Recorded Future publishes a 24 page report on i-SOON and their connections to offensive cyberespionage operations attributed to RedHotel, RedAlpha and POISON CARP. The links indicate that they are likely sub-teams focused on specific missions within the same company. i-SOON's victims span 22 countries, with government, telco and education being the most targeted sectors. i-SOON also supports domestic including the targeting of ethnic and religious minorities and the online gambling industry. i-SOON very likely uses and sells access to custom malware families like Winnti and ShadowPad. IOC provided. 🔗 https://www.recordedfuture.com/attributing-i-soon-private-contractor-linked-chinese-state-sponsored-groups

#ISOON #cyberespionage #China #APT #threatintel #IOC #redhotel #redalpha #poisoncarp #winnti #shadowpad

Attributing I-SOON: Private Contractor Linked to Multiple Chinese State-sponsored Groups

Insikt Group uncovers ties between I-SOON and multiple Chinese state-sponsored cyber groups like RedAlpha and RedHotel.

New Leak Shows Business Side of China’s APT Menace – Krebs on Security

New Leak Shows Business Side of China’s APT Menace – Krebs on Security

New Leak Shows Business Side of China’s APT Menace - A new data leak that appears to have come from one of China’s top private cybersec... https://krebsonsecurity.com/2024/02/new-leak-shows-business-side-of-chinas-apt-menace/ #u.s.departmentofjustice #neer-do-wellnews #alittlesunshine #databreaches #meidanowski #sentinelone #citizenlab #dakotacary #poisoncarp #willthomas #wuhaibo #i-soon
New Leak Shows Business Side of China’s APT Menace – Krebs on Security

Researchers from Lookout Threat Lab (Kristina Balaam et al.) have uncovered two new precrime #surveillance campaigns targeting #Uyghur diaspora & *in* the PRC

https://lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine

- intersects with Android exploit and tool against #Tibetan diaspora surfaced by @citizenlab in 2019 #poisoncarp

Lookout Discovers Long-running Surveillance Campaigns Targeting Uyghurs | Lookout

Researchers from Lookout Threat Lab have uncovered two new surveillance campaigns, BadBazaar and MOONSHINE, targeting Uyghurs in the People’s Republic of China and abroad.