Restrictive Laws Push Chinese Cybercrime toward Novel Monetization Techniques
Full article2,999 words · extracted from recordedfuture.com · click to collapse
Editor’s Note: To read the entire analysis with footnotes, click here to download the report as a PDF.
This report analyzes the structure of internet sources used by Chinese-speaking threat actors to facilitate cybercriminal activities. It focuses specifically on advertisements, posts, and interactions on Chinese-language dark web marketplaces and cybercrime-related Telegram channels. It also takes into consideration the effect of Chinese laws and regulations on data security and cybercrime in China. This report is a follow-up to our previous reporting in 2021 on China’s cybercrime landscape and Chinese cybercrime in neighboring countries. It will be of greatest interest to organizations and geopolitical analysts seeking to understand the cybercriminal underground in order to better monitor security-related threats, as well as to those researching the Chinese-language underground.
Executive Summary
As China has continued to pass cybersecurity laws that give greater control to the state, this has inversely affected cybercrime as the companies that are usually targeted are being required to better secure personally identifiable information (PII) data. Nonetheless, PII data (of both Chinese nationals and international entities) is still being widely compromised and sold on dark web marketplaces, special-access forums, and Telegram channels. Furthermore, new laws banning cryptocurrency trading, the tightening of banking regulations, and a renewed crackdown on telecommunications (telecom) and online fraud continue to make it tougher for cybercriminals to operate in China. As a result, cybercriminals have moved their operations abroad and devised novel ways to weaponize PII data to perpetrate fraudulent activities.
We analyzed new Chinese-language dark web marketplaces that have emerged in the past year as well as popular Chinese-language Telegram channels devoted to cybercrime. We surveyed Chinese- and Taiwanese-related PII and access offerings on English- and Russian-language special-access forums and analyzed how they could provide initial access to ransomware threat actors. We also examined some unique scams in the Chinese cybercrime landscape and how they could be traced back to aforementioned dark web marketplace offerings. Finally, we provided some analysis on how geopolitical tension between China and Taiwan might shape cross-strait cyber conflicts in the coming years.
Key Judgments
- The enactments of China’s Personal Information Protection Law (PIPL) and Data Security Law (DSL) signal that the Chinese government is serious about data security. The banning of cryptocurrency trading, mining, and advertisement, new regulations against money laundering, and new laws to combat telecom and online fraud are making it increasingly challenging for cybercriminals to operate in China as well as in neighboring countries.
- China’s drive toward a digital economy enabled by big data has opened up the attack surface for hackers and leaves data vulnerable, resulting in several high-profile data breaches leading to exposures of large numbers of PII data during the past year. It is highly likely that threat actors have harvested and analyzed big sets of data, organizing and parsing them into smaller sets of data that contain more specific groups and individuals in order to monetize them through cybercriminal sources.
- Despite the challenges noted above, Chinese-language dark web marketplaces continue to evolve, with new ones emerging to replace older ones that have gone offline. Telegram also serves an important role in the Chinese cybercrime scene, as it has been used to complement dark web marketplaces with threat actors who often advertise data sets and vice activities on their Telegram channels.
- As more leaked data from foreign countries appear on Chinese-language dark web marketplaces and more Chinese/Taiwanese data and access are posted on popular English- and Russian-language criminal sources, the national borders are increasingly blurred for cybercriminals.
- Chinese cybercriminals have become more organized in their transnational operations as they devise innovative ways to weaponize personally identifiable information (PII) to conduct fraud via sophisticated spearphishing schemes.
Background
Our previous reporting on the Chinese cybercrime landscape covered the Chinese-language dark web markets, clearnet hacking forums and blogs, and messaging platforms. We analyzed the features of these sources and the tactics, techniques, and procedures (TTPs) of Chinese-speaking threat actors within the context of their distinct cultural, political, and legal characteristics. In our reporting on Chinese cybercrime in neighboring countries, we uncovered the trend of well-resourced Chinese cybercrime syndicates moving their operations abroad, especially to Southeast Asian countries where the laws are more relaxed, which has enabled them to perpetuate fraud (such as online romance scams using the CryptoRom malware) on a global scale. As China marches toward a digital economy and enacts new laws and regulations to tighten data security and crack down on telecom fraud and cybercrimes, the environment becomes increasingly challenging for cybercriminals. However, new socioeconomic and technological developments present opportunities for cybercriminals who are constantly updating their TTPs to survive and thrive in the new landscape.
Threat Analysis
Laws and Regulations Affecting the Chinese Cybercriminal Landscape
In this section, we summarize various laws and regulations that went into effect during the past year that have a direct impact on the Chinese cybercriminal landscape, specifically the collection and storage of PII data by private companies, the Chinese government's continued crackdown on crypto use and mining, and laws designed to stymie activities that facilitate fraud and criminality.
The Enactments of PIPL and DSL
On November 1, 2021, China’s Personal Information Protection Law (PIPL), which was passed by the National People’s Congress on August 20, 2021, went into effect. The PIPL is seen as the Chinese equivalent of the European Union’s General Data Protection Regulation (GDPR) and was expected to add more compliance requirements for companies in the country. The Chinese government has instructed its tech giants to ensure better secure storage of user data, amid public complaints about mismanagement and misuse that have resulted in user privacy violations. The law stated that handling of personal information must have clear and reasonable purpose and shall be limited to the "minimum scope necessary to achieve the goals of handling" data. It also laid out conditions companies must abide by to collect personal data, including obtaining an individual's consent, and it also laid out guidelines for ensuring data protection when data is transferred outside the country. The law further called for handlers of personal information to designate an individual in charge of personal information protection, and also called for handlers to conduct periodic audits to ensure compliance with the law. The implementation of PIPL came after the passage of the Data Security Law (DSL), which came into effect on September 21, 2021, and set a framework for companies to classify data based on its economic value and relevance to China's national security. Together, PIPL and DSL provide 2 major regulations for governing China's internet in the future.
Didi Fined for Data Security Violations
On July 21, 2022, China’s internet regulator fined ride-hailing giant Didi $1.2 billion for its voracious data collection policies and lackluster security protections around sensitive user information.
The Cyberspace Administration of China (CAC) said it had concluded a network security review of the company and found “illegal activities” and violations of the country’s network security laws (DSL and PIPL). The fine was the largest data protection penalty ever issued by China, and the second-largest fine imposed on a Chinese technology firm after regulators slapped Alibaba with a $2.75 billion fine last year following an anti-monopoly probe.
The CAC said that during its investigation of Didi, which began in 2021, it found 16 violations that included the illegal collection of nearly 12 million users’ photo albums, 107 million facial recognition profiles of passengers, and significant amounts of users’ PPI data. According to Chinese regulators, Didi kept millions of sensitive user records unencrypted, causing “national security risks”.
The company’s app was also collecting “excessive” information on its drivers and often asked for device permissions that allowed widespread access to users’ devices. A spokesperson for the CAC criticized the company for having “inaccurate and unclear” descriptions of why it needed the information it was collecting.
The CAC said it plans to “intensify” its enforcement of cybersecurity and data protection laws in the coming years.
The Banning of Cryptocurrency Mining, Trading, and Advertisement, and the Introduction of Digital Yuan
While China has maintained a hostile relationship with the cryptocurrency industry since 2013, the latest crackdowns in 2021 were seen as the most severe. Citing concerns related to its effect on the climate, the State Council began calling for restrictions on crypto mining and trading in May 2021. Following the statement, provincial governments such as Inner Mongolia’s began to take proactive measures to eradicate crypto mining. As a result, miners in those regions were either forced to shut down permanently or to move to other crypto-friendly countries. In August 2021, the CAC ordered social media platforms to terminate 12,000 accounts that were promoting cryptocurrency “in the name of financial innovation”. The purged accounts spanned multiple platforms including Weibo, Baidu, and WeChat. It also shut down 105 websites that ran tutorials for cryptocurrency buying and selling. In September 2021, Chinese authorities ordered a fresh round of crackdowns on crypto mining and outlawed virtually all crypto trading activities.
In early 2022, the Chinese Central Bank issued the digital yuan (also known as the Digital Currency Electronic Payment (DCEP), e-Renminbi (e-RMB), and e-CNY), which was piloted in various Chinese cities during the second half of 2021 and made its global debut at the Beijing Winter Olympics in February 2022. It is a central bank digital currency (CBDC) that relies on blockchain technology to conduct transactions but is centrally controlled by regulatory authorities and backed up by fiat currency reserves. And unlike cryptocurrency, which offers a great deal of privacy and anonymity, the digital yuan gives the government unprecedented visibility into transactions as they have direct access to the data. It can also be made programmable so that the government can issue or cut off payments. 10 countries have already launched a CBDC and many more are considering it.
All Chinese-language dark web markets operate on cryptocurrency such as Bitcoin, Tether, and Ethereum. As detailed later in the dark web marketplace section, while we observed a number of such marketplaces going offline, new ones emerged to take their place. As a result of both government crackdowns in China and the issuance of the digital yuan, cryptocurrency trading will be pushed further into the underground and increasingly conducted on dark web marketplaces.
Regulations to Combat Money Laundering
A new regulation designed to combat money laundering was issued by China’s central bank and was scheduled to take effect on March 1, 2022. However, it was postponed due to “technical reasons”.
The new regulation requires people who make a single cash deposit or withdrawal that exceeds 50,000 yuan ($6,904 USD), or $10,000 USD in a foreign currency, to report the source and intended use of the money. Banks and other licensed financial institutions handling relevant transactions must also validate and store clients’ information, according to the joint order issued last month by the People’s Bank of China (PBoC), the China Banking and Insurance Regulatory Commission, and the China Securities Regulatory Commission.
Critics of the regulation claimed that it will effectively infringe on individual property rights by giving financial institutions the power to restrict deposits and withdrawals at their discretion, and may also mute capital flows and impede China’s economic recovery. Together with the ban on cryptocurrency trading, this new regulation makes it harder for cybercriminals inside of China to cash out their earnings.
Law Enforcement on Telecom and Online Fraud
On September 2, 2022,《中华人民共和国反电信网络诈骗法》(Law of the People’s Republic of China on Combating Telecom and Online Fraud) was passed during the 36th session of the Standing Committee of the 13th National People's Congress (NPC), and is set to take effect in December 2022.
The law was passed as telecom and online fraud grew more rampant in China during the past decade. The South China Morning Post reported that in recent years, criminals have illegally obtained victims’ information through advanced telecom network technologies and taken advantage of loopholes in management, and that this activity has become so rampant that it has posed serious threats to public security and social stability. Criminal syndicates have reportedly become better organized, with clear divisions of labor, and are able to conduct activities across multiple countries with the intention to scam people in China.
The law places major responsibility for anti-fraud security on telecom business operators, banking and financial institutions, non-bank payment institutions, and internet service providers. These organizations are expected to establish internal risk prevention, controls, and security systems. The law will be applicable both within and outside Chinese territory, and overseas organizations or individuals who conduct telecom network fraud activities will be held accountable in accordance with the relevant provisions of this law.
The law stipulates that the Chinese foreign and public security ministries must work more closely with international law enforcement agencies to crack down on these crimes. The law empowers the police to impose travel restrictions on suspects who frequently visit hotspot countries and regions, particularly Southeast Asian countries, unless they can provide valid reasons for their travel to such areas. Ex-offenders may also be subject to travel bans for as long as 3 years after completing their jail sentences.
The Drive toward Big Data and Major Data Breaches
According to the definition by Gartner, big data is “high-volume, high-velocity, and/or high-variety information assets that demand cost-effective, innovative forms of information processing that enable enhanced insight, decision making, and process automation.”
According to The Brookings Institution, many arms of the Chinese government have been collecting huge volumes of data for surveillance purposes, which authorities refer to as “visualization” (可视化) and “police informatization” (警务信息化). China’s data-fusion programs allow its surveillance systems to assemble highly detailed information of its citizens. The Chinese government makes use of data-fusion tools to monitor, collect, and store information of individuals classified as “focus personnel”, which includes “individuals petitioning the government, those purportedly involved in terrorism”, and those deemed by the Chinese government to be “undermining social stability”. These data-fusion tools have also helped to build predictive policing systems in Xinjiang, Brookings notes, helping to “‘accurately depict’ terrorists’ ‘religious, organizational, and behavioral characteristics’”.
Excessive monitoring, collecting, and storing of sensitive information belonging to individuals is not illegal under Chinese law. Under Article 28 and 33 of the Personal Information Protection Law of the People’s Republic of China, the law allows for state organs, such as the Chinese police force, to handle sensitive information, and the scope and limits of what type of data the Chinese government can collect and/or store legally are up to the state organs to decide. The types of information involved include biometric identification, religious beliefs, PII, medical care, financial accounts, individual whereabouts, and other information, as well as the personal information of minors under the age of 14.
The development of the big data industry was also seen as a key aspect of the 14th Five-Year-Plan period [2021-2025] as China’s industrial economy moves toward a digital economy. The big data industry had an average compound annual growth rate of over 30% during the 13th Five-Year Plan period [2016-2020]. New requirements were proposed for the development of the big data industry to allow it to enter a new phase of integrated innovation, rapid development, in-depth applications, and structural optimization. The drive toward big data was further accelerated during the COVID-19 pandemic. However, security is unable to catch up with the rapid growth of data collection, as evidenced by some high-profile data breaches reported during the past year. Threat actors have managed to obtain large volumes of data that contain extremely sensitive information, and then analyzed and repackaged these data sets into smaller data sets that have been resold on both Chinese- and non-Chinese-language cybercriminal sources.
Data Breaches of Beijing and Shanghai Health Code Apps
Since the start of the COVID-19 pandemic, China has required its citizens to use an app on their smartphones that acts as an e-passport to dictate whether they should be allowed in public or be quarantined. The app was first heralded by the local government of Hangzhou with the help of Ant Financial, a sister company of the e-commerce giant Alibaba. The app generates a QR code in 1 of 3 colors: a green code enables its holder to move about unrestricted; a yellow code means the holder may be asked to stay home for 7 days; and a red code means a 2-week quarantine. An analysis of the app’s software code by the New York Times showed that in addition to determining in real-time whether someone poses a contagion risk, the app also shared the user’s information with the police, raising privacy concerns. According to Maya Wang, a China researcher from Human Rights Watch, “China has a record of using major events, including the 2008 Beijing Olympics and the 2010 World Expo in Shanghai, to introduce new monitoring tools that outlast their original purpose”. Maya Wang also added that “The coronavirus outbreak is proving to be one of those landmarks in the history of the spread of mass surveillance in China”.
In addition to privacy concerns, poor security in the databases associated with the health code apps had led to 2 well-publicized data breaches, described below.
On April 28, 2022, Wei Bin, an official from the Beijing municipal government, disclosed that Beijing Jiankangbao (北京健康宝), a mobile-based app used to check health codes and provide nucleic acid testing results during the COVID-19 pandemic, was allegedly attacked by overseas hackers. "The Beijing Jiankangbao was attacked on Thursday morning during its peak visiting period. The team of technicians fixed the problems swiftly", Wei said at a news conference, adding, "We later found out the source of the attack was from overseas". Wei claimed that the app was also attacked by overseas hackers during the 2022 Beijing Winter Olympics. To date, we have not seen data from the app being offered on dark web marketplaces or forums.
On August 10, 2022, “XJP”, a member of the mid-tier BreachForums, was selling data from 48.5 million unique users of 随身码 (Suishenma), the Shanghai equivalent of the Beijing health code that was compromised earlier this year. The Suishenma health code was developed by the Shanghai Big Data Center, an agency under the Shanghai Municipal Government, in early 2020 to help local authorities manage the COVID-19 outbreak. It became an essential digital tool in the daily lives of Shanghai residents, who were required to show a green code before being allowed to take public transport or to go into public venues. The threat actor XJP claimed the database contained everyone who lived in or visited Shanghai since the adoption of the Shuishenma app, and shared a screenshot of the data sample. The database was priced at $4,850, which was later reduced to $4,000. XJP uses Matrix (breach.co:XJP) as their primary method of contact. The post was listed as verified, and XJP authorized pompompurin, the administrator of BreachForums, to conduct the trade of this database on the threat actor’s behalf. While many comments to the post indicated interest in the database, most of them thought it was too expensive, even at the reduced price. It is interesting to note that the post used the Chinese characters 随伸码 (instead of the correct 随身码) to indicate the health code app, which suggested that XJP might not be a native Chinese speaker. On September 9, 2022, XJP also offered to sell data from China’s Border Exit and Entry Management Bureau that reportedly contained information on people who have crossed Chinese borders between July 2020 and July 2022. The threat actor stated that the database contains more than 240 million records, but that it may be incomplete and may not include data about diplomatic visits. The database was priced at $100,000. The credibility of XJP is moderate: the threat actor has authored 5 threads and 20 posts since registering their account in July 2022 and has a positive reputation score of 92, at the time of this report.
Figure 1: XJP selling QR health codes belonging to 48.5 million residents in Beijing, China (Source: BreachForums)
Shanghai Police Database Breach
On July 3, 2022, news reports emerged regarding a data leak of 23 TB of personal information from the Shanghai National Police on Chinese citizens, posted by the user “ChinaDan” on BreachForums. According to Radio Free Asia, the leaked database was most likely hosted by Alibaba Cloud. As reported by Reuters, Zhao Changpeng, CEO of Binance, said on July 4, 2022, that the cryptocurrency exchange had stepped up its user verification processes after the company's threat intelligence detected the sale of records belonging to “1 billion residents of an Asian country on the dark web”, mostly likely referring to the BreachForums posting by ChinaDan.
Recorded Future has obtained the sample data shared by ChinaDan, and can confirm that the data includes full names, home addresses, birthplaces, national ID Numbers, mobile numbers, and crime/case details that date from as far back as 1995 to as recent as 2019. Our preliminary assessment of the data sample indicates that the data appears to be authentic. However, given the purported size of the data package, it is impossible to ascertain whether the entire package is what it is advertised to be.
Figure 2: ChinaDan selling the Shanghai Police databases on BreachForums; the owner of BreachForums pompompurin has verified the database to be legitimate (Source: BreachForums)
Chinese Database Storing Millions of Faces; Vehicle License Plates Left Exposed Online
On August 30, 2022, TechCrunch reported that a Chinese database that stored millions of faces and vehicle license plates was left exposed on the internet for months before it quietly disappeared in August 2022. The database, which reportedly held over 800 million records at its peak, belonged to a tech company called Xinai Electronics based in Hangzhou. The company builds systems for controlling access for people and vehicles at workplaces, schools, construction sites, and parking garages. Xinai Electronics had amassed millions of face prints and license plates through its network of cameras all over China, and claimed its data was “securely stored” on its servers.
The exposed data on an Alibaba-hosted server in China was found by security researcher Anurag Sen, who asked TechCrunch for help in reporting the security lapse to Xinai. Sen reported that neither the database nor the hosted image files were protected by passwords and could be accessed from the web browser by anyone who knew where to look. After several emails by TechCrunch notifying Xinai about the exposed database without replies, the database became inaccessible by mid-August 2022.
While we did not identify any postings on cybercriminal markets that directly mention this database, advertisements for car-owner information are often found on Chinese-language dark web marketplaces. For example, we found this posting of detailed information about General Motors car owners in China. We cannot ascertain if the data offered here came from the exposed database mentioned above, as it is a common practice for Chinese threat actors to parse large leaked databases into smaller sizes based on certain attributes in order to monetize it more easily.
DDoS Attacks and Hacktivism Surrounding Pelosi’s Visit
On August 3, 2022, the United States (US) House of Representatives Speaker Nancy Pelosi visited Taiwan and met with Tsai Ing-wen, the president of Taiwan (Republic of China). Pelosi declared that the US “will not abandon our commitment to Taiwan” and Tsai said Taiwan would "never back down" in the face of threats. Throughout the day on August 2, 2022, and into August 3, 2022, China continued its strong warnings against Speaker Pelosi’s visit and took political, military, and economic actions aimed at punishing Taiwan and deterring further US support for Taiwan. On August 4, 2022, The Record by Recorded Future reported that Taiwan’s Ministry of National Defense said its network was taken offline by a distributed denial-of-service (DDoS) incident for about 2 hours following Speaker Pelosi’s visit to the island; the attack started shortly after Pelosi left the island. The Record article states that “Chinese government officials were furious about the visit — the first by a high-ranking US official in 25 years — arguing that it violated the country’s ‘one China’ policy”. In a statement, Taiwan’s Ministry of National Defense said the DDoS attacks began around 23:40 and ended around 00:30 (Taipei time). The ministry said it was working with other agencies and the president’s office to defend the government’s information security infrastructure. The attack came after several websites run by the government of Taiwan, including the Ministry of Foreign Affairs, as well as the Taoyuan International Airport, were disrupted ahead of Pelosi’s visit.
The attacks were large enough to make the websites inaccessible for brief periods, but were not particularly large in scale. ISC Sans and other cybersecurity organizations suggested the DDoS attacks were likely the work of nationalist hacktivists in China rather than China’s formal civilian or military cyber forces.
Despite the lack of evidence for any large-scale government-sponsored cyberattacks, John Hultquist of Mandiant still expected China’s cyber espionage “to kick into ‘overdrive’ as its government seeks to learn ‘what the US is thinking, what the limits of our resolve are’”, and stated that “‘the way you find answers to that are by reading emails of diplomats and military members and government leaders’”.
We did not find any direct mentions of DDoS attacks against Taiwan on the Chinese-language underground. However DDoS tools, tutorials, and services are often advertised on Chinese-language cybercriminal marketplaces. Anyone interested can easily acquire the tools and knowledge to pull off a small-scale attack.
Changes in the Dark Web Markets
Since our last report on the Chinese cybercrime landscape in 2021, there have been noticeable changes in the makeup of dark web marketplaces. Several of the marketplaces have gone offline, including Loulan City Market, Tea Horse Road Market, Ali Marketplace, and Dark Web Exchange. However, some of the accompanying Telegram channels for these marketplaces continue to operate. There could be a number of reasons for these dark web marketplaces going offline, which include but are not limited to law enforcement actions, exit scams, and internal disagreement between threat actors.
Marketplaces that are still operating at the time of this report include the Exchange Market, FreeCity Market, Alibaba Market, and United Chinese Escrow Market (UCEM). Meanwhile, 3 new dark web marketplaces have emerged and are still in operation at the time of this report: Dark Web Chinese Market, Tengu Market, and Chang’An Sleepless Night. Below are the descriptions of each of these 3 new marketplaces.
Dark Web Chinese Market
The earliest post on the Dark Web Chinese Market was from September 2021. Registration for the marketplace is free and listings are divided into the following categories:
- Paid Advertisement (no listings under this section at the time of this report)
- Data: Various stolen data including PII, carding material, and more
- Tutorials: Hacking techniques, social engineering, fraud schemes, and more
- Physical Items: Mostly sets of 4 IDs (standard for bank account access in China) for bank account access
- Videos: Mostly adult content
- Virtual Items: Carding tutorials, templates for counterfeit documents, and more
- Software Websites: Various legal and illegal software, SMS receiving services, and more
There were 700 items for sale at the time of this report, with postings listed in US dollars as well as Bitcoin (BTC). A for-sale posting has information including the number of items sold, the rating of the item, and the time the item was posted. The information of the seller is completely anonymized (no handle for the seller is provided) for the sake of privacy protection.
The transaction escrow period is 5 days, as any transaction is automatically confirmed after 5 days. If an extension is needed, a user needs to specify “stop automatic payment from the system” on the order form. If delivery is delayed for more than a day from the seller, the buyer can request a refund and note the reason. If there is a dispute in the transaction, each party has 3 days to address the request. The party that does not reply in 3 days will lose the arbitration automatically. Due to the anonymous nature of the website, no administrator is identified based on available information.
Figure 3: The landing page for Dark Web Chinese Market (Source: Dark Web Chinese Market)
Tengu Market
The earliest seller registration on Tengu Market was dated from March 2022. Registration for the marketplace is free and listings are divided into the following categories (verbatim):
- BTC-Related: coin mixing services, cryptocurrency wallets without lost passwords, password crackers for wallets, and more
- Databases: email addresses with passwords, US driver’s licenses, blackhat search engine optimization (SEO) tutorials, and more
- Physical Stuff: cell phone cards, counterfeit watches, and more
- Entertainment: various types of games and software
- Online-SMS: Google voice numbers and other SMS receiving services
- Geek-Tech: remote access trojans (RATs), hacking tools and tutorials, and more
- Mysterious: carding materials and other tutorials
- Gift Cards: PayPal account numbers and passwords
There were about 60 postings at the time of this report, with postings listed in US dollars even though BTC is the only type of currency accepted. A for-sale posting has information including the number of items sold and remaining, the rating of the item, as well as the seller’s handle and rating. Each seller’s page has ratings in the categories of quality, communication, and delivery. The website charges a 7% processing fee for each transaction. After an order is placed on an item listed, if no payment is received after 5 hours, the transaction is automatically canceled. The website also offers arbitration for any disputed transactions. In addition, the website appears to have an associated chat room and Telegram channel. There does not appear to be a website administrator; however, the chat room has a member with the handle “管理员”, which is the Chinese word for “administrator”.
Figure 4: The landing page for Tengu Market (Source: Tengu Market)
Chang’An Sleepless Night
The earliest post on Chang’An Sleepless Night was from December 2021. Registration for the marketplace is free and listings are divided into the following categories:
- Paid Advertisement: a few listings including a solicitation to buy shopping and gambling data
- Data: Various stolen data including PII, protected health information (PHI), loan and retail data, and more
- Videos: Adult content
- Technical Skills: Hacking techniques, social engineering, fraud schemes, and more
- Carding and CVV: Carding material and tutorials
- Physical Items: Sets of 4 IDs for bank account access (standard for access in China), drugs, and more
- Services: Hacking, money laundering, and other illicit services
- Private Transactions: Private transactions between registered users
- Virtual Items: Leaked databases, account credentials, templates for counterfeit documents, and more
- Others: Miscellaneous tutorials and frauds
There were more than 1,600 items for sale at the time of this report, with postings listed in US dollars and BTC. Some items are also listed in Tether (USDT) and Ethereum (ETH). A for-sale posting has information including the number of items sold, the number of views, the handle of the seller, and the last time the seller was online. The marketplace offers escrow service, and transactions outside the website are discouraged. If an item purchased is not sent 3 days after payment, or if there is a dispute after the transaction, if the seller does not respond after 3 days, the transaction can be suspended by the buyer while notifying the administrator. After verification by the administrator, the cost of the transaction will be refunded to the buyer and the item will be taken offline. A certain percentage of the transaction proceeds will be deducted as a processing fee for website maintenance. The official Telegram channel of the market is @cabyc and the administrator can be contacted anonymously using the messaging service on the website or via Telegram at @ganmao.
Figure 5: The landing page for Chang’An Sleepless Night (Source: Chang’An Sleepless Night)
Below are some observations on the new developments on Exchange Market since our last report.
Greater Competition from Chinese Threat Actors on Exchange Market
2022 proved to be a popular time for Chinese threat actors to compete against the well-known Chinese threat actor “302513”, who has a moderate credibility on the Exchange Market, having more than 100 posts on leaked data affecting international entities since the relaunch of Exchange Market in Q4 2019. 302513 has indicated in their listings that reports have already been lodged against more than a dozen sellers, and that these sellers are recycling and reselling the data they bought from 302513. 302513 claims that other database sellers simply created new listings and resold the databases on the Exchange Market platform.
We observed that Exchange Market does not have any rules that clamp down on individuals that repackage and resell the data sets found in the platform’s listings. The platform lacks a protection mechanism for sellers like 302513, which has been hurting the financial profits of long-time database sellers. Such an observation also shows that Exchange Market is slowly evolving to become a more recognized platform for Chinese-speaking threat actors to market their database listings. As time goes by, we expect that more financially motivated threat actors will join Exchange Market and sell databases involving multiple countries and industries.
Figure 6: Exchange Market seller 302513 complaining about other Chinese threat actors recycling 302513’s data and reselling it on Exchange Market; the threat actor has lodged reports against more than a dozen sellers (Source: Exchange Market)
Chinese-Language Telegram Channels Devoted to Cybercrime
As stated earlier, some Telegram channels accompanying dark web marketplaces continue to operate even after those marketplaces have gone offline. Meanwhile, there are many independent Chinese-language channels that engage in carding, fraud, leaked data, and other illicit activities. While some of these channels initially disallow advertising, over time many channels, especially ones associated with dark web marketplaces, appear to be overrun by advertisements. The tables below list some of the Telegram channels associated with dark web marketplaces as well as ones that operate independently. The nature of these publicly accessible channels are mostly self-explanatory from their names. Additional intelligence is listed in the notes section, if warranted.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/research/restrictive-laws-push-chinese-cybercrime-toward-novel-monetization-techniques