund and AI Rides Shotgun

    29 April 2026

    How a venture firm invests in an increasingly fragmented world

    29 April 2026

    Stanford freshmen who want to rule the world. . . he will probably read this book and try even harder

    27 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Spyware leak offers ‘first-of-its-kind’ look at Chinese government hacking efforts
Security

Spyware leak offers ‘first-of-its-kind’ look at Chinese government hacking efforts

techtost.comBy techtost.com23 February 202405 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Spyware Leak Offers 'first Of Its Kind' Look At Chinese Government Hacking Efforts
Share
Facebook Twitter LinkedIn Pinterest Email

During the weekendsomeone posted a cache of files and documents apparently stolen by Chinese government hacking contractor I-Soon.

This leak gives cybersecurity researchers and rival governments an unprecedented opportunity to look behind the curtain of Chinese government hacking operations facilitated by private contractors.

Like hack-and-leak mode that targeted Italian spyware maker Hacking Team in 2015, the I-Soon leak includes corporate documents and internal communications that show I-Soon was allegedly involved in hacking companies and government agencies in India, Kazakhstan, Malaysia , Pakistan, Taiwan and Thailand, among others.

The leaked files were published on the code sharing site GitHub the manufacture. Since then, watchers of Chinese hacking operations have feverishly poured over the files.

“This represents the most significant data breach linked to a company suspected of providing cyberespionage and targeted intrusion services for Chinese security services,” said Jon Condra, threat intelligence analyst at cybersecurity firm Recorded Future.

For John Hultquist, the chief analyst at Google-owned Mandiant, this leak is “narrow, but deep,” he said. “Rarely do we have such unfettered access to the inner workings of any intelligence enterprise.”

Dakota Cary, an analyst at cybersecurity firm SentinelOne, he wrote in a blog publishes that “this leak provides a first-of-its-kind look into the inner workings of a state-linked hacking contractor.”

And, ESET malware researcher Matthieu Tartare said the leak “could help threat intelligence analysts link some of the compromises they’ve seen to I-Soon.”

One of the first people to go through the leak was a threat intelligence researcher from Taiwan who goes by the name Azaka. Azaka on Sunday posted a long thread at X, formerly Twitter, analyzing some of the documents and files, which don’t appear until 2022. The researcher highlighted spyware developed by I-Soon for Windows, Mac, iPhone and Android devices, as well as hardware hacking devices designed to be used in real-world situations that can crack Wi-Fi passwords, locate Wi-Fi devices, and disrupt Wi-Fi signals.

I-Soon’s ‘WiFi Near Field Attack System’, a device to hack Wi-Fi networks that comes disguised as an external battery. (Screenshot: Azaka)

“We researchers finally have a confirmation that this is how things work there and that APT teams work almost like all of us regular workers (except they get paid horribly),” Azaka told TechCrunch, “that the scale is decently large, that there is a lucrative market for hacking large government networks.” APT, or advanced persistent threats, are hacking groups that are usually supported by a government.

According to the investigators’ analysis, the documents show that I-Soon worked for China’s Ministry of Public Security, Ministry of State Security, and the Chinese army and navy. and I-Soon have also marketed and marketed their services to local law enforcement agencies across China to help target minorities such as Tibetans and Uighurs, a Muslim community living in the western Chinese region of Xinjiang.

Documents link I-Soon to APT41, a Chinese government hacker group which has reportedly been in business since 2012, targeting organizations in different healthcare, telecommunications, technology, and video gaming industries around the world.

Also, an IP address found in the I-Soon leak hosted a phishing site that digital rights organization Citizen Lab saw used against Tibetans in a 2019 hacking campaign. Citizen Lab researchers at the time named the hacking group “Poison Carp.”

Azaka, as well as others, also found logs of conversations between I-Soon employees and management, some of them extremely mundane, such as employees talking about gambling and playing the popular tile-based Chinese game mahjong.

Cary highlighted documents and conversations that show how much — or how little — I-Soon employees are paid.

Contact us

Do you know more about I-Soon or Chinese government hacks? From a non-working device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or via email. You can also contact TechCrunch via SecureDrop.

“$55,000 is being paid [US] — in 2024 dollars — to hack the Ministry of Economy of Vietnam, is not a lot of money for such a goal,” Cary told TechCrunch. “It makes me think how cheap it is for China to execute an operation against a high-value target. And what does that say about the nature of the organization’s security?’

What the leak also shows, according to Cary, is that researchers and cybersecurity firms should carefully consider the potential future actions of mercenary hacking groups based on their past activity.

“It demonstrates that a threat actor’s past targeting behavior, particularly when they are a Chinese government contractor, is not indicative of their future targets,” Cary said. “So it’s not helpful to look at this organization and say, ‘They only hacked the healthcare industry, or they hacked industry X, Y, Z and they’re hacking these countries.’ They respond to them [government] the agencies request. And these services may ask for something different. They may start work with a new office and a new location.”

The Chinese embassy in Washington did not respond to a request for comment.

An email sent to I-Soon’s support inbox went unanswered. Two anonymous employees of I-Soon he told the Associated Press that the company held a meeting on Wednesday and told staff that the leak would not affect their business and to “continue business as usual”.

At this point, there is no information on who posted the leaked documents and files and GitHub recently removed the leaked cache from its platform. But several researchers agree that the most likely explanation is a disgruntled current or former employee.

“The people who put this leak together gave her a table of contents. And the table of contents of the leak is the workers complaining about the low pay, the financial conditions of the business,” Cary said. “The leak is structured in a way that embarrasses the company.”

China Chinese cyber security efforts firstofitskind government hacker Hacking leak Leakage offers Spyware suitable
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTwo years after Russia’s invasion, Ukraine’s military startups continue
Next Article Apple’s iPhone business in India is outpacing individual EU countries, says Morgan Stanley
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Hackers are actively exploiting a bug in cPanel, which is used by millions of websites

30 April 2026

Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

30 April 2026

Sri Lanka reveals another missing payment, days after hackers stole $2.5 million from its finance ministry

29 April 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

1 May 2026

Rivian cuts DOE loan to $4.5 billion for Georgia plant

1 May 2026

Sources: Anthropic Potential $900B+ Valuation Round Could Happen Within 2 Weeks

1 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

1 May 2026

Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

30 April 2026

Steve Ballmer slams founder he backed, who pleaded guilty to fraud: ‘I was cheated and I feel stupid’

25 April 2026
Startups

Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

BCI startup Neurable wants to license ‘mind reading’ technology to wearable consumer devices

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.