ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft
|by Alpha Team

ZeroFox Intelligence Flash Report - iSoon Data Leak Provides a Glimpse of Chinese State Cyber Espionage Priorities, Tools, and Tradecraft
Product Serial: F-2024-02-21a
TLP:CLEAR
In this flash report, ZeroFox researchers provide an update on the iSoon data disclosures, which reveal the priorities, tools, and tradecraft of ongoing cyber espionage and influence operations being perpetrated by China nation-state actors.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- The iSoon data disclosures reveal the priorities, tools, and tradecraft of ongoing cyber espionage and influence operations being perpetrated by China nation-state actors, shedding light on the relationship between government contractors and the breadth of cyber tools at the Chinese government’s disposal.
- Although the authenticity of the documents remains unverified, preliminary analysis suggests iSoon is a Chinese MInistry of Public Safety-affiliated organization that, as of 2022, was tasked with offensive red team operations and monitoring Twitter (now X) to “curb illegal opinions” and to use accounts for “public opinion guidance and control.”
- Not much is known about the GitHub account and the user “I-S00N” that posted the leaked information (behavior consistent with both whistleblowing and disinformation campaigns), making it difficult to ascertain the ultimate goal of these disclosures.
Tags: tlp:clear, apac, threat actor, government