Honker Union of China (HUC), also rendered as 中国红客联盟, is a Chinese patriotic hacker collective that emerged in the late 1990s and became one of the best-known “red hacker” brands in China. Public reporting has long associated HUC with nationalist cyber activity aligned with Chinese geopolitical flashpoints, particularly website defacements and distributed denial-of-service attacks against foreign targets during regional disputes. Its exact relationship with the Chinese state has remained indeterminate in open sources, but the group has been repeatedly discussed in the context of PRC-aligned patriotic cyber operations. HUC has been linked to anti-Vietnam cyber activity during South China Sea tensions in 2011, when pro-PRC hacktivists defaced and disrupted Vietnamese government and commercial websites. The group is part of the broader ecosystem of Chinese patriotic hacking that helped shape later PRC cyber operations, bridging early mass-participation nationalist hacktivism and more organized state-linked activity. Although HUC was often described as having very large membership, including estimates of around 80,000 members, available evidence indicates that its real operational capability rested in a very small core of technically capable members, while the broader base largely consisted of loosely affiliated forum registrants and amateurs. Reporting has described only a handful of core operators and technical support personnel at the center of the organization. HUC therefore appears to have functioned less as a disciplined mass operational force than as a nationalist cyber community with a small skilled nucleus and a much larger symbolic following. Known aliases include HUC and Honker Union of China. The group is best characterized as a patriotic Chinese hacktivist collective focused on disruptive operations, especially defacement and denial-of-service activity, in support of nationalist causes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
High-profile Chinese 'honker' (patriotic hacking) collective; widely reported very large membership but reportedly only a handful of core operators providing technical support; aligned with 'patriotic' targeting of foreign entities perceived as hostile to China.
Pro-PRC patriotic hacktivist collective involved in defacement and DDoS attacks against Vietnamese websites during South China Sea disputes; later reappeared during international disputes, often involving the South China Sea.
Chinese patriotic hacktivist group referenced in the context of Sino-Vietnamese hacker conflict and nationalist cyber activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.