cognitive cybersecurity intelligence

News and Analysis

Search

Researchers Say a ‘Ghost’ Chinese Company Built the Network Hiding PLA Cyberattacks

Researchers Say a ‘Ghost’ Chinese Company Built the Network Hiding PLA Cyberattacks

A little-known Chinese company may have helped build the hidden network used to support military-linked cyber operations around the world.

Researchers say Guangdong Chanming, a firm with no obvious public-facing business, appears connected to tools designed to conceal online activity and move traffic through multiple systems.

The company’s alleged role matters because covert relay networks can make it much harder for defenders to identify where an intrusion began or who is behind it.

Recent reporting on China linked contractor operations has also highlighted how private firms can provide infrastructure and services that support state-backed espionage.

IntrusionTruth analysts identified the apparent link after reviewing company filings, software records, patents, and military procurement documents.

IntrusionTruth said in a report shared with Cyber Security News (CSN) that the evidence points to Guangdong Chanming as a supplier of anonymous networking technology to Chinese state customers.

The research does not describe a conventional malware outbreak with a single victim list or initial access method.

PLA procurement contracts (Source – IntrusionTruth)

Instead, it outlines the infrastructure layer behind cyber campaigns, including software that may help operators hide command traffic, relay data, and reduce the chance that victims can trace activity back to its source.

‘Ghost’ Chinese Company

Guangdong Chanming reportedly has no public website, storefront, or visible commercial product catalogue.

Yet its registered patents and software copyrights describe products with names such as Internet Security Access System, Multi-functional Security Proxy System, File Transfer Network System, Security Tunnel Network, and Anti-traceability Network System.

Several recorded product titles also reference an Android Secret Extraction System and Telegram Data Collection System.

While names alone do not prove operational use, they suggest that the company’s work extended beyond ordinary consumer networking products and into surveillance, data collection, and concealment capabilities.

The researchers found procurement listings naming Guangdong Chanming as a supplier to the People’s Liberation Army.

STN file (Source – IntrusionTruth)

One listing reportedly describes an Anonymous Network System delivered to a military unit in Beijing’s Haidian District, an area that hosts major Chinese military and technology organizations.

That connection is significant because Haidian is also associated with the PLA Cyberspace Force, the branch responsible for China’s military cyber operations.

The report argues that the company’s network technology could have provided a practical layer of cover for operators running long-term espionage campaigns.

The alleged setup resembles other cases in which covert access tools blend into legitimate-looking traffic or use relay systems to complicate investigation.

Defenders tracking Chinese proxy tunnel activity should treat unusual encrypted connections, unfamiliar proxy services, and unexplained outbound routes as possible warning signs.

FCN Links to WHIPWEAVE

The investigation centers on Wang Huiping, one of Guangdong Chanming’s listed shareholders.

Researchers linked a phone number associated with Wang to an email address that was also connected to FCN, or FreeConnect, a software project that was once hosted on GitHub under the handle “boywhp.”

Although the original repository was removed, forks remained online and pointed researchers to the xfconnect.com domain.

VirusTotal results for files tied to that domain included samples that researchers said resembled stn.exe, a file described as part of an STN Security Tunnel product.

A (Red)Relay from Haidian to Guangdong (Source – IntrusionTruth)

Researchers also found that Linux versions of FCN used an unusual command to identify a network interface.

Searching for that distinctive command led them to “bulbature,” a file associated with WHIPWEAVE malware, which has been linked to the RedRelay or ORBWEAVER covert network.

The overlap does not by itself establish that every FCN user participated in state operations.

However, IntrusionTruth argues that the shared development clues, patent descriptions, and procurement records create a stronger picture of a commercial toolset that may have evolved into infrastructure used by Chinese threat actors.

The report links RedRelay use to a cluster known by many names, including Red Vulture, APT15, Ke3chang, Vixen Panda, Playful Dragon, and Nylon Typhoon.

It further associates the activity with PLA Unit 61046 and the Cyberspace Force’s 8th Bureau, though such attribution should be assessed alongside independent evidence.

Organizations at elevated risk should monitor outbound network traffic for unfamiliar relays, investigate unexpected Linux binaries, and preserve logs that could reveal multi-hop connections.

Strong segmentation, multi-factor authentication, and network visibility remain essential, especially as persistent Chinese threat groups continue to target high-value systems.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionDomainxfconnect.comDomain linked by researchers to FCN/FreeConnect tracesEmail addressboywhpat126.comEmail address associated with Wang Huiping in the reportGitHub repository FCN-related repository fork cited by researchersFile namestn.exeFile described as STN Security TunnelFile namebulbatureFile associated with WHIPWEAVE malwareSHA-25668ee37b260facbae2869b57c85471bce156726b69ebe8a90af400fedb188b143FCN-related binary referenced through VirusTotalSHA-2567b9aa96c19d342b9a352cac8e53b116edc92b871afca86b6b8d6ea834678f029stn.exe-related binary referenced through VirusTotal

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post Researchers Say a ‘Ghost’ Chinese Company Built the Network Hiding PLA Cyberattacks appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Comprehensive Human Vagus Nerve Map Unveiled

Comprehensive Human Vagus Nerve Map Unveiled

Scientists at Northwell Health’s Feinstein Institutes for Medical Research said they have released the world’s first comprehensive human vagus nerve anatomical map. The achievement could