
UpdatedJul 28, 2026
Chinese-Cybercrime-Research — Updated!
Resources to learn more about Chinese-language cybercrime actors.
Chinese Cybercrime Research
Resources to learn more about Chinese-language cybercrime actors.
Phishing
- Phishing Kits
- YYlaiyu
https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services
https://spycloud.com/blog/yylaiyu-chinese-phishing-as-a-service-panel/ - Darcula/Magic Cat
https://www.mnemonic.io/resources/blog/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation
https://www.nrk.no/spesial/inside-the-scam-network-1.17399135
https://www.nrk.no/spesial/the-hunt-for-darcula-1.17399157
https://www.netcraft.com/blog/ai-enabled-darcula-suite-makes-phishing-kits-more-accessible-easier-to-deploy
https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services
https://urlscan.io/blog/2026/05/11/CnDarcula/ - Lighthouse
https://www.silentpush.com/blog/smishing-triad/
https://krebsonsecurity.com/2025/01/chinese-innovations-spawn-wave-of-toll-phishing-via-sms/
https://blog.google/company-news/outreach-and-initiatives/public-policy/legal-action-and-legislation-fight-scammers/ - Magic Mouse/Haozai
https://www.netcraft.com/blog/haozi-s-plug-and-play-phishing-as-a-service-has-facilitated-280-000-of-criminal-transactions https://hackmag.com/news/magic-mouse - Lucid
https://catalyst.prodaft.com/public/report/lucid/overview - CoGUI
https://www.proofpoint.com/us/blog/threat-insight/cogui-phish-kit-targets-japan-millions-messages
https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_2_%20shadow_liu-lime_chen-albert_song_en.pdf
https://urlscan.io/blog/2026/06/01/CnOrientalGudgeon/
https://urlscan.io/blog/2025/05/06/oriental-gudgeon/ - Doggo/ xiū gǒu
https://www.netcraft.com/blog/doggo-threat-actor-analysis - Sailor Framework
https://urlscan.io/blog/2026/05/04/CnSailor/
- YYlaiyu
- Bulk SMS
https://garwarner.blogspot.com/2025/09/sms-pools-and-what-us-secret-service.html
https://garwarner.blogspot.com/2025/08/chinese-sms-spammers-go-mobile.html
https://www.resecurity.com/blog/article/smishing-triad-is-now-targeting-toll-payment-services-in-a-massive-fraud-campaign-expansion - Other
https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/
https://urlscan.io/blog/2026/04/27/CnIntro/
https://www.group-ib.com/blog/toll-of-deception/
Carding/Money Laundering
- Ghost Tap
https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/
https://krebsonsecurity.com/2025/02/how-phished-data-turns-into-apple-google-wallets/
https://www.threatfabric.com/blogs/ghost-tap-new-cash-out-tactic-with-nfc-relay
https://www.recordedfuture.com/research/ghost-tapping-chinese-criminal-ecosystem
https://www.group-ib.com/blog/ghost-tapped-chinese-malware/ - Bank Accounts & Ramp-and-Dump
https://krebsonsecurity.com/2025/04/china-based-sms-phishing-triad-pivots-to-banks/
https://krebsonsecurity.com/2025/08/mobile-phishers-target-brokerage-accounts-in-ramp-and-dump-cashout-scheme/ - Other
https://www.trmlabs.com/reports-and-whitepapers/shadow-bankers
https://garwarner.blogspot.com/2026/02/chinese-money-laundering-jargon-via.html
Scams
- Scam Compounds
https://www.uscc.gov/research/protecting-americans-china-linked-scam-centers-update-emerging-trends
https://www.unodc.org/roseap/uploads/documents/Publications/2025/Inflection_Point_2025.pdf
https://www.infoblox.com/blog/threat-intelligence/scams-slaves-and-malware-as-a-service-tracking-a-trojan-to-cambodias-scam-centers/
https://www.wired.com/story/child-sextorition-scam-compounds-southeast-asia/
https://www.wired.com/story/starlink-scam-compounds/
https://www.bbc.com/news/articles/cw076g5wnr3o - Links to Africa
https://www.bbc.com/news/world-africa-68777137
https://adf-magazine.com/2025/06/chinese-cybercrime-networks-spread-like-a-cancer-into-africa/ - Illegal Gambling Operations
https://insights.infoblox.com/resources-report/infoblox-report-vigorish-viper-a-venomous-bet - Scams Targeting Chinese Expats
https://www.voanews.com/a/cyber-kidnapping-scams-target-chinese-students-around-the-world/7432998.html
https://www.fcc.gov/consumers/scam-alert/chinese-language-robocall-scams - Fake/Scam E-Commerce
https://www.theguardian.com/money/article/2024/may/08/chinese-network-behind-one-of-worlds-largest-online-scams
https://www.group-ib.com/blog/ghost-stadium-football-fraud/ - Other
https://spycloud.com/blog/year-of-the-trojan-horse-digital-red-envelope-scams-schemes-and-fraud/
https://www.panewslab.com/en/articles/jt0fs1z0585j
Cybercrime Forums & Data Leaks
- Chinese Cybercrime Forums
https://www.recordedfuture.com/blog/russian-chinese-hacking-communities
https://www.recordedfuture.com/research/restrictive-laws-push-chinese-cybercrime-toward-novel-monetization-techniques - Chinese Data Leaks on International Forums
https://spycloud.com/blog/state-secrets-for-sale-chinese-hacking/
https://www.nattothoughts.com/p/indictments-and-leaks-different-but
https://medium.com/s2wblog/story-of-h2-2023-a-deep-dive-into-data-leakage-and-commerce-in-chinese-telegram-2f5d0df1dafc
https://netaskari.substack.com/p/chinas-massive-data-leak-of-military
https://netaskari.substack.com/p/knownsec-breach-what-we-know-so-far - Stolen and Insider-Acquired Data
https://www.wired.com/story/chineses-surveillance-state-is-selling-citizens-data-as-a-side-hustle/
https://spycloud.com/blog/growing-chinese-threat-actor-ecosystem/
https://spycloud.com/blog/deep-dive-chinese-cybercrime-ecosystem/
https://spycloud.com/blog/inside-the-chinese-data-leak/
https://spycloud.com/blog/the-largest-known-chinese-pii-data-leak/
https://spycloud.com/blog/insights-from-leaked-chinese-national-id-numbers/
https://m.thepaper.cn/newsDetail_forward_25611279 - Gray Market
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
Guarantee Groups
- Huione Group/Prince Group
https://home.treasury.gov/news/press-releases/sb0278
https://moneyandbanking.co.th/en/2025/189857/
https://www.elliptic.co/blog/huione-largest-ever-illicit-online-marketplace-stablecoin
https://www.elliptic.co/blog/cyber-scam-marketplace
https://www.elliptic.co/blog/telegram-dark-markets-expand-to-fill-the-gap-left-by-huione-guarantee - Other
https://www.recordedfuture.com/research/evolution-of-the-chinese-language
https://www.404media.co/hello-boss-inside-the-chinese-realtime-deepfake-software-powering-scams-around-the-world/
https://www.elliptic.co/blog/tudou-guarantee-winds-down-operations-after-12-billion-in-transactions
https://www.elliptic.co/blog/xinbi-guarantee
https://garwarner.blogspot.com/2025/09/chinese-guarantee-syndicates-and-fruit.html
Links to Chinese APTs
- Contemporary APT Operators Moonlighting in Cybercrime
https://cloud.google.com/blog/topics/threat-intelligence/apt41-dual-espionage-and-cyber-crime-operation
https://intrusiontruth.wordpress.com/2024/08/07/is-the-ccp-the-biggest-apt/
https://www.security.com/threat-intelligence/chinese-espionage-ransomware
https://i.blackhat.com/Asia-22/Friday-Materials/AS-22-Li-To-Loot-Or-Not-To-Loot-That-Is-Not-a-Question.pdf
https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/Down-the-GRAYRABBIT-hole-exposing-UNC3569-and-its-modus-operandi.pdf
https://jsac.jpcert.or.jp/archive/2025/pdf/JSAC2025_1_1_steve_aragon_chi-yu.pdf - Patriotic Hackers / Red Hackers
https://www.rusi.org/explore-our-research/publications/commentary/40-red-hackers-who-shaped-chinas-cyber-ecosystem
https://github.com/curated-intel/CTI-fundamentals/blob/main/Archive/the-dark-visitor-inside-the-world-of-chinese-hackers.pdf
https://www.nattothoughts.com/p/few-and-far-between-during-chinas
Residential Proxy Services & Botnets
- Airports
https://arxiv.org/pdf/2606.18427 - 911s5
https://krebsonsecurity.com/2022/07/a-deep-dive-into-the-residential-proxy-service-911/
https://krebsonsecurity.com/2024/05/treasury-sanctions-creators-of-911-s5-proxy-botnet/
https://www.justice.gov/archives/opa/pr/911-s5-botnet-dismantled-and-its-administrator-arrested-coordinated-international-operation - Kimwolf [NOTE: The Operators of the KimWolf botnet were not themselves Chinese, but they exploited devices by relaying malicious commands to insecure devices on the local networks of proxy endpoints of Chinese residential proxy services like IPIDEA and Plainproxies. They also hacked BADBOX 2.0. Thus, they are significantly linked to the CN Residential Proxy space.]
https://blog.xlab.qianxin.com/kimwolf-botnet-en/
https://synthient.com/blog/a-broken-system-fueling-botnets
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/
https://krebsonsecurity.com/2026/01/who-benefited-from-the-aisuru-and-kimwolf-botnets/
https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
https://www.infoblox.com/blog/threat-intelligence/kimwolf-howls-from-inside-the-enterprise/
https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos - IPIDEA
https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network - BADBOX
https://www.trendmicro.com/en_us/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html
https://www.humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/
https://krebsonsecurity.com/2026/01/who-operates-the-badbox-2-0-botnet/ - Other
https://spur.us/blog/how-spur-uncovered-a-chinese-proxy-and-vpn-service-used-in-an-apt-campaign
Malware
- ZhongStealer / Golden Gh0st RAT
https://any.run/cybersecurity-blog/zhong-stealer-malware-analysis/
https://bsky.app/profile/squiblydoo.bsky.social/post/3mjwerqal4m2p
https://expel.com/blog/introducing-cylindricalcanine/ - Silver Fox / Winos 4.0
- General
https://threatbook.io/blog/silver-fox-not-an-organization-but-a-tool-uncovering-the-underground-ecosystem - As deployed by "Void Arachne"
https://www.trendmicro.com/en_us/research/24/f/behind-the-great-wall-void-arachne-targets-chinese-speaking-user.html - As deployed by GoldenEye Dog(APT-Q-27)
https://ti.qianxin.com/blog/articles/apt-q-27-gang-recent-use-of-silver-fox-trojan-stealing-activities-en/ - ValleyRAT
https://www.proofpoint.com/us/blog/threat-insight/chinese-malware-appears-earnest-across-cybercrime-threat-landscape
- General
- AtlasRAT
- GoldFactory (Android & iOS Banking Trojans)
https://www.group-ib.com/blog/goldfactory-ios-trojan/
https://www.group-ib.com/blog/turning-apps-into-gold/
Other Useful Resources
https://en.wikipedia.org/wiki/Chinese_Internet_slang