i-SOON, also known as Shanghai Anxun Information Technology Co., Ltd., Anxun Information, and I-Soon, is a China-based private cybersecurity contractor widely assessed to operate as a hacker-for-hire in support of Chinese state security and public security interests. Public reporting and legal actions have linked the company to China’s Ministry of Public Security ecosystem, with allegations that it worked with numerous provincial and municipal security bureaus and supported broader Chinese nation-state cyber operations. The company has also been associated with activity clusters and aliases including Deepclif, Dragnet Panda, Hassium, Houndstooth Typhoon, Aquatic Panda, Red Alpha, Red Hotel, Charcoal Typhoon, Red Scylla, Chromium, and TAG-22. Reporting also links i-SOON to FishMonger, also known as Earth Lusca, which is believed to be operated by the contractor for long-term intelligence collection and data theft. i-SOON’s operations are characterized primarily by espionage, surveillance, and information operations rather than financially motivated crime. Leaked internal materials and subsequent investigations indicate that the company marketed intrusion services, access acquisition, data exfiltration, and intelligence production from stolen data to Chinese government customers. Its comparative strength appears to have been post-compromise exploitation and large-scale processing of stolen communications and documents, including platforms for email ingestion, search, translation, classification, and operational analysis. The company also advertised or used tooling for social-media monitoring and manipulation, credential harvesting, and continuous collection from online accounts. The actor has been linked to intrusions against government agencies, foreign ministries, telecommunications providers, universities, media organizations, dissidents, religious organizations, and other public-sector and civil-society targets across Asia and beyond. High-confidence reporting ties i-SOON-linked activity to targeting in Taiwan, Hong Kong, Pakistan, Thailand, Honduras, and other countries in Asia, Central America, Europe, and Africa. Reported victim sectors include government, public safety, foreign affairs, telecommunications, health care, academia, and media. The company has also been accused of supporting influence operations, including impersonation of overseas dissidents, spreading false narratives related to Japan, and online manipulation intended to exacerbate social tensions in Taiwan. Tradecraft attributed to i-SOON includes phishing, credential theft, data exfiltration, cross-platform malware deployment, persistence, and defense evasion. Leaked product descriptions and malware analyses indicate capabilities spanning Windows, Linux, macOS, iOS, and Android, including remote access trojans, keylogging, screen capture, file management, service management, microphone activation, traffic capture, and pivoting through compromised hosts. Reporting on FishMonger-linked malware associated with i-SOON describes advanced post-exploitation capability, including command-and-control over multiple protocols, kernel-level rootkit functionality to hide processes, files, registry artifacts, and network connections, and possible use of a UEFI bootkit exploiting CVE-2023-24932 for deep persistence and stealth. The actor has also been associated with collection from telecommunications systems and location-related subscriber data, underscoring a surveillance and intelligence-gathering mission set. i-SOON is notable as an example of China’s contractor-based offensive cyber ecosystem, in which nominally private firms provide operational support, tooling, and deniability for state-directed activity. U.S., U.K., and E.U. authorities have sanctioned the company, and U.S. indictments have named multiple employees and alleged Chinese public security officers connected to its operations. The available evidence consistently supports assessment of i-SOON as a Chinese state-aligned intrusion and surveillance contractor focused on espionage, repression-related targeting, and influence support operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a corporate partner of China Unicom and accused by the U.S. government of involvement in multiple hacking campaigns.
Private Chinese hacking contractor linked to operating FishMonger and supporting espionage operations involving SprySocks backdoor variants against government targets.
Private Chinese hacking contractor assessed to operate FishMonger for espionage, including long-term intelligence gathering and data theft.
Chinese offensive cyber contractor described as a lower-tier subcontractor and broker in the PRC hacking ecosystem, involved in brokering or subcontracting offensive work rather than being presented here as the primary operator of the Hafnium activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.