A House committee report found that China Telecom Americas, China Mobile USA, and China Unicom Americas remained operationally dependent on parent companies in China or Hong Kong while still maintaining equipment, transmission hardware, points of presence, and active network assets inside the United States. Investigators said those lingering interconnections and private leases persisted despite federal restrictions, raising concerns that routing, service provisioning, and oversight of U.S.-based infrastructure could still be influenced from abroad.
The report also linked the carriers to entities that U.S. authorities and researchers have associated with Chinese state-backed cyber activity, including CloudRadium, Integrity Technology Group, and i-SOON. Separate reporting on the 2024 i-SOON leak said internal chats, sales materials, and malware documentation appeared genuine and tied the company to previously reported Chinese espionage operations, including overlaps with Comm100 supply-chain activity, POISON CARP, ShadowPad infrastructure, and a Linux malware controller called Treadstone. Together, the findings sharpen concerns that commercial Chinese telecom and security firms can preserve access and support capabilities that complicate efforts to remove national-security risks from U.S. networks.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
On Feb. 16, 2024, someone uploaded data to GitHub allegedly containing i-Soon internal communications, sales materials, product manuals, screenshots, and probable victim data. Unit 42 assessed with high confidence that the leaked materials are genuine.
A congressional committee report said China Unicom and Integrity Technology Group formalized a cooperation agreement in November 2023. The report said this occurred while the Flax Typhoon botnet was operating.
Trend Micro reported in September 2022 that attackers trojanized the installer for Comm100’s chat-based customer engagement application hosted on the company’s official website. Unit 42 later assessed with moderate confidence that hackers within i-Soon were involved.
On June 17, 2022, IP address 8.218.67[.]52 served a Linux ELF file from /js/xxx.jpg. Unit 42 said leaked i-Soon chats claimed this Hong Kong-based server belonged to them and linked it to infrastructure used in the Comm100 intrusion.
A 2019 U.S. grand jury indictment against three Chengdu 404 employees referenced Treadstone malware controller software and attributed it to Elemental Taurus (APT41). Unit 42 noted a leaked i-Soon manual showed a Linux malware control panel with the same name.
Citizen Lab reported a 2019 campaign using iOS and Android exploits to target Tibetan groups and attributed the activity to the Chinese threat group it tracks as POISON CARP. Unit 42 later linked leaked i-Soon data to this previously reported campaign.
A congressional committee report found that China Telecom Americas, China Mobile USA, and China Unicom Americas remained operationally dependent on parent entities in China or Hong Kong while retaining equipment and network connections inside the United States. The report also described ties to entities linked by U.S. authorities to Chinese state-backed cyber activity, including CloudRadium, Integrity Technology Group, and i-SOON.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourcescworld.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourceunit42.paloaltonetworks.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.