Friday, September 11, 2026

VenusTech and Salt Typhoon Breach Sheds Light on China’s Covert Cyber Mercenary Networks

The dark web forum DarkForums, which has been a site for data breaches and leaks since BreachForums was shut down in mid-April, was the scene of two major leaks in late May involving Chinese cybersecurity organizations: VenusTech, a well-known IT security vendor, and Salt Typhoon, a state-sponsored advanced persistent threat (APT) organization affiliated with the Ministry of State Security (MSS).

These leaks, posted by newly created accounts “IronTooth” and “ChinaBob,” offer a rare glimpse into the intricate web of China’s hack-for-hire industry and its deep ties to government operations.

While the sample data provided is smaller compared to previous leaks like those from TopSec and iSoon, the exposed information ranging from government contracts to compromised infrastructure reveals critical insights into the operational structure and targets of these entities.

VenusTech Leak Exposes Government Contracts

The VenusTech leak, posted on May 17 by “IronTooth,” includes nonpublic documents, spreadsheets, and contracts that suggest the company’s involvement in offensive cyber operations for Chinese government clients.

Salt Typhoon
Spreadsheet containing transaction data 

VenusTech, founded in 1996 and listed on the Shenzhen Stock Exchange, has a documented history of engaging with hack-for-hire groups such as XFocus (creators of the 2003 Blaster worm) and Integrity Tech, linked to the Flax Typhoon hacking campaign.

The leaked spreadsheets, though lacking column headers, appear to detail intelligence targets and hacked organizations across regions like Hong Kong, India, Taiwan, South Korea, Croatia, and Thailand.

One notable entry indicates VenusTech’s access to the Korean National Assembly’s email server, with a contract to deliver monthly data updates for 65,000 yuan (approximately $9,000 USD).

Additionally, client lists featuring Unified Social Credit Codes point to various Chinese government entities as customers, underscoring VenusTech’s dual role as a security vendor and a facilitator of state-sponsored cyber espionage.

Salt Typhoon Data Leak Links MSS

“ChinaBob” posted data allegedly from Salt Typhoon, an APT group implicated in high-profile intrusions into US telecommunications firms and global infrastructure, including Viasat, as recently reported in 2024.

Salt Typhoon
ChinaBob’s original post to DarkForums offering Salt Typhoon data for sale.

The leak includes employee personal identifiable information (PII) such as Chinese national ID numbers and phone numbers, transaction records with cybersecurity vendors like Qi’anxin and VenusTech, and configurations of 242 hacked routers, some tied to Cisco devices a known target for Salt Typhoon.

Transaction data reveals dealings with entities like PLA Unit 61419, associated with the “Tick” threat group, and the Institute of Information Engineering of the Chinese Academy of Sciences, a stakeholder in iSoon.

Moreover, the data names two previously unindicted companies Beijing Huanyu Tiangiong Information Technology Company Limited and Sichuan Zhixin Ruijie Network Technology Company Limited alongside the sanctioned Sichuan Juxinhe Network Technology Company, as part of Salt Typhoon’s operational network, hinting at a broader front for MSS activities.

These leaks, while limited in scope, highlight the porous nature of China’s state-sanctioned cyber ecosystem, where insiders often siphon data for black market sales, and underscore the growing presence of Chinese cybercriminals in Western digital crime spaces.

They serve as pivot points for understanding the scale and sophistication of China’s covert cyber mercenary networks, raising urgent questions about global cybersecurity defenses against such state-backed threats.

Exclusive Webinar Alert: Harnessing Intel® Processor Innovations for Advanced API Security – Register for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News