'Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
Some of China’s scrappiest hackers-for-hire are evolving into full-service private intelligence agencies, exploiting advances in artificial intelligence and other technologies to put stolen secrets of foreign governments at the fingertips of the country’s security agencies.
A trove of internal data belonging to a China-based cybersecurity company, reviewed by The Wall Street Journal, provides a new window into an evolution that international cybersecurity experts have tracked in recent years.
The material turns the table on hackers by providing an inside view of how they operate. It shows the company, Zhengzhou Zhirong Network Technology Co., or ZRON, offering a menu of sensitive data that is presented as coming from the government email systems of China’s rivals and friends alike. Documents in the trove include Russian diplomatic correspondence, preparations for foreign leaders’ visits to the Philippines and confidential minutes from a meeting in the Pakistan prime minister’s office.
The trove seen by the Journal also contains intelligence reports that appear to be based in part on stolen data, internal company chat logs and a company slide deck that appears aimed at prospective clients.
Detailed glimpses inside the operations of private Chinese hacking operations are rare. According to the chat logs, ZRONs sales representatives talk to clients across China’s northeastern, eastern and southern regions. Clients are referred to in the chats by code names, though they occasionally reveal the names of specific police units.
ZRON touts access to a vast database of public information scraped from social and traditional media, along with private data acquired from telecom operators based in Asia, according to the slide deck. Rather than simply hand over raw intelligence, the company has developed a dashboard system that combines, sorts and analyzes data to make it easier to digest, according to the slide deck, other information in the trove and software copyrights registered by the company.
Some of the ZRON material has been circulating among cybersecurity researchers in recent months. The Journal reviewed a large portion of the data, including internal company records and documents that ZRON appears to have obtained from foreign governments.
Western intelligence officials said ZRON belongs to an interconnected network of Chinese hacking-for-hire companies that steal and analyze confidential information and sell it to Chinese authorities.
For years, government officials and cybersecurity experts tracking China’s cyber espionage activities have asked the same question: How is Beijing planning to make use of the mountain of data its hackers have collected?
In the U.S., law-enforcement officials have tied Chinese actors to breaches involving hundreds of millions of records—a haul of intelligence even a bureaucracy as massive as China’s would struggle to sift.
The ZRON documents appear to show how some Chinese hackers-for-hire are competing to solve that problem. In offering not just the data, but also AI-driven systems to organize and analyze it, they promise to make their intelligence more accessible for a government hungry to understand what is happening around the globe.
“It makes a ton of sense, if you can get access to a bunch of data, to do your own ingestion and analysis and then sell it out as a product to many different customers,” said Dakota Cary, a China analyst at cybersecurity companySentinelOnewho has viewed some of the ZRON data. “It’s not surprising to see that companies are trying to play in that space.”
Multiple calls and text messages to phone numbers associated with ZRON employees went unanswered, and a comment request sent to its registered email address bounced back.
China’s Ministry of Foreign Affairs didn’t respond to a faxed request for comment. In the past, Beijing has denied involvement in cyber espionage and portrayed itself as one of the world’s foremost victims of hacking.
The chat logs discuss selling clients access permissions to foreign computer systems as well as acquiring data from third parties on behalf of clients, indicating ZRON both compromises networks directly and acts as a broker for stolen information.
In a country at the center of global trade, many local security agencies have an interest in foreign affairs. The police border-control unit in one heavily Muslim city in central China felt a report ZRON had sent them was too thin, a salesman wrote in April, saying the client wanted more intelligence on “key considerations associated with travel between China and the Middle East under the current geopolitical climate.”'