Ghost Chinese Company Allegedly Built Network Infrastructure for PLA Cyber Operations
Researchers have identified Guangdong Chanming, a Chinese company with no public presence, as a potential supplier of covert networking technology to the People's Liberation Army, enabling obfuscation of state-backed cyberattacks.

A little-known Chinese company, Guangdong Chanming, is under scrutiny by researchers for its alleged role in providing covert networking technology to the People's Liberation Army (PLA). This infrastructure is believed to be instrumental in obscuring the origins of state-backed cyber espionage campaigns, making attribution significantly more challenging for defenders.
The research, conducted by IntrusionTruth, points to Guangdong Chanming as a supplier of anonymous networking systems, based on an analysis of company filings, software records, patents, and military procurement documents. The company itself appears to have no public website or visible commercial product catalog, leading researchers to dub it a 'ghost' entity. Despite its lack of public presence, its registered patents and software copyrights describe products with names such as 'Internet Security Access System,' 'Multi-functional Security Proxy System,' and 'Anti-traceability Network System,' suggesting capabilities in surveillance, data collection, and concealment.
Significant findings include procurement listings that reportedly name Guangdong Chanming as a supplier to the PLA. One such listing allegedly details the delivery of an 'Anonymous Network System' to a military unit in Beijing's Haidian District. This district is notable for hosting major Chinese military and technology organizations, including those associated with the PLA Cyberspace Force, the branch responsible for China's military cyber operations. This connection suggests the company's technology may directly support the PLA's cyber warfare capabilities.
The infrastructure provided by Guangdong Chanming could offer a crucial layer of deniability for state-sponsored threat actors. By enabling operators to hide command traffic, relay data through multiple systems, and reduce the traceability of their activities, these tools complicate investigations and allow for the prolonged execution of espionage campaigns. This alleged setup aligns with known tactics where covert access tools are disguised within legitimate traffic or utilize relay systems to evade detection.
Further investigation by IntrusionTruth linked a shareholder of Guangdong Chanming, Wang Huiping, to the 'FreeConnect' (FCN) software project. Researchers found that versions of FCN hosted on GitHub shared technical similarities with 'stn.exe,' a component of Guangdong Chanming's STN Security Tunnel product. Moreover, a distinctive command used in FCN's Linux versions led researchers to 'bulbature,' a file associated with the WHIPWEAVE malware, which has been linked to the RedRelay or ORBWEAVER covert network.
While the overlap in development clues, patent descriptions, and procurement records does not definitively prove that every FCN user is involved in state operations, IntrusionTruth argues that these combined factors paint a compelling picture. The evidence suggests a commercial toolset that may have evolved into critical infrastructure for Chinese threat actors, potentially supporting well-known APT groups like Red Vulture, APT15, Ke3chang, and others associated with PLA Unit 61046.
Organizations operating in sectors targeted by Chinese state-sponsored cyber espionage should remain vigilant. Key indicators include unusual encrypted outbound traffic, unfamiliar proxy services, and unexplained network routes. Implementing strong network segmentation, multi-factor authentication, and maintaining robust network visibility are essential defenses against these sophisticated, infrastructure-backed campaigns.
The report highlights the increasing reliance of state actors on seemingly legitimate commercial entities or 'ghost' companies to build and maintain the sophisticated infrastructure required for global cyber operations. This trend underscores the evolving nature of cyber warfare, where the lines between commercial enterprise and military support are increasingly blurred.