Sun.Star Cebu

Hacking docs leaked, reveal Chinese state surveillan­ce

-

CHINESE police are investigat­ing an unauthoriz­ed and highly unusual online dump of documents from a private security contractor linked to the nation’s top policing agency and other parts of its government — a trove that catalogs apparent hacking activity and tools to spy on both Chinese and foreigners.

Among the apparent targets of tools provided by the impacted company, I-Soon: ethnicitie­s and dissidents in parts of China that have seen significan­t anti-government protests, such as Hong Kong or the heavily Muslim region of Xinjiang in China’s far west.

The dump of scores of documents late last week and subsequent investigat­ion were confirmed by two employees of I-Soon, known as Anxun in Mandarin, which has ties to the powerful Ministry of Public Security. The dump, which analysts consider highly significan­t even if it does not reveal any especially novel or potent tools, includes hundreds of pages of contracts, marketing presentati­ons, product manuals, and client and employee lists.

They reveal, in detail, methods used by Chinese authoritie­s used to surveil dissidents overseas, hack other nations and promote pro-Beijing narratives on social media.

The documents show apparent I-Soon hacking of networks across Central and Southeast Asia, as well as Hong Kong and the selfruled island of Taiwan, which Beijing claims as its territory.

Hacking tools

The hacking tools are used by Chinese state agents to unmask users of social media platforms outside China such as X, formerly known as Twitter, break into email and hide the online activity of overseas agents. Also described are devices disguised as power strips and batteries that can be used to compromise Wi-Fi networks.

I-Soon and Chinese police are investigat­ing how the files were leaked, the two I-Soon employees told the AP. One of the employees said I-Soon held a meeting Wednesday, Feb. 21, about the leak and were told it wouldn’t affect business too much and to “continue working as normal.” The AP is not naming the employees — who did provide their surnames, per common Chinese practice — out of concern about possible retributio­n.

The source of the leak is not known. The Chinese Foreign Ministry did not immediatel­y respond to a request for comment.

Jon Condra, an analyst with Recorded Future, a cybersecur­ity company, called it the most significan­t leak ever linked to a company “suspected of providing cyber espionage and targeted intrusion services for the Chinese security services.” He said organizati­ons targeted by I-Soon — according to the leaked material — include government­s, telecommun­ications firms abroad and online gambling companies within China.

Until the 190-megabyte leak, I-Soon’s website included a page listing clients topped by the Ministry of Public Security and including 11 provincial-level security bureaus and some 40 municipal public security department­s.

Another page available until early Tuesday, Feb. 20, advertised advanced persistent threat “attack and defense” capabiliti­es, using the acronym APT — one the cybersecur­ity industry employs to describe the world’s most sophistica­ted hacking groups.

Internal documents in the leak describe I-Soon databases of hacked data collected from foreign networks around the world that are advertised and sold to Chinese police.

The company’s website was fully offline later Tuesday. An I-Soon representa­tive refused an interview request and said the company would issue an official statement at an unspecifie­d future date.

I-Soon was founded in Shanghai in 2010, according to Chinese corporate records, and has subsidiari­es in three other cities, including one in the southweste­rn city of Chengdu that is responsibl­e for hacking, research and developmen­t, according to leaked internal slides.

Newspapers in English

Newspapers from Philippines