GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
Key Takeaways A previously obscure Chinese company, Guangdong Chanming, is suspected of developing and supplying a covert network infrastructure. This infrastructure, dubbed “GhostNet,”...
Key Takeaways
- A previously obscure Chinese company, Guangdong Chanming, is suspected of developing and supplying a covert network infrastructure.
- This infrastructure, dubbed “GhostNet,” is allegedly used to mask the origins of cyber-espionage operations tied to the People’s Liberation Army (PLA).
- The network leverages tools designed for anonymization, traffic relay, and data exfiltration, making attribution of cyberattacks significantly more difficult.
- Researchers identified links between Guangdong Chanming’s shareholder, specific software projects (FCN/FreeConnect), and known PLA-linked malware like WHIPWEAVE.
- The findings underscore the increasing reliance of state-sponsored cyber operations on private firms for specialized, deniable infrastructure.
Chinese Company Implicated in PLA Cyber Espionage Network
A Chinese company with a minimal public footprint is believed to have played a crucial role in establishing a clandestine network supporting cyber operations connected to the Chinese military. This network, termed “GhostNet” by some, appears to facilitate global cyber espionage activities by obscuring their true origin.
Table Of Content
According to researchers, Guangdong Chanming, a company lacking a visible commercial presence, is reportedly associated with sophisticated tools engineered to conceal online activities and route internet traffic through multiple intermediary systems. This capability is critical for obfuscating the source of cyber intrusions and making it challenging for cybersecurity defenders to trace attacks back to their perpetrators.
This revelation aligns with recent reports detailing how private Chinese firms provide essential infrastructure and services that enable state-sponsored espionage campaigns. Such arrangements allow state actors to maintain a degree of plausible deniability while leveraging advanced cyber capabilities.
The alleged connection was uncovered by IntrusionTruth in a report shared with Cyber Security News (CSN). Their analysis, which involved scrutinizing company filings, software records, patents, and military procurement documents, suggests that Guangdong Chanming acts as a provider of anonymous networking technology to Chinese state clients. The full report can be found here.
This research does not detail a typical malware campaign with a specific list of victims or initial compromise vectors. Instead, it focuses on the foundational infrastructure that underpins various cyber operations. This infrastructure includes software designed to obscure command and control traffic, relay data, and minimize the traceability of malicious activities.
The “Ghost” Company’s Portfolio
Guangdong Chanming reportedly operates without a public website, physical storefront, or a readily available commercial product catalog. Despite this, its registered patents and software copyrights reveal a suite of products with names such as “Internet Security Access System,” “Multi-functional Security Proxy System,” “File Transfer Network System,” “Security Tunnel Network,” and “Anti-traceability Network System.”
Further investigation into their product titles uncovered references to an “Android Secret Extraction System” and a “Telegram Data Collection System.” While product names alone do not definitively prove their operational deployment, they strongly indicate that Guangdong Chanming’s activities extend far beyond standard consumer networking solutions, venturing into surveillance, data collection, and anonymity capabilities. The full report with details on these products is available here.
Procurement records reportedly identify Guangdong Chanming as a supplier to the People’s Liberation Army. One specific listing describes an “Anonymous Network System” delivered to a military unit located in Beijing’s Haidian District, a region known for hosting significant Chinese military and technology organizations. This connection is particularly noteworthy as Haidian is also associated with the PLA Cyberspace Force, the military branch responsible for China’s cyber operations. The report posits that the company’s networking technology could provide a crucial layer of obfuscation for operators conducting extended espionage campaigns. More details can be found <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/f6a28447-ba4f-4ec2-91f3-eb4657297283/Researchers-Say-a-Ghost-Chinese-Company-Built-the-Network-Hiding-PLA-Cyberattacks.pdf?AWSAccessKeyId=ASIA2F3EMEYET3VWKIFJ&Signature=eB%2BIE1TwipjaIlqNpshfVtTeEbY%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJr%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBnT6Ya4OsbbSg7N3SGxpkBxoTHA%2FdFLLLeEJdG%2BAca9AiEAjUEssZGuQQA6qNTBHpDbZjTWVGi0BBtOlLMrYid2mP8q8wQIYxABGgw2OTk3NTMzMDk3MDUiDI5368CZeJrGmoMcMyrQBKp6%2BC2qqniFHeHmigrnojkxGK2htRJWl9gcyLSulpYV0V2CZgsmBdJmkpfp3AwIs9lcHdnqSpYFUBNYTHcmmHvU1hAPOZR%2F%2Fck08AKCNOusrGH9xuqjYX4MYzAGMUMjlAjaCEAn7fplEx%2Fy2orEFswf4uP3aY4yOqPA8ii8pkBdFbTE%2Bqw33SFivEYoZcM5LBhFVGNKFChVTPrM9C2tmfEi9bzS42aLYU4Gikl5G5kXkgL9UCCIglrcHz2x9NbgRiOl9Ekg2g9F033lJd05
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.