Researchers Say a ‘Ghost’ Chinese Company Built the Network Hiding PLA Cyberattacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A little-known Chinese company may have helped build the hidden network used to support military-linked cyber operations around the world.

Researchers say Guangdong Chanming, a firm with no obvious public-facing business, appears connected to tools designed to conceal online activity and move traffic through multiple systems.

The company’s alleged role matters because covert relay networks can make it much harder for defenders to identify where an intrusion began or who is behind it.

Recent reporting on China linked contractor operations has also highlighted how private firms can provide infrastructure and services that support state-backed espionage.

IntrusionTruth analysts identified the apparent link after reviewing company filings, software records, patents, and military procurement documents.

IntrusionTruth said in a report shared with Cyber Security News (CSN) that the evidence points to Guangdong Chanming as a supplier of anonymous networking technology to Chinese state customers.

The research does not describe a conventional malware outbreak with a single victim list or initial access method.

PLA procurement contracts (Source – IntrusionTruth)

Instead, it outlines the infrastructure layer behind cyber campaigns, including software that may help operators hide command traffic, relay data, and reduce the chance that victims can trace activity back to its source.

‘Ghost’ Chinese Company

Guangdong Chanming reportedly has no public website, storefront, or visible commercial product catalogue.

Yet its registered patents and software copyrights describe products with names such as Internet Security Access System, Multi-functional Security Proxy System, File Transfer Network System, Security Tunnel Network, and Anti-traceability Network System.

Several recorded product titles also reference an Android Secret Extraction System and Telegram Data Collection System.

While names alone do not prove operational use, they suggest that the company’s work extended beyond ordinary consumer networking products and into surveillance, data collection, and concealment capabilities.

The researchers found procurement listings naming Guangdong Chanming as a supplier to the People’s Liberation Army.

STN file (Source – IntrusionTruth)

One listing reportedly describes an Anonymous Network System delivered to a military unit in Beijing’s Haidian District, an area that hosts major Chinese military and technology organizations.

That connection is significant because Haidian is also associated with the PLA Cyberspace Force, the branch responsible for China’s military cyber operations.

The report argues that the company’s network technology could have provided a practical layer of cover for operators running long-term espionage campaigns.

The alleged setup resembles other cases in which covert access tools blend into legitimate-looking traffic or use relay systems to complicate investigation.

Defenders tracking Chinese proxy tunnel activity should treat unusual encrypted connections, unfamiliar proxy services, and unexplained outbound routes as possible warning signs.

FCN Links to WHIPWEAVE

The investigation centers on Wang Huiping, one of Guangdong Chanming’s listed shareholders.

Researchers linked a phone number associated with Wang to an email address that was also connected to FCN, or FreeConnect, a software project that was once hosted on GitHub under the handle “boywhp.”

Although the original repository was removed, forks remained online and pointed researchers to the xfconnect.com domain.

VirusTotal results for files tied to that domain included samples that researchers said resembled stn.exe, a file described as part of an STN Security Tunnel product.

A (Red)Relay from Haidian to Guangdong (Source – IntrusionTruth)

Researchers also found that Linux versions of FCN used an unusual command to identify a network interface.

Searching for that distinctive command led them to “bulbature,” a file associated with WHIPWEAVE malware, which has been linked to the RedRelay or ORBWEAVER covert network.

The overlap does not by itself establish that every FCN user participated in state operations.

However, IntrusionTruth argues that the shared development clues, patent descriptions, and procurement records create a stronger picture of a commercial toolset that may have evolved into infrastructure used by Chinese threat actors.

The report links RedRelay use to a cluster known by many names, including Red Vulture, APT15, Ke3chang, Vixen Panda, Playful Dragon, and Nylon Typhoon.

It further associates the activity with PLA Unit 61046 and the Cyberspace Force’s 8th Bureau, though such attribution should be assessed alongside independent evidence.

Organizations at elevated risk should monitor outbound network traffic for unfamiliar relays, investigate unexpected Linux binaries, and preserve logs that could reveal multi-hop connections.

Strong segmentation, multi-factor authentication, and network visibility remain essential, especially as persistent Chinese threat groups continue to target high-value systems.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain xfconnect.com Domain linked by researchers to FCN/FreeConnect traces
Email address boywhpat126.com Email address associated with Wang Huiping in the report
GitHub repository https://github.com/longzai2651/fcn- Remaining FCN-related repository fork cited by researchers
File name stn.exe File described as STN Security Tunnel
File name bulbature File associated with WHIPWEAVE malware
SHA-256 68ee37b260facbae2869b57c85471bce156726b69ebe8a90af400fedb188b143 FCN-related binary referenced through VirusTotal
SHA-256 7b9aa96c19d342b9a352cac8e53b116edc92b871afca86b6b8d6ea834678f029 stn.exe-related binary referenced through VirusTotal

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.