On July 27, the investigative collective Intrusion Truth published an OSINT dossier identifying Guangdong Chanming as a provider of anonymized relay infrastructure for the PLA and nearly a dozen Chinese APT groups. The company has no website, no known commercial clients, and leaves no conventional digital footprint. Its discovery confirms that the Chinese cyber-espionage industrial chain includes invisible vendors whose disruption can be more effective than targeting individual actors.
- Guangdong Chanming has no public commercial presence: no website, storefront, or visible catalog, according to the Intrusion Truth dossier.
- Military procurement records on plap.mil.cn name Chanming as a supplier of an "Anonymous Network System" to a unit in Beijing's Haidian district, home of the PLA Cyberspace Force.
- The personal FCN VPN project of its shareholder Wang Huiping shares identical technical commands with the WHIPWEAVE malware, a component of the ORBWEAVER network documented by Symantec.
- Nearly a dozen distinct APT clusters, including PLA and Ministry of Public Security actors, have used the same relay infrastructure purchased from this single vendor.
How to Uncover a Company That Does Not Want to Be Found
Intrusion Truth's methodology starts with Chinese corporate filings. Guangdong Chanming is registered with two shareholders: Dai Zhoujun and Wang Huiping. Wang's phone number, 13760865234, appears in a data-breach dump linked to the email address boywhp@126.com. That email is tied to the GitHub repository for FCN (Free Connect), Wang's personal VPN project, now deleted but with surviving forks.
The domain xfconnect.com, associated with FCN, hosts binaries on VirusTotal that include a file analogous to stn.exe ("STN Security Tunnel") attributed to Chanming. Internal strings reference FCN, establishing a bridge between the personal project and the corporate product. The stn.exe binary is listed among Chanming's products, alongside systems for Android data extraction, Telegram collection, and network vulnerability testing.
FCN's Linux builds use an unusual command to identify network interfaces. The same command is documented by Mandiant in the WHIPWEAVE malware, file bulbature, a core component of the RedRelay/ORBWEAVER network. Symantec has technically confirmed that Whipweave serves as a tunneling tool for the Orbweaver network and is derived from FCN.
From Personal Project to Military Product
The technical chain reconstructed by the dossier is linear: FCN evolves into STN Security Tunnel, which transforms into infrastructure-as-a-service for multi-hop relays. Two Chanming patents describe a multi-hop anonymization architecture matching the known design of RedRelay. The transition from personal open-source code to patented enterprise system is not anomalous in the Chinese context; it is the model Resecurity has documented for other contractors such as Knownsec and i-Soon.
RedRelay is classified by Mandiant as an ORB1 network: nodes from compromised IoT devices and routers, with a rotation cycle of 31 days or less to avoid tracking. Since roughly 2020, Chinese APT groups have systematically adopted this model. The strategic value lies in infrastructure sharing across different actors, which dilutes geographic attribution traces of C2 traffic.
"Either the FCN's unusual commands coincidentally match those of a covert-network malware which matches patent descriptions that name the FCN developer. Or FCN is a variant of the malware and the patents are an attempt to legitimise it." — Intrusion Truth
When Nearly a Dozen APTs Share the Same Vendor
The investigation links Chanming infrastructure to APT15 (Ke3chang, Vixen Panda, Red Vulture, NICKEL, Nylon Typhoon, Playful Dragon), with new designations proposed by Intrusion Truth: Unit 61046 and CSF 8th Bureau, the 8th Technical Reconnaissance Base of the PLA Cyberspace Force. These designations are not independently verifiable as official PLA designations; they are the collective's analytical reconstructions.
The dossier documents that nearly a dozen distinct APT clusters have used the same relay infrastructure. This finding, also reported by Risky.biz, has operational consequences for defenders. Mandiant had already observed in May 2024 that "the proliferation of ORB networks means defenders may need to abandon the concept of the attacking IP as a static indicator of compromise altogether, and instead treat adversary relay networks as threats in their own right."
Microsoft seized 42 domains in its operation against NICKEL (APT15) in December 2021. The discovery of Chanming explains why that disruption was partial: the domains were only the visible layer of a shared, replaceable commercial infrastructure.
What to Do Now
The confirmation that nearly a dozen APT clusters share a single commercial vendor has concrete operational implications for defenders. The first step is to integrate the documented technical indicators into monitoring platforms: SHA-256 hashes 30093c2502fed7b2b74597d06b91f57772f2ae50ac420bcaa627038af33a6982 (Whipweave), 68ee37b260facbae2869b57c85471bce156726b69ebe8a90af400fedb188b143 (FCN-related), and 7b9aa96c19d342b9a352cac8e53b116edc92b871afca86b6b8d6ea834678f029 (stn.exe-related) must be treated as signals of ORB infrastructure presence, not as single-actor indicators.
The second step is to abandon static C2 IP monitoring. With rotation cycles of 31 days or less, relay IP addresses are replaceable and shared across multiple actors. Threat intelligence teams must instead map domain patterns and network behaviors associated with multi-hop architectures, as described in the two Chanming patents.
The third step is to assess visibility over their own assets: IoT devices and consumer routers are the typical nodes of ORB1 networks. Network segmentation and detection of unauthorized tunneled traffic become priorities, given that these devices serve as relays without their owners' knowledge.
For intelligence decision-makers, the proposed designation of Unit 61046/CSF 8th Bureau as PLA (not MSS) requires attention in the classification of operations attributed to APT15. The legal framework and response options change depending on attribution to armed forces versus civilian security services.
Why It Matters
The dossier does not specify whether Guangdong Chanming still exists operationally after public exposure, nor whether legal or sanction actions are underway against the company or its shareholders. The source does not quantify the exact number of APT customers: "nearly a dozen" remains a vague qualifier. It is also unclear whether other Chinese vendors operate with an identical model to Chanming, though the structural context suggests it.
What emerges clearly instead is the vulnerability of the "plausible deniability" model based on commercial contractors. When a single invisible vendor serves multiple state actors, its identification via public OSINT simultaneously exposes the entire client network. The discovery of Chanming is not an anomaly to catalog; it is proof that attribution based on shared infrastructure can be more disruptive than attribution based on tactical indicators.
For the intelligence sector, the proposed designation of Unit 61046/CSF 8th Bureau as PLA (not MSS) shifts the legal framework of operations attributed to APT15. For enterprise defenders, the confirmation that multiple APTs share commercial infrastructure renders static IP monitoring obsolete. The effective target becomes the vendor, not the individual actor.
The Questions That Remain Open
The information has been verified against the cited sources and is current as of publication.
The information has been verified against the cited sources and is current as of publication.
Sources
- https://www.techtimes.com/articles/322063/20260729/guangdong-chanming-sold-spy-botnet-pla-nearly-dozen-chinese-hacking-groups.htm
- https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/
- https://www.cryptika.com/researchers-say-a-ghost-chinese-company-built-the-network-hiding-pla-cyberattacks/
- https://www.security.com/threat-intelligence/cloud-espionage-attacks
- https://www.resecurity.com/blog/article/knownsec-data-breach-a-trove-of-espionage-tradecraft-with-an-insider-narrative
- https://news.risky.biz/risky-bulletin-new-chinese-cyber-contractor-identified/
- https://www.qcc.com/cmainmember/5d96ff148bd19263df5c7f1f2c52f48f