KELA REPORT

Alleged Knownsec Data Leak

In late October 2025, a significant data leak allegedly exposed the internal operations of Knownsec, one of China’s leading cybersecurity firms. This research report analyzes the 12,000+ file dataset to reveal a company operating under a "civil-military fusion" model. Publicly, Knownsec acts as a commercial innovator. However, it secretly serves as a contractor for Chinese state agencies like the Ministry of Public Security.

Share:

KELA report cover: Alleged Knownsec Data Leak

In KELA’s new report, you’ll learn:

  • State-Private Nexus: Documents reveal organizational links between Knownsec and the Ministry of Public Security. This illustrates the blurred lines between private vendors and state intelligence .
  • Global Target Mapping: Analysis of a “Key Infrastructure Target Database” shows the tracking of over 24,000 organizations and 379 million IPs. These targets span nations like the US, Japan, and the UK .
  • Weaponized Reconnaissance: The internal version of ZoomEye is used not just for search, but also to identify and prioritize vulnerable assets for exploitation campaigns .
  • Offensive Toolset: KELA details proprietary tools like “Un-Mail” for email interception and “GhostX” for identity theft. These tools were developed well beyond the scope of defensive security.

Download the Report

Related Resources

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested