I-Soon — APT Profile
I-Soon (Shanghai Anxun) is a Chinese hacker-for-hire contractor for MPS, MSS, and PLA. Massive GitHub leak in February 2024 revealed espionage against 14+ foreign governments, NATO, and dissidents. Linked to APT41, RedAlpha, RedHotel. Develops ShadowPad malware and custom surveillance tools.Also tracked as
Anxun, Anxun Information Technology, iSOON
IntelFusions coverage (2)
- Chinese cyberspies hit governments with a stealthier Windows backdoor 2026-06-17 · Nation-State
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16 · Nation-State
Tools & malware
- Custom Android RAT Spyware
- Custom iOS Implant Spyware
- Custom Windows RAT Remote Access Trojan
- ShadowPad Backdoor
- Treadstone Command and Control
- Wi-Fi Surveillance Kit Hardware Implant
Vendor research
- Attributing I-SOON: Private Contractor Linked to Chinese State-Sponsored Groups Recorded Future
- Data from Chinese Security Services Company i-Soon Linked to Previous APT Campaigns Unit 42
- A First Analysis of the i-Soon Data Leak Malwarebytes
- I-SOON: An Analysis of the Chinese Hacker-for-Hire Ecosystem SentinelOne