Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory

Flaming China

Also known asFlaming China

Flaming China is the name used by actors claiming responsibility for an alleged intrusion involving the National Super Computer Center of China (NSCC) in Tianjin. The available reporting indicates the group identified itself as “Flaming China,” and that its Telegram channel appears to have existed since early February; however, the source explicitly assesses that this may be a temporary alias rather than a permanent or stable threat group. In the reported activity, a dark web actor using the handle “airborneshark1” advertised for sale an alleged 10-petabyte dataset purportedly stolen from the NSCC and later reposted the offer to increase bidding. The source attributes the intrusion to Flaming China. Based on several gigabytes of leaked sample data, the source assesses that at least part of the breach appears genuine, although the full claimed 10 PB volume could not be verified. The reported sample data allegedly included screenshots of internal directory layouts and user credentials, PDFs, reports, handbooks, radar test data, physics simulation renderings, test calculations, and documents dated 2024 and 2025. The content states that the NSCC supports academic, state-owned enterprise, partner, and military-linked simulation workloads, and that the leaked material allegedly reflected simulation of payload and weapon-system effects against targets and materials. Reported examples include a document marked “秘密*10年” described as a 2025 bunker-buster ammunition testing report, with modeled targets including a HIMARS truck, an aircraft carrier, and bunker configurations, as well as radar-related data and a system referred to as “stealth.” If the claimed 10-petabyte exfiltration is accurate, the source assesses that the operation would likely have required prolonged access, exploration of NSCC clusters and storage infrastructure, and lateral movement across the environment, and suggests possible insider assistance. No nation-state attribution is established in the provided content. Known alias in the content: flaming_china.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Academia & Research
  • Military

Where they target

Geographies tied to known operations.

  • 🇨🇳 China
MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics10 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1078×3
Valid Accounts
TA0003
Persistence
1 technique
T1078×3
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
1 technique
T1078×3
Valid Accounts
TA0008
Lateral Movement
2 techniques
T1534
Internal Spearphishing
T1570
Lateral Tool Transfer
TA0009
Collection
3 techniques
T1074×2
Data Staged
T1213
Data from Information Repositories
T1560
Archive Collected Data
TA0010
Exfiltration
1 technique
T1041×2
Exfiltration Over C2 Channel
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.