KELA REPORT
Chinese Cybercrime Ecosystem [Report]
CISA prioritized Chinese cyber threats in 2023 amidst increased state-sponsored attacks and cybercrime originating from China.
Share:
![KELA report cover: Chinese Cybercrime Ecosystem [Report]](https://www.kelacyber.com/wp-content/uploads/2026/09/chinese-cybercrime-ecosystem-report-mockup-712x1024.png)
Mutual growth between financially motivated cybercriminals and state-sponsored APTs within the Chinese cybercrime ecosystem is noted. KELA’s research aims to empower defenders against these evolving threats.
Key Report Highlights:
- How China’s real-name internet rules, law-enforcement crackdowns and VPN and crypto restrictions shaped an ecosystem dominated by “gray” financial fraud
- The three layers of the ecosystem: tech and infosec hacking forums, established underground markets, and a Telegram fraud ecosystem offering hacking-as-a-service, card data, counterfeit IDs and money laundering
- Typical prices: corporate databases for USD 200-500, DDoS-as-a-service for USD 50 per attack, phishing tutorial packages for USD 100
- Chinese-speaking actors on non-Chinese platforms and the efforts of major forums to attract them
- Chinese APTs such as APT10, APT1, Mustang Panda, Gallium and Budworm using tools from the cybercrime ecosystem, including Poison Ivy and Quasar




