Chinese Firm Allegedly Built Network Concealing PLA Cyberattacks

Recent investigations have uncovered that Guangdong Chanming, a Chinese company with minimal public presence, may have developed infrastructure facilitating cyber operations linked to the People’s Liberation Army (PLA). This firm’s involvement is significant, as such covert networks can obscure the origins of cyber intrusions, complicating attribution efforts.

Guangdong Chanming lacks a public website or visible commercial products. However, its registered patents and software copyrights reveal products like the Internet Security Access System, Multi-functional Security Proxy System, and Security Tunnel Network. These titles suggest capabilities in surveillance, data collection, and network concealment.

Procurement records indicate that Guangdong Chanming supplied an Anonymous Network System to a military unit in Beijing’s Haidian District, a hub for Chinese military and technology entities, including the PLA Cyberspace Force responsible for military cyber operations. This connection implies that the company’s technology may have provided cover for prolonged espionage campaigns.

Further investigation links Guangdong Chanming to the FreeConnect (FCN) software project, previously hosted on GitHub under the handle “boywhp.” A phone number associated with one of the company’s shareholders, Wang Huiping, connects to an email address tied to FCN. Analysis of FCN’s Linux versions revealed commands similar to those in WHIPWEAVE malware, associated with Chinese cyber activities.

These findings highlight the intricate infrastructure supporting state-sponsored cyber operations. The use of seemingly legitimate companies to develop tools that mask cyber activities underscores the challenges in attributing and defending against such threats. Organizations should remain vigilant, monitoring for unusual encrypted connections and unfamiliar proxy services as potential indicators of covert cyber activities.