I-Soon — APT Profile
I-Soon (Shanghai Anxun) is a Chinese hacker-for-hire contractor for MPS, MSS, and PLA. Massive GitHub leak in February 2024 revealed espionage against 14+ foreign governments, NATO, and dissidents. Linked to APT41, RedAlpha, RedHotel. Develops ShadowPad malware and custom surveillance tools.Also tracked as
Anxun, Anxun Information Technology, iSOON, Houndstooth Typhoon, HASSIUM, DRAGNET PANDA, deepclif
IntelFusions coverage (3)
- One link was enough to backdoor a Chinese typing app 2026-09-18 · Vulnerabilities
- Chinese cyberspies hit governments with a stealthier Windows backdoor 2026-06-17 · Nation-State
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16 · Nation-State
Tools & malware
- Custom Android RAT Spyware
- Custom iOS Implant Spyware
- Custom Windows RAT Remote Access Trojan
- ShadowPad Backdoor
- Treadstone Command and Control
- Wi-Fi Surveillance Kit Hardware Implant
Vendor research
- Attributing I-SOON: Private Contractor Linked to Chinese State-Sponsored Groups Recorded Future
- Data from Chinese Security Services Company i-Soon Linked to Previous APT Campaigns Unit 42
- A First Analysis of the i-Soon Data Leak Malwarebytes
- I-SOON: An Analysis of the Chinese Hacker-for-Hire Ecosystem SentinelOne