i-SOON, also known as iSoon, iSOON, Anxun Information, and Shanghai Anxun Information Technology Co., Ltd., is a Chinese private cybersecurity contractor that supplies cyberintrusion, surveillance, and intelligence-production services to Chinese state security agencies. Founded in Shanghai in 2010, it has operations in Chengdu and subsidiaries in Yunnan and Jiangsu. Its customers include the Ministry of Public Security, Ministry of State Security, and provincial and municipal security bureaus. The company operates within China's state-linked hacking-for-hire ecosystem, conducting intrusions and supplying stolen information and offensive platforms to government customers. Its targeting encompasses foreign government agencies, military and defense organizations, telecommunications providers, universities, healthcare institutions, media organizations, religious organizations, and critics of the Chinese government. Operations support foreign intelligence collection and surveillance of dissidents, including Tibetan and Xinjiang-related targets. Telecommunications compromises provide access to subscriber communications and location information. i-SOON's services span initial access, data exfiltration, and intelligence production. Its tradecraft includes phishing, credential collection, remote-access implants, keylogging, host reconnaissance, and pivoting through compromised systems. Email-collection and analysis platforms support continuous mailbox acquisition and large-scale searching, translation, and classification of stolen communications and documents. Associated FishMonger, also known as Earth Lusca, activity uses SprySocks backdoors on Linux and Windows; Windows variants employ kernel-level concealment of processes, files, and network connections. The company also has tooling and operational links to the Winnti and ShadowPad ecosystems and business connections to APT41-linked contractors, without being synonymous with APT41. Activity attributed to i-SOON has been tracked under Aquatic Panda, Red Alpha, Red Hotel, Charcoal Typhoon, Red Scylla, Hassium, Chromium, and TAG-22. These labels cover associated activity clusters rather than establishing that every cluster is interchangeable. A February 2024 internal-document leak exposed its contracting relationships and operational tooling. In March 2025, the United States indicted eight employees, including co-founders Wu Haibo and Chen Cheng, over alleged intrusions against government, media, and other organizations. The United Kingdom sanctioned the company in December 2025, followed by European Union sanctions against the company and its co-founders in March 2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese information security company discussed as a historical comparison for ZRON within China's commercial hacking ecosystem. The content notes its February 2024 internal-document leak and connections to APT41, without detailing its operations.
A Chinese information security company discussed as a historical comparison for the commercial hacking ecosystem revealed by the ZRON leak. The content identifies connections to APT41 but provides no specific malware, vulnerabilities, or operational techniques.
Mentioned as an example of a China-based intrusion company whose leaked documents reportedly showed commercialized espionage services and pricing for stolen data.
Cyber intrusion firm mentioned through business relationships involving entities connected to it and the company behind QTFY. No specific attacks, malware, exploited vulnerabilities, or operational involvement in the disrupted services are attributed to i-Soon in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.