Chengdu 404 is a China-linked offensive cyber contractor and intrusion operator associated with APT41, also widely connected to the Winnti Group ecosystem. It has been described as a self-identified cybersecurity firm based in Chengdu, China, and as one of the more prolific Chinese advanced persistent threat operators at its peak. Public reporting and U.S. government actions have linked the company and its operators to state-directed activity and to work performed on behalf of Chinese security services, placing it within the broader PRC contractor ecosystem that blends private firms, subcontractors, and government tasking. Chengdu 404 has been tied to global intrusions against more than 100 targets worldwide and to operations affecting strategically significant sectors. A notable publicly attributed case involved ransomware attacks in Taiwan in 2020 against organizations in energy, chemicals, telecommunications, and semiconductors. In that campaign, the operators reportedly obtained persistent access to multiple victims before distributing ransomware through centralized management systems, indicating a workflow that combined network compromise, persistence, post-exploitation, and disruptive deployment. The same reporting linked the operators to APT41. The company is also connected to the Winnti and ShadowPad tooling ecosystem. Reporting on leaked materials from another Chinese contractor referenced a Linux implant controller name previously cited in an FBI indictment of Chengdu 404, reinforcing overlap with long-observed Chinese intrusion tradecraft and shared malware infrastructure across affiliated firms. Chengdu 404 has additionally been characterized as a prime contractor or higher-tier competitor to other Chinese hacking-for-hire firms, with multiple offices and comparatively stable business operations. Known aliases include chengdu404 and chengdu_404. Chengdu 404 is best understood not as an isolated malware cluster but as part of a broader Chinese state-aligned contractor network in which personnel, tooling, and operational responsibilities may be shared across companies and campaigns. Its dominant activity profile is consistent with state-linked espionage and strategic cyber operations, with occasional use of ransomware as a disruptive or coercive mechanism rather than purely criminal extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese offensive cyber contractor and activity cluster described as a more capable and stable prime contractor than i-Soon, operating from multiple offices and characterized as once being China’s most prolific APT.
Chinese offensive hacking outfit described as part of the PRC contractor ecosystem and characterized in the article as having been China's most prolific APT at one point.
China-based cybersecurity company referenced as a linked/partner entity in the same ecosystem as I-Soon; associated in public/legal reporting with Winnti control tooling (TreadStone) and alleged linkage to APT41; described as having had a business relationship with I-Soon (including sourcing of a Linux implant).
Chinese hacking group/contractor described as having conducted intrusions against 100+ targets worldwide (per DOJ charging), referenced here as an industry competitor/collaborator to I-Soon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.