logo

Chinese APT Tactics and accesses uncovered after analyzing the I-SOON repository

ID: f2c51078-e2a8-5250-a55b-de61fbab1858

STIX ID: report--f2c51078-e2a8-5250-a55b-de61fbab1858

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2024-02-23

Date Updated: 2026-04-27

...
...

**Executive summary:** The report describes a February 2024 GitHub leak attributed to I-SOON, a Chinese cyber-intelligence company that offers nation-state style spyware and offensive tools (RATs for multiple OSes, social media control systems, automated penetration platforms, DDoS botnets, and WiFi/telecom exploitation). The leaked repository contains employee chats, business contracts with Chinese police and government agencies, product brochures, and large datasets allegedly exfiltrated from governments, telecoms, and organizations across Asia, Europe and beyond (multiple TBs of call detail records, emails, and PC files). The materials link I-SOON to known APT activity (notably similarities and personnel/business ties to Chengdu 404/APT41), disclose real-world customers and targets (including Indian ministries and telecoms), and include PII and infrastructure access indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.