Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagetelecommunications-sector-threatgovernment-diplomatic-threatcybercrime-service-ecosystem

I-Soon Leak Exposes Chinese State-Linked Hacking Operations

Updated 21d agoFirst seen May 25, 20263 sources

A leaked trove of internal files from Chinese contractor I-Soon exposed tools, target lists, pricing documents, and operational details tied to cyber-espionage work reportedly conducted on behalf of Chinese government entities. Reporting indicates the material links I-Soon to intrusions and surveillance activity targeting foreign governments, telecommunications providers, ethnic minorities, dissidents, and online platforms, while also outlining services such as account compromise, data theft, social media monitoring, and infrastructure support for offensive operations.

The disclosures provide a rare inside view of China’s contractor ecosystem, showing how a private firm allegedly supplied hacking capabilities to public security and intelligence customers through a commercialized menu of services. Researchers and media reports said the leak included screenshots, chat logs, and project records that appeared to document operational workflows, victim targeting, and the broader relationship between state agencies and outsourced cyber operators, offering unusual transparency into how Chinese cyber-espionage campaigns may be organized and monetized.

Share:
I-Soon Leak Exposes Chinese State-Linked Hacking Operations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 27, 20242y ago

Researchers report Chinese APT campaigns targeting ASEAN-linked entities

On or around the March 2024 ASEAN-Australia Special Summit, Palo Alto Networks Unit 42 observed Mustang Panda targeting organizations in Myanmar, the Philippines, Japan, and Singapore, while also noting a separate breach of an ASEAN-affiliated victim. Trend Micro separately reported Earth Krahang had targeted 116 entities in 35 countries since early 2022, with overlaps suggesting links to Earth Lusca and contractor I-Soon.

Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries
Feb 22, 20242y ago

Researchers analyze leak and detail I-Soon's cyber operations

Security researchers and media outlets analyzed the leaked I-Soon materials and published findings describing the company's offensive cyber capabilities, pricing, victim targeting, and relationships with Chinese state customers. These reports framed the leak as a rare window into China's contractor-based cyber ecosystem.

Feb 16, 20242y ago

Large cache of I-Soon internal files leaks online

A substantial trove of internal documents, chat logs, contracts, and tooling information from Chinese cybersecurity contractor I-Soon was posted publicly, exposing details of the firm's operations and customers. The leak revealed apparent links between I-Soon and Chinese government and public security entities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Affected products
1 linked
Openfire
Organizations
9 linked
Trend MicroI-SoonPalo Alto NetworksBishop FoxRecorded FutureReliaQuestSentinelOneMargin ResearchComm100
Breaches
1 linked
COMM100-2024-03
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.