i-Soon, also known as Shanghai Anxun Information Technology Co., Ltd. and Anxun Information, is a China-based information-security contractor implicated in Chinese state-linked cyber operations. U.S. authorities allege that the company worked with dozens of Ministry of State Security and Ministry of Public Security bureaus, conducted unauthorized intrusions, sold stolen data, and supplied intrusion platforms to Chinese intelligence and security customers. The company has been publicly associated with activity tracked as Aquatic Panda, Red Alpha, Red Hotel, Charcoal Typhoon, Red Scylla, Hassium, Chromium, and TAG-22. Reporting has also linked i-Soon to FishMonger/Earth Lusca activity, including deployments of SprySocks. i-Soon has targeted government bodies, foreign ministries, U.S. federal and state agencies, telecommunications providers, universities, healthcare entities, media organizations, religious organizations, and Chinese-government critics and dissidents. Its documented and marketed capabilities include phishing-based access acquisition; credential and token collection for persistent email collection; large-scale analysis, search, translation, and classification of stolen email and document repositories; remote-access tooling for multiple operating systems; system and process discovery; file collection and transfer; keylogging; screen capture; and pivoting through compromised systems. Malware associated with FishMonger has used kernel-level concealment to hide processes, files, network connections, and listening ports. Internal material exposed in 2024 indicated that i-Soon operated as a contractor serving provincial and municipal public-security customers, including through penetration services, data-exfiltration services, and intelligence production from stolen data. In 2025, the United States indicted eight i-Soon employees and two Ministry of Public Security officers alleged to have directed some company activity. The United Kingdom sanctioned i-Soon in 2025, and the European Union sanctioned the company and its co-founders Wu Haibo and Chen Cheng in 2026 for persistent malicious cyber activity. i-Soon’s operations are consistent primarily with state-directed cyberespionage, domestic surveillance, and suppression of perceived political opposition, with reported use of influence and impersonation activity in support of Chinese state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of a China-based intrusion company whose leaked documents reportedly showed commercialized espionage services and pricing for stolen data.
Named as a corporate partner of China Unicom and accused by the U.S. government of involvement in multiple hacking campaigns.
Private Chinese hacking contractor linked to operating FishMonger and supporting espionage operations involving SprySocks backdoor variants against government targets.
Private Chinese hacking contractor assessed to operate FishMonger for espionage, including long-term intelligence gathering and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.