Orange Cyberdefense mapped more than 300 entities and 400 relationships in a Chinese ecosystem linking state agencies, private cybersecurity companies, universities and hacking competitions to offensive cyber operations and espionage. Its Hidden Network Report, with a research cutoff of October 22, 2024, highlights the roles of the People’s Liberation Army (PLA) and Ministry of State Security. The February 2024 i-SOON leak exposed extensive government contracting, while academic partnerships and competitions supply research, recruits and exploitable vulnerabilities. Private contractors expand operational capacity and provide plausible deniability, although fragmented subcontracting creates operational-security risks.
The report identifies interconnected vulnerability databases and mandatory disclosure requirements as mechanisms that give Chinese authorities access to newly discovered flaws, potentially enabling exploitation before remediation. Separate Jamestown Foundation reporting covers the PLA’s command reorganization and elimination of its Strategic Support Force, highlighting changes to the military structure alongside the broader contractor ecosystem. For security leaders, the findings reinforce the importance of rapid vulnerability remediation, monitoring for exploitation before patches become available, and assessing Chinese cyber threats beyond individual named groups to include their state, commercial and academic connections.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
The PLA underwent a reorganization involving the Information Support Force and Cyberspace Force. Orange Cyberdefense noted uncertainty about the division of responsibilities between the forces.
The February 2024 Sichuan i-SOON leak exposed contracts and communications documenting the company's longstanding role as an MSS contractor. The records described cyber campaigns against targets in more than 70 countries, including France, Rwanda, and Nepal.
Microsoft Exchange vulnerability CVE-2021-42321 was exploited in the wild days after its demonstration at the 2021 Tianfu Cup.
China's 2021 Regulations on the Management of Network Product Security Vulnerabilities required researchers to consult MIIT before public or vendor disclosure and routed vulnerabilities into an MIIT-managed sharing platform.
Beginning in 2003, Chinese authorities recruited civilian hackers into the PLA, MSS, and MPS through competitions, hacker-forum job advertisements, and freelance participation in offensive operations.
The report describes a competition that tasked participants with infiltrating the networks of U.S. Department of Defense contractor VAE Inc., in its discussion of the TOPSEC Cup co-organized by Beijing Topsec and Southeast University.
Leaked i-SOON records indicated that vulnerabilities identified during the 2021 Tianfu Cup were transferred to the MPS. The source does not specify when the transfer occurred.
The report states that Zhao Qixun's Chaos exploit was shared with Chinese state agencies and subsequently used in targeted attacks against Uyghurs before patches were released.
According to Adam Kozy's reporting cited in the report, KRYPTONITE PANDA exploited Microsoft Office vulnerability CVE-2018-0802 a month before Qihoo360 disclosed it to Microsoft.
Chengdu 404, a company linked to APT41, sued i-SOON over intellectual-property violations.
i-SOON obtained a vulnerability affecting the QQ messaging platform from competitor NoSugarTech for use in an intrusion campaign.
During the 2015–2016 reforms, the PLA created the Strategic Support Force. Its Network Systems Department absorbed cyberespionage responsibilities and operational units from the former Third and Fourth Departments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
jamestown.org
Open sourceresearch.cert.orangecyberdefense.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.