How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying

Dow Jones
3小时前

Some of China's scrappiest hackers-for-hire are evolving into full-service private intelligence agencies, exploiting advances in artificial intelligence and other technologies to put stolen secrets of foreign governments at the fingertips of the country's security agencies.

A trove of internal data belonging to a China-based cybersecurity company, reviewed by The Wall Street Journal, provides a new window into an evolution that international cybersecurity experts have tracked in recent years.

The material turns the table on hackers by providing an inside view of how they operate. It shows the company, Zhengzhou Zhirong Network Technology Co., or ZRON, offering a menu of sensitive data that is presented as coming from the government email systems of China's rivals and friends alike. Documents in the trove include Russian diplomatic correspondence, preparations for foreign leaders' visits to the Philippines and confidential minutes from a meeting in the Pakistan prime minister's office.

The trove seen by the Journal also contains intelligence reports that appear to be based in part on stolen data, internal company chat logs and a company slide deck that appears aimed at prospective clients.

Detailed glimpses inside the operations of private Chinese hacking operations are rare. According to the chat logs, ZRONs sales representatives talk to clients across China's northeastern, eastern and southern regions. Clients are referred to in the chats by code names, though they occasionally reveal the names of specific police units.

ZRON touts access to a vast database of public information scraped from social and traditional media, along with private data acquired from telecom operators based in Asia, according to the slide deck. Rather than simply hand over raw intelligence, the company has developed a dashboard system that combines, sorts and analyzes data to make it easier to digest, according to the slide deck, other information in the trove and software copyrights registered by the company.

Some of the ZRON material has been circulating among cybersecurity researchers in recent months. The Journal reviewed a large portion of the data, including internal company records and documents that ZRON appears to have obtained from foreign governments.

Western intelligence officials said ZRON belongs to an interconnected network of Chinese hacking-for-hire companies that steal and analyze confidential information and sell it to Chinese authorities.

For years, government officials and cybersecurity experts tracking China's cyber espionage activities have asked the same question: How is Beijing planning to make use of the mountain of data its hackers have collected?

In the U.S., law-enforcement officials have tied Chinese actors to breaches involving hundreds of millions of records-a haul of intelligence even a bureaucracy as massive as China's would struggle to sift.

The ZRON documents appear to show how some Chinese hackers-for-hire are competing to solve that problem. In offering not just the data, but also AI-driven systems to organize and analyze it, they promise to make their intelligence more accessible for a government hungry to understand what's happening around the globe.

"It makes a ton of sense, if you can get access to a bunch of data, to do your own ingestion and analysis and then sell it out as a product to many different customers," said Dakota Cary, a China analyst at cybersecurity company SentinelOne who has viewed some of the ZRON data. "It's not surprising to see that companies are trying to play in that space."

Multiple calls and text messages to phone numbers associated with ZRON employees went unanswered, and a comment request sent to its registered email address bounced back.

China's Ministry of Foreign Affairs didn't respond to a faxed request for comment. In the past, Beijing has denied involvement in cyber espionage and portrayed itself as one of the world's foremost victims of hacking.

The chat logs discuss selling clients access permissions to foreign computer systems as well as acquiring data from third parties on behalf of clients, indicating ZRON both compromises networks directly and acts as a broker for stolen information.

In a country at the center of global trade, many local security agencies have an interest in foreign affairs. The police border-control unit in one heavily Muslim city in central China felt a report ZRON had sent them was too thin, a salesman wrote in April, saying the client wanted more intelligence on "key considerations associated with travel between China and the Middle East under the current geopolitical climate."

Offering an apparent window into the company's marketing strategy, ZRON's slide deck touts a tool that allegedly allows users to monitor screens, log keystrokes and execute commands on computers running the Windows operating system. Another promises access to system information, contacts and location data on devices running Apple's iOS mobile operating system.

The presentation also features a system for harvesting data from mainstream webmail servers and internal email systems, along with data visualization tools that map out email communication networks. Other tools promise the ability to track and analyze foreign media.

To tie it all together, the slide deck outlines an AI-powered "intelligent" system capable of running models by companies like Alibaba and DeepSeek that can organize messy data sets, generate incident timelines and produce automated reports.

It isn't clear whether ZRON had the capability to provide the full suite of products its slide deck describes, or whether it was using AI to exploit vulnerabilities in foreign computer networks. Chinese corporate registry data shows the company owns copyrights to software that cybersecurity experts say could enable the company to do what it promises.

The Journal couldn't independently verify the authenticity of the foreign government documents in the trove. But many of the documents align closely with public events. Some include draft texts that were later posted online.

An 18-page document, marked secret and seemingly circulated to senior Pakistan government officials, contains what appear to be minutes and decisions from a meeting of an economic coordination committee in May 2023 in the prime minister's office. A summary of the meeting was posted on the Pakistan Finance Ministry's website.

Documents that appear to be linked to Russia's government include talking points for the country's civil defense minister, a letter from a Russian business executive to a foreign affairs official and a diplomatic note analyzing a foreign ambassador's public remarks.

The Philippines, which has been locked for more than a decade in an intense standoff with China over disputed territorial claims in the South China Sea, appeared to be a top target. A review by the Journal of several spreadsheets describing data from the Southeast Asian country that ZRON appeared to be offering included 19 distinct government email addresses.

One document provides inputs for a Philippine official's meeting with a U.S. National Security Council director during a March 2025 conference in India. An online program for the conference, called the Raisina Dialogue, listed the NSC director as a speaker.

A Philippine government email titled "EXTREMELY URGENT AND CONFIDENTIAL" contains briefing materials about South China Sea territorial issues and other topics for a state visit by Vietnam's president that took place on May 31 and June 1.

Even the Vatican appeared to attract ZRON's interest.

A message that was apparently sent from the Vatican's Secretary of State email address is marked April 23, 2025, two days after Pope Francis' death, and includes an attachment with letterhead indicating it is from Taiwan's Embassy to the Holy See. The attachment lists three Taiwanese delegates who planned to attend the pope's funeral and their flight details. All three were later photographed at the funeral.

The Vatican is one of a small coterie of governments that officially recognizes Taiwan, which Beijing claims as part of China.

The foreign ministries of the Philippines and Taiwan declined to confirm or deny the authenticity of the hacked materials. Both said they pay serious attention to the security of their computer systems.

The Vatican and the foreign ministries of Pakistan and Russia didn't respond to requests for comment.

Document summaries ZRON supplies to prospective clients sometimes include sensitive personal information. One entry names U.S. officials who had applied for temporary visas to enter Pakistan, along with their visa tracking numbers. Other entries contain foreign citizens' passport numbers.

The State Department said it wouldn't comment on the authenticity or content of alleged leaked or hacked material.

It wasn't immediately evident how many of the documents that were described in summaries were obtained by ZRON or whether they had been supplied to customers. In some cases, specific email addresses were listed alongside document summaries as sources.

The company's internal chats show employees trying to market the AI platform to prospective customers.

"AI can handle the risk assessments and recommendations in the reports; we only need to provide the source material," one staffer wrote in an internal chat in early 2025. "This could lead to a qualitative leap in both the quality and quantity of our reports."

ZRON isn't alone in offering easy-to-use intelligence to Chinese police. Last year, cybersecurity researcher Marc Hofer found unprotected police servers of two domestic surveillance platforms with similar features, including one designed to help local police track the movements of foreigners in the skiing destination of Zhangjiakou.

应版权方要求,你需要登录查看该内容

免责声明:投资有风险,本文并非投资建议,以上内容不应被视为任何金融产品的购买或出售要约、建议或邀请,作者或其他用户的任何相关讨论、评论或帖子也不应被视为此类内容。本文仅供一般参考,不考虑您的个人投资目标、财务状况或需求。TTM对信息的准确性和完整性不承担任何责任或保证,投资者应自行研究并在投资前寻求专业建议。

热议股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10