An obscure company in Guangdong province with no public website, no product catalog, and no apparent customers built and sold the anonymous relay network used by almost a dozen Chinese state-sponsored hacking groups to hide the origins of their global intrusions — and then sold it directly to the People’s Liberation Army. That is the finding of new research published July 27, 2026, by cyber intelligence group Intrusion Truth, confirmed the same day by independent coverage from Risky Business News. China’s most sophisticated hacking groups did not build their own evasion infrastructure. They bought it off-the-shelf, from a vendor the intelligence community missed.
The company is Guangdong Chanming. It does not sell to the public, maintains no storefront, and has spent what appears to be considerable effort staying invisible. The evasion is incomplete.
Guangdong Chanming Sells Nothing — Except to the Chinese Military
Guangdong Chanming’s patent portfolio tells the story its marketing materials cannot, because it has none. Registered product names uncovered by Intrusion Truth researchers include an Internet Security Access System, a Multi-Functional Security Proxy System, a File Transfer Network System, an Anti-Traceability Network System, a Network Vulnerability Testing System, an Android Secret Extraction System, and a Telegram Data Collection System. As Intrusion Truth noted with characteristic dryness: “Subtle, Guangdong Chanming. Very subtle.”
None of these tools appear to be sold commercially. What Chanming does have is a documented military customer. Publicly accessible PLA procurement records — available on plap.mil.cn, a government purchasing platform — name Guangdong Chanming as the supplier of an “Anonymous Network System” to a military unit in Beijing’s Haidian District. Haidian hosts the PLA Cyberspace Force, China’s military branch responsible for offensive cyber operations.
The company lists two shareholders in its corporate filings: Dai Zhoujun and Wang Huiping. Wang Huiping proved to be the thread that unraveled the company’s obscurity.
How Researchers Traced a VPN Side Project to a Military Backdoor
Using phone numbers extracted from Chanming’s corporate records, Intrusion Truth linked Wang Huiping to the email address boywhp@126.com, which appeared repeatedly in leaked data breach dumps. That address was attached to a GitHub repository for a piece of software called Free Connect, or FCN — a Chinese VPN tool Wang had originally developed as a personal project.
The FCN repository has since been deleted from GitHub, but forks remain online, pointing researchers to the domain xfconnect.com. A VirusTotal search on that domain returned multiple FCN binaries, one of which closely resembled a file called stn.exe — sold under Chanming’s product line as the “STN Security Tunnel.” Strings extracted from the STN binary contain direct references to FCN, confirming a direct lineage: Wang’s personal VPN project became Chanming’s commercial intelligence tool.
The most technically significant finding came from the Linux builds of FCN, which share an unusual command used to identify a network interface. Every Linux version of FCN examined by Intrusion Truth used the same distinctive chain of commands that Mandiant and other security vendors had already documented inside the WHIPWEAVE malware. WHIPWEAVE — also known by its filename, bulbature — is a core tunneling component of the RedRelay covert network, which Mandiant tracks as ORBWEAVER. Two of Chanming’s own patents describe a multi-hop, anonymizing traffic architecture that aligns exactly with RedRelay’s known design.
Intrusion Truth’s assessment: either an extraordinary set of unrelated coincidences converged — the same unusual command appearing in both a personal VPN project and a state-linked covert network, whose architecture matches the patents of the VPN developer’s company — or FCN is a variant of the malware itself, and the patents exist to provide commercial cover for what is, in practice, a military relay tool.
What the RedRelay Network Is and Why It Matters
RedRelay is what the cybersecurity industry calls an Operational Relay Box (ORB) network: a proxy botnet built specifically for intelligence operations. Rather than connecting directly from Chinese infrastructure to a target organization’s network, an operator routes all command-and-control traffic through chains of intermediate nodes — compromised routers, leased virtual private servers, and internet-of-things devices distributed across multiple countries. A network analyst at the victim organization sees traffic appearing to originate from a server in Germany or Brazil, not from China.
Google’s Mandiant unit published landmark research on this trend in May 2024, documenting how Chinese APT groups had systematically adopted ORB networks since approximately 2020, and describing the model as “the professionalization of infrastructure-as-a-service.” Mandiant classified RedRelay as ORB1 — a non-provisioned network, built primarily from compromised devices rather than leased servers, with individual nodes cycling every 31 days or fewer to evade tracking.
When Any Hacking Group Can Buy the Same Evasion Network, Attribution Breaks Down
The deeper significance of the Chanming exposure is not the corporate attribution story — it is what it reveals about how Chinese cyber operations have been structured. Almost a dozen distinct APT clusters, including the PLA and China’s Ministry of Public Security, were using the same relay infrastructure purchased from a single vendor. Traditional threat intelligence tracks indicators of compromise tied to specific hacking groups. When multiple groups share a commercially-supplied relay network, those indicators no longer distinguish between actors — and the infrastructure vendor, not the APT group, is the node that needs to be targeted for disruption.
Mandiant’s analysts concluded in 2024 that the spread of ORB networks means defenders may need to abandon the concept of attacker IPs as static indicators of compromise entirely, and instead treat adversary relay networks as threats in themselves — with their own shifting tactics and techniques.
PLA Unit 61046, the CSF 8th Bureau, and APT15
Having established the probable link between Chanming’s product and the RedRelay network, Intrusion Truth turned to the customer roster. PLA procurement records confirm Chanming supplied an “Anonymous Network System” to a Haidian District military unit. Cross-referencing RedRelay’s known users against that Haidian customer trail, researchers connected the infrastructure to APT15 — one of the most extensively documented Chinese cyber-espionage actors in the threat intelligence record.
APT15 goes by more aliases than nearly any other tracked group: Ke3chang, Vixen Panda, Red Vulture, Playful Dragon, Nylon Typhoon, NICKEL, and others. It has been active since at least 2010 and has targeted oil companies, government ministries, diplomatic agencies, military organizations, and NGOs across Central and South America, the Caribbean, Europe, and North America. In December 2021, Microsoft seized 42 domains associated with APT15’s NICKEL infrastructure.
Intrusion Truth’s new research adds two designations to APT15’s alias list: Unit 61046 and the CSF 8th Bureau — the 8th Technical Reconnaissance Base of the PLA Cyberspace Force. This attribution shift matters: operations previously tracked under MSS-linked APT designations may in fact be PLA military cyber operations, with different implications under international law. The group has been using Chanming’s RedRelay network to conduct espionage campaigns worldwide. Intrusion Truth has promised a follow-up report detailing specific operational campaigns.
China’s Contractor Problem Keeps Growing
For those tracking the Chinese state cyber ecosystem, the Chanming identification fits a structural pattern that has been emerging since early 2024.
In February 2024, documents from i-Soon — a Shanghai-based cybersecurity contractor — were leaked to GitHub, exposing the firm’s contracts with China’s Ministry of State Security and Ministry of Public Security. The leak revealed internal chat logs, contract terms, offensive tooling, and evidence of intrusions targeting government and telecom organizations across Asia and Europe. A year later, in March 2025, the US Department of Justice unsealed indictments charging 12 individuals — including 8 i-Soon employees and 2 Ministry of Public Security officers — for hacking campaigns stretching back to 2016.
In November 2025, a separate leak exposed KnownSec, a Beijing-based firm with documented government ties. More than 12,000 classified internal documents were posted briefly to GitHub before removal, revealing hacking tools, global target lists, and evidence of stolen data including immigration records from India, call records from South Korea’s LG U Plus, and transport planning data from Taiwan.
Guangdong Chanming differs from both in one structural respect: it was not exposed by a leak. Intrusion Truth identified the company entirely through open-source investigation — patent registries, corporate filings, breach data dumps, VirusTotal queries, GitHub forks, and public procurement databases. A company that has gone to considerable lengths to avoid public visibility left enough of a traceable record across public systems to be identified by determined investigators. The implication is uncomfortable for any state cyber contractor operating in China: the infrastructure of official invisibility is itself visible, if you know where to look.
What Defenders Should Do With This Information
For security teams, the Chanming disclosure produces a specific, actionable intelligence upgrade. RedRelay and ORBWEAVER indicators of compromise — previously associated with a diffuse collection of Chinese APT designations — can now be more tightly anchored to a specific supplier and a specific set of confirmed state customers. That anchoring matters for strategic intelligence even when it offers limited help for real-time detection, because ORB networks are specifically designed to rotate nodes fast enough to defeat static indicator blocking.
The broader defensive implication is that vendor-level disruption — sanctions, indictments, or operational takedowns targeting infrastructure suppliers rather than the APT groups who use their products — is the structural gap in current Western response frameworks. Targeting APT15 or its aliases leaves Chanming in place to sell the same relay service to the next group.
China’s National Intelligence Law of 2017, Article 7, requires all organizations and citizens to support, assist, and cooperate with state intelligence work. Article 14 grants intelligence agencies authority to demand that cooperation. For Chanming, those provisions are already moot: the PLA procurement contracts confirm the relationship is direct and explicit. For any other Chinese company whose tools end up in an adversary’s hands, the legal architecture exists to mandate the same.
Intrusion Truth has indicated its next article will detail exactly how Unit 61046 and the CSF 8th Bureau used Chanming’s relay infrastructure in specific operational campaigns. The ghost, it turns out, left a trail.
Frequently Asked Questions
What is an ORB network and why do Chinese hackers use it?
An Operational Relay Box network is a proxy botnet — a mesh of compromised devices and leased servers spread across multiple countries — used to route attack traffic through intermediate nodes before it reaches a target. The result is that a victim organization’s network logs show traffic originating from a server in Germany or Brazil, not China. Chinese espionage groups began systematically using ORB networks around 2020, according to Google’s Mandiant unit. The appeal is straightforward: ORB networks make attribution dramatically harder, because the intermediate nodes cycle frequently, and multiple hacking groups can share the same infrastructure simultaneously.
What makes Guangdong Chanming different from i-Soon and KnownSec?
The i-Soon and KnownSec contractor exposures both resulted from data leaks — someone posted internal company documents. Guangdong Chanming was identified entirely through open-source investigation: patent filings, corporate records, breach data, and public procurement databases. No insider leak was required. That distinction matters for the broader question of how China’s cyber-industrial complex stays hidden: even a company with no public presence, no website, and no visible commercial activity leaves a discoverable trail in the public systems it must use to register patents and win government contracts.
What does this mean for organizations trying to defend against Chinese cyber threats?
The Chanming disclosure reveals a structural gap in how threat intelligence is typically organized. Most threat detection focuses on indicators tied to specific APT groups — IP addresses, malware signatures, domain names. When almost a dozen APT groups share commercial relay infrastructure from a single vendor, those group-level indicators stop being reliable markers of a specific actor. Mandiant’s analysts warned in 2024 that ORB networks may have made static IP-based indicators of compromise obsolete. The practical implication is that defensive postures aimed at blocking named APT groups, rather than disrupting the infrastructure vendors who supply them, are incomplete. Security teams should treat ORBWEAVER/RedRelay indicators as infrastructure-level threats, not APT-specific signatures.
Could Guangdong Chanming face US sanctions or indictment?
No action against Guangdong Chanming has been announced as of publication. The pattern from comparable cases suggests it is a possibility: the DoJ indicted 12 individuals connected to i-Soon in March 2025, and the Treasury Department sanctioned Sichuan Juxinhe Network Technology in January 2025 for its role in Salt Typhoon’s telecom intrusions. The PLA procurement records linking Chanming to a Haidian military unit — available on a public government procurement platform — provide a direct evidentiary trail of the kind that has supported prior US enforcement actions against Chinese cyber contractors.
Click Here For The Original Source.
