Private Contractor Linked to Multiple Chinese State-Sponsored Groups

June 13, 2025, 8:51 p.m.

Description

A recent leak from I-SOON, a Chinese IT and cybersecurity company, has revealed connections to several state-sponsored cyber groups including RedAlpha, RedHotel, and Poison Carp. The leak exposes a sophisticated espionage network involving the theft of communications data for individual tracking. Analysis confirms operational and organizational ties between I-SOON and these groups, highlighting I-SOON's role as a digital quartermaster providing shared cyber capabilities in China's aggressive cyber ecosystem. Despite the leak, I-SOON is expected to continue operations with minor adjustments. The revelation enhances understanding of Chinese cyber espionage and may impact future US legal actions against I-SOON operatives.

Date

  • Created: June 13, 2025, 7:49 p.m.
  • Published: June 13, 2025, 7:49 p.m.
  • Modified: June 13, 2025, 8:51 p.m.

Attack Patterns

Additional Informations

  • China
  • United States of America