Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionageunderground-data-leakremote-access-implantgovernment-diplomatic-threat

KnownSec Data Breach Exposes Chinese Cyber Tools and Global Target Lists

Updated 3mo agoFirst seen Nov 12, 20254 sources

Chinese cybersecurity firm KnownSec suffered a significant data breach, resulting in the leak of over 12,000 internal documents. The files, briefly posted on GitHub before removal, reportedly include details on KnownSec's contracts with Chinese government and military entities, internal hacking tools, and a spreadsheet listing 80 overseas targets. Analysis of the leaked data suggests the presence of remote access trojans (RATs) capable of compromising Linux, Windows, macOS, iOS, and Android systems, with some tools able to extract data from popular messaging apps such as Telegram and Chinese platforms. The breach also exposed large datasets, including 95GB of Indian immigration data, 3TB of call records from South Korea's LG U Plus, and 459GB of Taiwanese road planning data.

Security researchers and analysts have described the leak as an intelligence gold mine, providing rare insight into the operations of a major Chinese cyber contractor. While the exact motivation behind the leak remains unclear—whether it was the act of a disgruntled insider or an external hack-and-dump operation—the incident highlights the scale and scope of KnownSec's cyber activities, including its role in mapping foreign digital infrastructure and developing tools for state-sponsored operations. The exposure of these documents is likely to have significant implications for both Chinese cyber operations and the security of the affected international targets.

Share:
KnownSec Data Breach Exposes Chinese Cyber Tools and Global Target Lists
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Nov 11, 20258mo ago

Reports detail leaked KnownSec cyber tools, contracts, and target lists

Subsequent reporting said the leaked files exposed KnownSec's alleged Chinese government contracts, internally developed offensive tooling, and a broad target list covering organizations in multiple countries. Analysts also noted the newest leaked files appeared to date to 2023, suggesting the material was not current.

Nov 9, 20258mo ago

KnownSec internal documents are leaked online via GitHub

More than 12,000 internal documents from Chinese security firm KnownSec were briefly posted to GitHub by an unknown individual before being removed. Reporting said the source of the leak was unclear, with analysts considering either an insider leak or a hack-and-dump operation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

82 LINKEDOpen in app
Threat actors
3 linked
Malware
2 linked
Affected products
17 linked
TriofoxAndroidAzure Virtual DesktopTelegramVeracodeDrupalGithubCheck PointKubernetesZoomAmazon Web ServicesFirefoxKubernetesGithubDjangoDjangoChrome
Organizations
58 linked
MozillaDell TechnologiesCheck Point Software TechnologiesRockwell AutomationCisco SystemsAdvensNvidiaCensysGladinetSuper Micro ComputerElasticShodanLinkedinI-SoonABBPalo Alto NetworksSchneider ElectricSamsung ElectronicsSAPInternational Business MachinesSiemensMoxaKnownsecJaguar Land RoverKnowbe4Zoom CommunicationsAdvanced Micro DevicesDatadogVeracodeQNAP SystemsSynologyAsahi Group HoldingsMeta PlatformsFortinetPython Package IndexIvantiD-LinkCyberProofQualcommKirin HoldingsAppleMicrosoft CorporationGitHubAdobeYahooIntelNewsGuardBank of EnglandQuad9ProwlerMayaStealthMoleZoomEyeNetAskariLG UplusBinaryEdgeAssociation of British InsurersMrxn
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.