216.73.216.6

Yet Another Leak of China's Contractor-Driven Cyber-Espionage Ecosystem

· Published 10/01/2026 13:29 · Modified 12/01/2026 12:14

Export JSON

Essential information

Published
10/01/2026 13:29
Modified
12/01/2026 12:14
Tags
2026-01-10 china contractor critical-infrastructure cyber espionage ghostx passive radar public security taiwan un-mail zoomeye
Related entities
6 observables, 1 intrusion sets (apt), 11 techniques (mitre), 3 malware, 15 others

Description

The Knownsec leak exposes a state-aligned Chinese cyber deeply integrated with national security and intelligence operations. Internal documents reveal Knownsec's role in developing offensive cyber capabilities, large-scale reconnaissance systems, and data fusion platforms for bureaus and military clients. Key products include for global IP scanning, for exploitation, and for covert network mapping. The leak provides unprecedented insight into Knownsec's organizational structure, personnel, and strategic targeting of foreign critical infrastructure, particularly in and other Asian countries. It demonstrates how commercial entities like Knownsec function as core components of 's cyber-espionage ecosystem, blending state objectives with industrial-scale development of intrusion and surveillance technologies.

External references