KELA REPORT

Chinese Cybercrime Ecosystem [Report]

CISA prioritized Chinese cyber threats in 2023 amidst increased state-sponsored attacks and cybercrime originating from China.

Share:

KELA report cover: Chinese Cybercrime Ecosystem [Report]

Mutual growth between financially motivated cybercriminals and state-sponsored APTs within the Chinese cybercrime ecosystem is noted. KELA’s research aims to empower defenders against these evolving threats.

Key Report Highlights:

  • How China’s real-name internet rules, law-enforcement crackdowns and VPN and crypto restrictions shaped an ecosystem dominated by “gray” financial fraud
  • The three layers of the ecosystem: tech and infosec hacking forums, established underground markets, and a Telegram fraud ecosystem offering hacking-as-a-service, card data, counterfeit IDs and money laundering
  • Typical prices: corporate databases for USD 200-500, DDoS-as-a-service for USD 50 per attack, phishing tutorial packages for USD 100
  • Chinese-speaking actors on non-Chinese platforms and the efforts of major forums to attract them
  • Chinese APTs such as APT10, APT1, Mustang Panda, Gallium and Budworm using tools from the cybercrime ecosystem, including Poison Ivy and Quasar

Download the Report

Related Resources

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested