A leaked trove of internal files from Chinese contractor I-Soon exposed tools, target lists, pricing documents, and operational details tied to cyber-espionage work reportedly conducted on behalf of Chinese government entities. Reporting indicates the material links I-Soon to intrusions and surveillance activity targeting foreign governments, telecommunications providers, ethnic minorities, dissidents, and online platforms, while also outlining services such as account compromise, data theft, social media monitoring, and infrastructure support for offensive operations.
The disclosures provide a rare inside view of China’s contractor ecosystem, showing how a private firm allegedly supplied hacking capabilities to public security and intelligence customers through a commercialized menu of services. Researchers and media reports said the leak included screenshots, chat logs, and project records that appeared to document operational workflows, victim targeting, and the broader relationship between state agencies and outsourced cyber operators, offering unusual transparency into how Chinese cyber-espionage campaigns may be organized and monetized.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On or around the March 2024 ASEAN-Australia Special Summit, Palo Alto Networks Unit 42 observed Mustang Panda targeting organizations in Myanmar, the Philippines, Japan, and Singapore, while also noting a separate breach of an ASEAN-affiliated victim. Trend Micro separately reported Earth Krahang had targeted 116 entities in 35 countries since early 2022, with overlaps suggesting links to Earth Lusca and contractor I-Soon.
Security researchers and media outlets analyzed the leaked I-Soon materials and published findings describing the company's offensive cyber capabilities, pricing, victim targeting, and relationships with Chinese state customers. These reports framed the leak as a rare window into China's contractor-based cyber ecosystem.
A substantial trove of internal documents, chat logs, contracts, and tooling information from Chinese cybersecurity contractor I-Soon was posted publicly, exposing details of the firm's operations and customers. The leak revealed apparent links between I-Soon and Chinese government and public security entities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityaffairs.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.