EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/i-soon-anxun-leak-2024
114/430

File EL-0317HighResolvedEspionage Operation / Commercialized State-Sponsored Hacking Tools

I-Soon (Anxun) Contractor Data Leak

Also filed as Anxun Information Technology Leak · Chinese MSS Contractor Leak

The leak exposed over 570 files from I-Soon, a private contractor for China's Ministry of Public Security. The documents reveal the commercialization of state-sponsored hacking, detailing tools used for surveillance, identity unmasking, and data theft. This provides an unprecedented look into the infrastructure of Chinese digital espionage.

  • #china
  • #mss
  • #anxun
  • #hacking-tools
  • #dissident-surveillance
  • #apt
  • #github-leak
Notoriety7/10
Event
16 Feb 2024
Disclosed
16 Feb 2024
Target
I-Soon (Anxun Information Technology)
Actor
Anonymous / Internal I-Soon Leak
Scale
190 Megabytes (Cache Size)
Status
Resolved

01Summary

The leak, which occurred in February 2024, provided a massive cache of documents detailing the services and tools offered by I-Soon (Anxun Information Technology). These tools were sold directly to Chinese police and intelligence agencies, confirming the commercial nature of state-backed cyber operations. Key capabilities exposed included sophisticated Remote Access Trojans (RATs) for multiple operating systems (Windows, Mac, iOS, Android), and specialized modules for unmasking the real-world identities of anonymous users on platforms like X (formerly Twitter). The leaked materials also contained target lists and evidence of hacking campaigns aimed at foreign governments and dissidents across Asia and NATO member states, highlighting the breadth of China's digital intelligence reach.

02Background

The incident highlights the growing trend of state intelligence services outsourcing cyber capabilities to private, commercial contractors. Before this leak, the full scope of how state actors monetized surveillance tools was largely opaque. The leak provided concrete evidence of the operational pipeline connecting state demand (MSS) to private execution (I-Soon).

03Key revelations

  1. 01The existence of a commercialized pipeline for state-sponsored hacking tools.
  2. 02Specific capabilities to unmask anonymous users on major social media platforms.
  3. 03Evidence of targeting foreign governments and political dissidents across multiple continents.

04Technical analysis

The leaked materials detailed specific malware families and toolkits, including custom RATs designed for persistent access and data exfiltration. The tools were highly tailored, suggesting a high degree of operational maturity and integration with state intelligence requirements. The focus on social media unmasking points to advanced techniques for correlating digital footprints with real-world identities.

Attack vector
N/A (The leak is the event, not an attack vector)
Attack method
Espionage and Surveillance
Initial access
Malware/Phishing (Implied)
Lateral movement
Remote Access (RATs)
Persistence
RATs/Backdoors
Exfiltration
Data Theft/Exfiltration
Tool / malware
Custom RATs, Unmasking Tools
Malware type
Spyware/RAT

MITRE ATT&CK techniques

  • T1056.001
  • T1071.001
  • T1566.001

05Threat actor

I-Soon (Anxun Information Technology) operated as a private contractor for China's Ministry of Public Security. Its business model was to develop and sell sophisticated, state-grade surveillance and hacking tools to domestic intelligence and law enforcement agencies.

Aliases

  • I-Soon (Anxun Information Technology)

MITRE groups

  • T1071.001
  • T1566.001

Attribution sources

  • Investigative Journalists
  • Security Researchers

06Victims and impact

Additional victims

  • Dissidents
  • Foreign Governments (India, Thailand, Vietnam, South Korea, NATO)
  • Social Media Platforms (X/Twitter)

Countries affected

  • China
  • India
  • Thailand
  • Vietnam
  • South Korea
  • NATO Member States

07Data exposed

Data types

  • Source Code
  • Hacking Tools
  • Target Lists
  • Operational Procedures

Notable documents

  • I-Soon Toolkits
  • Targeting Protocols

08Timeline

  1. 2024-02-16Leak of I-Soon (Anxun) contractor documents on GitHub.

09Reaction and fallout

Public reaction

The leak prompted international concern regarding the transparency and ethical boundaries of state-backed cyber operations. It fueled global debate over the privatization of intelligence gathering and the vulnerability of digital communication.

Political impact

The incident increased international scrutiny on China's cyber capabilities and its use of private contractors for intelligence gathering. It reinforced the narrative of China's growing digital authoritarianism.

Geopolitical consequences

It contributed to the ongoing geopolitical tension surrounding cyber sovereignty, particularly between Western nations and China, by providing technical proof of surveillance reach.

10Legal

No immediate legal action was reported against the contractor or the leak source, but the incident contributed to calls for international regulation of cyber warfare tools.

11Aftermath

Policy changes

  • Increased calls for international standards on cyber contractor accountability.

Regulatory changes

  • Enhanced scrutiny of foreign technology providers handling sensitive data.

Security improvements

  • Increased emphasis on end-to-end encryption and decentralized communication methods.

12Significance and legacy

Significance

This leak is significant because it provided a rare, technical glimpse into the commercialized structure of state espionage. It moved the discussion beyond abstract accusations of surveillance and into the concrete mechanics of how private companies facilitate national intelligence goals.

Legacy

The leak has contributed to a more detailed understanding of the cyber-intelligence supply chain, forcing security researchers and policymakers to consider the risks posed by private contractors operating with state-level access.

13Disclosure and media

Authentication
Source Code/Repository Analysis

Media partners

  • The Guardian
  • Security Research Outlets

Publishing organisations

  • GitHub

14Field notes

  1. 01The leak demonstrated that state intelligence services can effectively outsource highly sensitive, complex surveillance capabilities to private, for-profit entities.
  2. 02The tools were designed to operate across multiple major operating systems (Windows, Mac, iOS, Android), indicating a high level of technical resource allocation.

15Resolution

The leak was published on GitHub and subsequently analyzed by security researchers and journalists, leading to public awareness and academic study of the exposed tools.

16Sources

References

  1. [1]GitHub Repository Leak
  2. [2]Security Research Reports (2024)
Fact sheetEL-0317

Dates

Event
16 Feb 2024
Discovered
16 Feb 2024
Disclosed
16 Feb 2024
Ongoing
No

Target

Organisation
I-Soon (Anxun Information Technology)
Type
Corporation
Sector
Intelligence/Cybersecurity Services
Country
China
Gov. level
Contractor to MSS

Actor

Name
Anonymous / Internal I-Soon Leak
Type
Corporate Insider
Nationality
Chinese
Nation-state
China
Affiliation
Ministry of Public Security (MSS) Contractor
Motivation
Whistleblowing/Exposure of State Surveillance Practices
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
190 Megabytes (Cache Size)
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.