
已更新Jul 28, 2026
Chinese-Cybercrime-Research — 已更新!
了解更多关于中文网络犯罪行为者的资源。
中文网络犯罪研究
关于中文网络犯罪行为者的更多学习资源。
钓鱼
- 钓鱼工具包
- YYlaiyu
https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services
https://spycloud.com/blog/yylaiyu-chinese-phishing-as-a-service-panel/ - Darcula/Magic Cat
https://www.mnemonic.io/resources/blog/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation
https://www.nrk.no/spesial/inside-the-scam-network-1.17399135
https://www.nrk.no/spesial/the-hunt-for-darcula-1.17399157
https://www.netcraft.com/blog/ai-enabled-darcula-suite-makes-phishing-kits-more-accessible-easier-to-deploy
https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services
https://urlscan.io/blog/2026/05/11/CnDarcula/ - Lighthouse
https://www.silentpush.com/blog/smishing-triad/
https://krebsonsecurity.com/2025/01/chinese-innovations-spawn-wave-of-toll-phishing-via-sms/
https://blog.google/company-news/outreach-and-initiatives/public-policy/legal-action-and-legislation-fight-scammers/ - Magic Mouse/Haozai
https://www.netcraft.com/blog/haozi-s-plug-and-play-phishing-as-a-service-has-facilitated-280-000-of-criminal-transactions https://hackmag.com/news/magic-mouse - Lucid
https://catalyst.prodaft.com/public/report/lucid/overview - CoGUI
https://www.proofpoint.com/us/blog/threat-insight/cogui-phish-kit-targets-japan-millions-messages
https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_2_2_%20shadow_liu-lime_chen-albert_song_en.pdf
https://urlscan.io/blog/2026/06/01/CnOrientalGudgeon/
https://urlscan.io/blog/2025/05/06/oriental-gudgeon/ - Doggo/ xiū gǒu
https://www.netcraft.com/blog/doggo-threat-actor-analysis - Sailor Framework
https://urlscan.io/blog/2026/05/04/CnSailor/
- YYlaiyu
- 批量短信
https://garwarner.blogspot.com/2025/09/sms-pools-and-what-us-secret-service.html
https://garwarner.blogspot.com/2025/08/chinese-sms-spammers-go-mobile.html
https://www.resecurity.com/blog/article/smishing-triad-is-now-targeting-toll-payment-services-in-a-massive-fraud-campaign-expansion - 其他
https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/
https://urlscan.io/blog/2026/04/27/CnIntro/
https://www.group-ib.com/blog/toll-of-deception/
盗卡/洗钱
- Ghost Tap
https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/
https://krebsonsecurity.com/2025/02/how-phished-data-turns-into-apple-google-wallets/
https://www.threatfabric.com/blogs/ghost-tap-new-cash-out-tactic-with-nfc-relay
https://www.recordedfuture.com/research/ghost-tapping-chinese-criminal-ecosystem
https://www.group-ib.com/blog/ghost-tapped-chinese-malware/ - 银行账户与拉高出货
https://krebsonsecurity.com/2025/04/china-based-sms-phishing-triad-pivots-to-banks/
https://krebsonsecurity.com/2025/08/mobile-phishers-target-brokerage-accounts-in-ramp-and-dump-cashout-scheme/ - 其他
https://www.trmlabs.com/reports-and-whitepapers/shadow-bankers
https://garwarner.blogspot.com/2026/02/chinese-money-laundering-jargon-via.html
诈骗
- 诈骗园区
https://www.uscc.gov/research/protecting-americans-china-linked-scam-centers-update-emerging-trends
https://www.unodc.org/roseap/uploads/documents/Publications/2025/Inflection_Point_2025.pdf
https://www.infoblox.com/blog/threat-intelligence/scams-slaves-and-malware-as-a-service-tracking-a-trojan-to-cambodias-scam-centers/
https://www.wired.com/story/child-sextorition-scam-compounds-southeast-asia/
https://www.wired.com/story/starlink-scam-compounds/
https://www.bbc.com/news/articles/cw076g5wnr3o - 与非洲的关联
https://www.bbc.com/news/world-africa-68777137
https://adf-magazine.com/2025/06/chinese-cybercrime-networks-spread-like-a-cancer-into-africa/ - 非法赌博活动
https://insights.infoblox.com/resources-report/infoblox-report-vigorish-viper-a-venomous-bet - 针对海外华人的诈骗
https://www.voanews.com/a/cyber-kidnapping-scams-target-chinese-students-around-the-world/7432998.html
https://www.fcc.gov/consumers/scam-alert/chinese-language-robocall-scams - 虚假/诈骗电商
https://www.theguardian.com/money/article/2024/may/08/chinese-network-behind-one-of-worlds-largest-online-scams
https://www.group-ib.com/blog/ghost-stadium-football-fraud/ - 其他
https://spycloud.com/blog/year-of-the-trojan-horse-digital-red-envelope-scams-schemes-and-fraud/
https://www.panewslab.com/en/articles/jt0fs1z0585j
网络犯罪论坛与数据泄露
- 中文网络犯罪论坛
https://www.recordedfuture.com/blog/russian-chinese-hacking-communities
https://www.recordedfuture.com/research/restrictive-laws-push-chinese-cybercrime-toward-novel-monetization-techniques - 国际论坛上的中国数据泄露
https://spycloud.com/blog/state-secrets-for-sale-chinese-hacking/
https://www.nattothoughts.com/p/indictments-and-leaks-different-but
https://medium.com/s2wblog/story-of-h2-2023-a-deep-dive-into-data-leakage-and-commerce-in-chinese-telegram-2f5d0df1dafc
https://netaskari.substack.com/p/chinas-massive-data-leak-of-military
https://netaskari.substack.com/p/knownsec-breach-what-we-know-so-far - 被盗数据与内部人员获取的数据
https://www.wired.com/story/chineses-surveillance-state-is-selling-citizens-data-as-a-side-hustle/
https://spycloud.com/blog/growing-chinese-threat-actor-ecosystem/
https://spycloud.com/blog/deep-dive-chinese-cybercrime-ecosystem/
https://spycloud.com/blog/inside-the-chinese-data-leak/
https://spycloud.com/blog/the-largest-known-chinese-pii-data-leak/
https://spycloud.com/blog/insights-from-leaked-chinese-national-id-numbers/
https://m.thepaper.cn/newsDetail_forward_25611279 - 灰色市场
https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in
担保集团
- Huione Group/Prince Group
https://home.treasury.gov/news/press-releases/sb0278
https://moneyandbanking.co.th/en/2025/189857/
https://www.elliptic.co/blog/huione-largest-ever-illicit-online-marketplace-stablecoin
https://www.elliptic.co/blog/cyber-scam-marketplace
https://www.elliptic.co/blog/telegram-dark-markets-expand-to-fill-the-gap-left-by-huione-guarantee - 其他
https://www.recordedfuture.com/research/evolution-of-the-chinese-language
https://www.404media.co/hello-boss-inside-the-chinese-realtime-deepfake-software-powering-scams-around-the-world/
https://www.elliptic.co/blog/tudou-guarantee-winds-down-operations-after-12-billion-in-transactions
https://www.elliptic.co/blog/xinbi-guarantee
https://garwarner.blogspot.com/2025/09/chinese-guarantee-syndicates-and-fruit.html
与中国 APT 的关联
- 当代 APT 运营者兼职网络犯罪
https://cloud.google.com/blog/topics/threat-intelligence/apt41-dual-espionage-and-cyber-crime-operation
https://intrusiontruth.wordpress.com/2024/08/07/is-the-ccp-the-biggest-apt/
https://www.security.com/threat-intelligence/chinese-espionage-ransomware
https://i.blackhat.com/Asia-22/Friday-Materials/AS-22-Li-To-Loot-Or-Not-To-Loot-That-Is-Not-a-Question.pdf
https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/Down-the-GRAYRABBIT-hole-exposing-UNC3569-and-its-modus-operandi.pdf
https://jsac.jpcert.or.jp/archive/2025/pdf/JSAC2025_1_1_steve_aragon_chi-yu.pdf - 爱国黑客 / 红色黑客
https://www.rusi.org/explore-our-research/publications/commentary/40-red-hackers-who-shaped-chinas-cyber-ecosystem
https://github.com/curated-intel/CTI-fundamentals/blob/main/Archive/the-dark-visitor-inside-the-world-of-chinese-hackers.pdf
https://www.nattothoughts.com/p/few-and-far-between-during-chinas
住宅代理服务与僵尸网络
- 机场
https://arxiv.org/pdf/2606.18427 - 911s5
https://krebsonsecurity.com/2022/07/a-deep-dive-into-the-residential-proxy-service-911/
https://krebsonsecurity.com/2024/05/treasury-sanctions-creators-of-911-s5-proxy-botnet/
https://www.justice.gov/archives/opa/pr/911-s5-botnet-dismantled-and-its-administrator-arrested-coordinated-international-operation - Kimwolf [注:KimWolf 僵尸网络的运营者本身并非中国人,但他们通过将恶意命令中继到中国住宅代理服务(如 IPIDEA 和 Plainproxies)的代理端点本地网络中的不安全设备来利用这些设备。他们还入侵了 BADBOX 2.0。因此,他们与中国住宅代理领域有显著关联。]
https://blog.xlab.qianxin.com/kimwolf-botnet-en/
https://synthient.com/blog/a-broken-system-fueling-botnets
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/
https://krebsonsecurity.com/2026/01/who-benefited-from-the-aisuru-and-kimwolf-botnets/
https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
https://www.infoblox.com/blog/threat-intelligence/kimwolf-howls-from-inside-the-enterprise/
https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos - IPIDEA
https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network - BADBOX
https://www.trendmicro.com/en_us/research/23/e/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html
https://www.humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/
https://krebsonsecurity.com/2026/01/who-operates-the-badbox-2-0-botnet/ - 其他
https://spur.us/blog/how-spur-uncovered-a-chinese-proxy-and-vpn-service-used-in-an-apt-campaign
恶意软件
- ZhongStealer / Golden Gh0st RAT
https://any.run/cybersecurity-blog/zhong-stealer-malware-analysis/
https://bsky.app/profile/squiblydoo.bsky.social/post/3mjwerqal4m2p
https://expel.com/blog/introducing-cylindricalcanine/ - Silver Fox / Winos 4.0
- 概述
https://threatbook.io/blog/silver-fox-not-an-organization-but-a-tool-uncovering-the-underground-ecosystem - 由 "Void Arachne" 部署
https://www.trendmicro.com/en_us/research/24/f/behind-the-great-wall-void-arachne-targets-chinese-speaking-user.html - 由 GoldenEye Dog(APT-Q-27) 部署
https://ti.qianxin.com/blog/articles/apt-q-27-gang-recent-use-of-silver-fox-trojan-stealing-activities-en/ - ValleyRAT
https://www.proofpoint.com/us/blog/threat-insight/chinese-malware-appears-earnest-across-cybercrime-threat-landscape
- 概述
- AtlasRAT
- GoldFactory (Android 与 iOS 银行木马)
https://www.group-ib.com/blog/goldfactory-ios-trojan/
https://www.group-ib.com/blog/turning-apps-into-gold/