China Eagle Union is an early Chinese “red hacker” group that emerged in the late 1990s and 2000s as part of the formative wave of patriotic Chinese hacking communities. It is commonly discussed alongside other prominent groups such as the Green Army and the Honker Union of China. The group is associated with China’s nationalist hacktivist milieu, which developed around politically charged regional events and helped shape the broader Chinese underground and quasi-patriotic cyber ecosystem. The group was founded by Wan Tao, also known as “eagle.” Like other Chinese hacker communities of its era, China Eagle Union appears to have combined a large public-facing membership base with a much smaller operational core. Archived reporting cited approximately 50 core members in the mid-2000s, while the group’s website reportedly had more than 113,000 registered users by 2007. This disparity reflects a common structure in early Chinese hacker organizations: low-barrier forum registration created very large nominal membership figures, but actual technical operations were conducted by a comparatively small number of skilled members, supported by additional personnel handling administration, logistics, and community functions. China Eagle Union belonged to a broader ecosystem characterized by community-oriented forums, mentorship, and patriotic identity rather than the overtly profit-driven marketplace model more typical of Russian cybercriminal forums. Early Chinese hacking groups of this type were influential in normalizing collaboration between technically skilled civilians and state institutions. Chinese patriotic hacking communities have been described as a recruiting environment from which some individuals later moved into government roles or work connected to the Ministry of State Security or the People’s Liberation Army. China Eagle Union is best understood as a historically significant nationalist hacktivist collective rather than a modern ransomware or financially motivated intrusion set. High-confidence reporting supports its role in the development of China’s early patriotic hacker scene, but does not provide sufficient corroborated detail to attribute specific malware families, intrusion campaigns, or a distinct long-term operational playbook uniquely to this group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese red-hacker collective with very large registered user base but a comparatively small core membership (tens) assessed as the real operational/technical nucleus; used forums/community structure to organize and discuss campaigns.
Early Chinese patriotic hacking group involved in internet defacements, DDoS attacks, and credential theft targeting the U.S. and other Chinese adversaries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.