Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇨🇳 CN2 malware families

I-Soon

Also known asi-SOON

I-SOON, also known as Shanghai Anxun Information Technology Co., Ltd. and referred to as i-Soon/i_soon, is a China-based private cybersecurity contractor described as part of China’s hacker-for-hire and state contracting ecosystem. The provided content characterizes it as a lower-tier contractor that provided hacking, surveillance, and intelligence-gathering services primarily to Chinese public security customers, and as a certified supplier to the Ministry of Public Security. It is described as likely working for the Chinese state, with reporting linking it to China-based threat activity including APT41 and overlaps with clusters such as Fishmonger and Earth Lusca. According to the leaked internal documents cited in the content, I-SOON was founded in Shanghai in 2010, had roughly 70-100 employees, maintained subsidiaries in Chengdu, Yunnan, and Jiangsu, and established an “APT research” division in 2013 for overseas projects. Its leaked files reportedly included contracts, quotations, technical attack materials, internal chats, and customer information. The company’s customers were described as provincial and municipal public security bureaus and departments across multiple Chinese provinces. The content also states that the UK sanctioned I-SOON for cyber activities against the UK and its allies. The content indicates I-SOON’s operational strength was post-compromise exploitation and intelligence production rather than initial access or exploit development. Reported capabilities included Windows malware/RAT functionality such as command execution, file and service management, screen capture, keylogging, and pivoting; a Linux implant called Hector with plugin-based architecture and HTTP/HTTPS/websocket C2; referenced macOS malware; and mobile malware for iOS and Android capable of collecting device identifiers, location, files, contacts, microphone audio, and in some Android cases SMS/IM data, Wi‑Fi/camera control, traffic capture, and persistence with root. The leak also described platforms for ingesting, searching, classifying, and operationalizing stolen emails and documents, including Outlook-, Gmail-, POP3/IMAP-, and Twitter-focused collection platforms using phishing, malicious executables, credentials, and tokens for continuous collection. The provided reporting states that I-SOON used or sold spyware and had penetrated targets including Hong Kong government departments, universities, telecommunications providers, and a broad set of government, military, telecom, NGO, and academic entities across multiple continents. NHK reporting cited in the content alleges I-SOON conducted operations for the Chinese government that included theft of internal European Union documents, impersonation of overseas dissidents, spreading false information about Fukushima wastewater discharge in Japan, and online influence activity intended to trigger xenophobic demonstrations in Taiwan. The content also notes that its social-media and “public opinion” tooling may have been overstated and likely was not suited to large-scale information warfare compared with true troll-farm operations. The content further notes that leaked chats and DOJ materials indicated Zhou Shuai brokered the sale of Yin Kecheng’s work through i-SOON, placing the company within a broader Chinese offensive cyber ecosystem connected to activity tracked under Silk Typhoon/Hafnium. It also describes I-SOON as part of China’s loosely controlled contractor ecosystem, often subcontracting to larger firms, with poor morale and low-paying contracts. After the February 2024 leak of hundreds of internal files, NHK reported that I-SOON’s Shanghai office had been vacated and that some employees were reportedly taken away by police.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics62 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
3 techniques
T1589
Gather Victim Identity Information
T1592
Gather Victim Host Information
T1596
Search Open Technical Databases
TA0042
Resource Development
1 technique
T1586
Compromise Accounts
T1586.001
Social Media Accounts
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.003×2
Windows Command Shell
TA0003
Persistence
3 techniques
T1078
Valid Accounts
T1112
Modify Registry
T1542
Pre-OS Boot
T1542.003
Bootkit
TA0004
Privilege Escalation
3 techniques
T1068
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1548
Abuse Elevation Control Mechanism
TA0005
Stealth
4 techniques
T1014
Rootkit
T1027
Obfuscated Files or Information
T1078
Valid Accounts
T1542
Pre-OS Boot
T1542.003
Bootkit
TA0112
Defense Impairment
2 techniques
T1112
Modify Registry
T1601
Modify System Image
TA0006
Credential Access
7 techniques
T1003
OS Credential Dumping
T1040
Network Sniffing
T1056
Input Capture
T1056.001×2
Keylogging
T1110
Brute Force
T1528×2
Steal Application Access Token
T1557
Adversary-in-the-Middle
T1557.004
Evil Twin
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
6 techniques
T1007
System Service Discovery
T1012
Query Registry
T1016
System Network Configuration Discovery
T1040
Network Sniffing
T1057
Process Discovery
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001
Remote Desktop Protocol
TA0009
Collection
7 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001×2
Keylogging
T1113
Screen Capture
T1114×2
Email Collection
T1123
Audio Capture
T1213×3
Data from Information Repositories
T1213.002
Sharepoint
T1557
Adversary-in-the-Middle
T1557.004
Evil Twin
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001×2
Web Protocols
T1090
Proxy
T1090.001
Internal Proxy
T1095×2
Non-Application Layer Protocol
T1219
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1020
Automated Exfiltration
T1041
Exfiltration Over C2 Channel
TA0040
Impact
2 techniques
T1498
Network Denial of Service
T1657
Financial Theft
IOCS

Observables

28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

sentinelone labsNews
Apr 23, 2026
China’s Covert Capabilities | Silk Spun From Hafnium | SentinelOne

Chinese offensive cyber contractor described as a lower-tier subcontractor and broker in the PRC hacking ecosystem, involved in brokering or subcontracting offensive work rather than being presented here as the primary operator of the Hafnium activity.

Read more
risky biz rssNews
Dec 4, 2025
Srsly Risky Biz: When Do Cyber Campaigns Cross a Line?

I-Soon is a Chinese contractor involved in state-sponsored cyber operations, including mass exploitation of vulnerabilities such as Microsoft Exchange.

Read more
harfanglab insidethelabNews
Mar 4, 2025
A comprehensive analysis of I-Soon's commercial offering - HarfangLab

China-based commercial hacking-for-hire / intelligence contractor providing intrusion services (access acquisition, data exfiltration, intelligence production) and tooling to Chinese public-sector customers (notably public security bureaus). Operations emphasize phishing/credential theft and large-scale data exploitation platforms (email/Outlook token siphoning, analytics/classification) more than in-house exploit development; tooling includes Windows/Linux/macOS/mobile implants and operational infrastructure/OPSEC support.

Read more
natto thoughts blogNews
Jan 8, 2025
Chengdu: Teahouses, Hotpots, Universities and … Hackers

i-SOON is a Chinese information security company based in Chengdu, linked to APT41 and believed to operate as a hacker-for-hire for the Chinese state. The company has provided cyber range platforms to local universities and has been involved in cyber operations.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping45

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables28

Domains, IPs, and hashes tied to this actor, refreshed continuously.

I-Soon | Mallory