Techtimes Guangdong Chanming Sells Botnet to PLA for Cyber Operations
Article Content
- •Guangdong Chanming sold a spy botnet to the PLA and multiple hacking groups.
- •The company operates without a public-facing business and lacks commercial sales.
- •Research linked Chanming's tools to military cyber operations, revealing state-sponsored tactics.
Guangdong Chanming, a covert Chinese company, has been linked to the sale of a spy botnet to the People's Liberation Army (PLA) and various hacking groups. This botnet serves as an anonymous relay network, facilitating global cyber intrusions while masking their origins. Research by Intrusion Truth revealed that Chanming's tools, including an 'Anonymous Network System,' were sold to military units, confirming its role in state-sponsored cyber operations. The company lacks a public presence and does not appear to sell its products commercially. Investigations uncovered connections between Chanming's shareholders and a previously developed VPN tool, indicating a direct lineage to its current offerings. The implications of this discovery highlight the reliance of sophisticated hacking groups on external vendors for evasion infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Apt15, Orbweaver and Guangdong Chanming in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…