China’s spies, invoiced

China, and espionage read from the paperwork

The cinematic account of Chinese hacking favours the long game and the silent professional. APT1, the group a 2013 Mandiant report tied to a People’s Liberation Army unit in Shanghai, and APT41 after it, arrive in the literature as advanced persistent threats: patient, sophisticated, dwelling undetected in a network for months. The register is one of admiration dressed as alarm, the adversary as a kind of dark craftsman.

From the paperwork rather than the intrusion, Chinese cyber activity looks less like a dark craft and more like procurement: a large, price-sensitive acquisition programme, staffed by underpaid contractors, buying and stealing technology against a published shopping list. The paperwork exists, unusually, because a great deal of it leaked at once.

Procurement explains one layer of the Chinese system well and others hardly at all. What it shows most clearly is a three-part arrangement, an industrial policy that supplies the shopping list, a security apparatus that supplies the customer, and a commercial technical market that supplies the labour.

A stylised procurement ledger reading the February 2024 i-Soon leak, drawn as the mundane paperwork behind the intrusion. Vendor: i-Soon, also known as Anxun, a Shanghai contractor. Billed to a provincial bureau of the Ministry of State Security. Line items with prices: access to one Vietnamese ministry, priced for resale, 55,000 dollars; lesser targets in bulk, many at far less, hundreds of dollars; one operator per month, complaints attached, around 1,000 dollars; access to a university, off the target list and resold later, with no order yet; and a six-figure sum i-Soon owed to Chengdu 404, the company behind APT41, in an unpaid contract dispute. A note records the staff as underpaid, competitive, and playing mahjong between intrusions. The paperwork is dull because the work is procurement.

Stealing off the shopping list

The tie between plan and theft shows most cleanly where a theft can be laid against a named plan priority. Commercial aviation is the standard case. China’s first large domestically built airliner, the COMAC C919, was a declared objective of the industrial programme, and over roughly 2010 to 2015 a cluster of operations tracked as Turbine Panda, run out of the Jiangsu bureau of the Ministry of State Security, worked through the Western firms supplying the aircraft’s engine and components. One of the officers involved, Xu Yanjun, was later lured to Belgium, extradited, and in 2021 convicted in a US court of economic espionage against GE Aviation, one of the few times an MSS officer has been tried in person. Analysts assessed that the campaign materially aided China’s indigenous engine programme, the domestically built CJ-1000AX showing marked similarities to the Western engines it was meant to replace. The counterfactual has not been measured, and the saving is an assessment rather than an outcome, but theft in and plan priority advanced is a coupling made legible because the shopping list was published in advance.

Semiconductors, advanced materials, aerospace, biotechnology and telecommunications recur across the wider record as both stated policy priorities and collection targets, which makes aviation the cleanest instance rather than the whole proof.

Breadth and patience, in this light, are not signatures of craft. They are what an acquisition programme looks like from outside. APT41, tied by US prosecutors to the company Chengdu 404, was charged in 2020 with intrusions against more than a hundred organisations across a long list of industries and countries, conducting state espionage and private profit-making at once. The dual character is the point: the same technical workforce moves between customers and revenue models, state collection one month and criminal profit the next. A threat-intelligence account put the usefulness plainly: intelligence services lean on actors like this because they are an expedient, cost-effective and deniable capability. Not a craftsman. A supplier.

APT41 shows a state-connected contractor workforce operating across state espionage and private crime, and the question it poses is how far into the commercial market the intelligence service extends.

A market with a customer

The substrate is not industrial policy alone, though industrial policy is the part that shows first. China has named, in successive economic plans, the sectors in which it intends to move from low-grade manufacturing to the technological frontier: aviation, semiconductors, biotech, advanced materials and the rest, gathered under headings such as Made in China 2025 and the strategic emerging industries of the thirteenth Five-Year Plan. That supplies the list of what to acquire. It does not, on its own, explain why the state built or tolerated a market of contractors able to supply intelligence against so broad a range of targets.

The fuller substrate is a state intelligence system that can buy capability from a domestic technical market. Where the earlier PLA model put hacking inside a uniformed military unit, much of the current activity runs through nominally private companies performing intrusion under the direction of provincial bureaus of the Ministry of State Security. The contractor model gives the state deniable access to a private technical workforce, and gives the workforce something to compete over. A 2017 National Intelligence Law supplies the legal backing, obliging organisations and citizens to support and cooperate with intelligence work. The law does not turn every Chinese technology company into an intelligence contractor, a common and lazy extrapolation, but it is the legal ground the commercial relationship sits on. The condition is the combination: a legal mechanism for compelling cooperation, and a market able to supply offensive technical capability.

That combination is what gives the case its shape: a commercial technical market brought inside the intelligence procurement system rather than run from within a uniformed military unit. Different customer, different boundary.

A price for everything

Calling it procurement invites a tidier picture than the evidence supports. The state can buy an intrusion against a named target. Contractors can build a capability the state may later purchase. A contractor can find access on its own initiative and offer it to a state customer afterwards. A firm can develop an offensive tool sold to government and criminal buyers alike. The i-Soon material seems to hold all of these at once, which is more interesting than a single clean chain.

The step that follows is the one that makes the system adaptive. The state does not have to specify every target if it has created a market in which access itself has exchange value. A contractor breaking into a body nobody ordered is not necessarily disobeying the procurement system. It is behaving entrepreneurially inside it, on the reasonable bet that the access will find a buyer.

What the market prices is not people but capabilities. The i-Soon documents show productisation: target access, credential harvesting, surveillance tooling, exploit capability, telecom interception, social-media monitoring, data extraction, each packaged and given a price. That makes procurement literal rather than metaphorical. The state is not buying hackers. It is buying capabilities, and capabilities are far easier to substitute between vendors than people are. It may be why the leak feels so mundane. Markets make extraordinary things ordinary by turning them into line items.

Mahjong between the intrusions

In February 2024 an anonymous upload to GitHub exposed the internal files of i-Soon, a Shanghai contractor also known as Anxun, and the trove holds contracts, target lists, product marketing, and years of employee chat logs. What it depicts is not a nest of dark craftsmen. It is a mediocre software firm. Staff complain about low pay, reportedly around a thousand dollars a month, and gamble over mahjong in the office. Targets carry prices: access to one Vietnamese ministry was put at around fifty-five thousand dollars, others at much less. The leak shows government targeting requirements driving a competitive marketplace of hackers-for-hire, bidding for low-value contracts against one another.

The clerical texture goes all the way down. In one exchange an employee is recorded breaking into a university that was not on the target list, the supervisor waving it off as an accident, because in this arrangement contractors proactively hunt for access that might sell later rather than only filling named orders. The marketplace even has internal accounts receivable: Chengdu 404, the company behind APT41, fell into a contract dispute with i-Soon over an unpaid six-figure sum. Vendors invoicing vendors.

The mahjong is not colour. It punctures the category. The Conti leak showed that a criminal organisation is, on the inside, an ordinary company; the i-Soon leak shows that an intelligence contractor is too. The register says advanced persistent threat. The chat log asks whether anyone has been paid. The people conducting state espionage are not an exotic caste of cyber-warrior. They can be poorly paid employees of a mediocre firm trying to make a revenue target.

The output, not the invoice

The i-Soon leak is a Rosetta Stone. For almost every other Chinese operation the record is different in kind: malware telemetry, victim reports, indictments, sanctions, threat-actor clustering, the occasional infrastructure discovery. What is normally missing is the invoice. The usual view is the output of an operation. i-Soon briefly exposed the market that produced some of them.

The contractor model does not rest on that one leak. An advisory led by Australia and co-sealed by Japan and others in 2024 placed the group known as APT40 in Haikou, on Hainan, receiving its tasking from the Ministry of State Security’s provincial department there. The commercial paperwork at i-Soon and the state-tasked group on Hainan are the same arrangement seen from two angles: intrusion run at arm’s length from the service that directs it.

Data and pre-positioning

The larger footprint is data. Chinese operations have taken personal, commercial and strategic datasets at scale: the 2015 breach of the US Office of Personnel Management exposed background-investigation records on more than twenty-one million people, China named by the US intelligence chief as the leading suspect, and later assessments describe sustained targeting of telecommunications providers, cloud infrastructure and government networks, including a campaign against telecom networks tracked as Salt Typhoon that took customer call records and the communications of people in government and politics. Identity records, travel histories, personnel files, telecoms metadata: datasets that can be recombined later. The commodity being bought is not always an answer. Sometimes it is a dataset from which answers can be manufactured afterwards.

Beside the activity tracked as Volt Typhoon, two acquisition models come apart. Allied agencies assess that Volt Typhoon is pre-positioning inside critical infrastructure rather than stealing anything, using living-off-the-land techniques hard to tell from legitimate administration, with the assessed purpose of holding access that could disrupt services in a future crisis. One model asks what China needs in order to catch up. The other asks what it would want to be able to interrupt. The first is industrial acquisition; the second is strategic pre-positioning. Espionage has stopped being a wide enough umbrella for the whole.

The same security substrate reaches wider still, into surveillance, influence and overseas pressure, and a 2014 ASPI report read Chinese cyber doctrine as three things at once: control of networks and data at home, espionage for the economy, and disruption aimed at an opponent’s military systems. The point is not that China also does influence. It is that a single state security apparatus can buy several different outputs from overlapping technical and commercial markets.

A directed diagram of effects for Chinese state cyber acquisition, read left to right along a spine and downward into two open branches, with no loop closing. Published industrial priorities drive state collection tasking, tasking builds a contractor market, the contractor market yields access and stolen data, and the stolen material lands as domestic industrial capability. Nothing returns from there to the priorities that set it in motion, so the chain does not close. Drawn in grey, meaning a sourced effect on a branch with no evidenced return: stockpiled data holdings, and access pre-positioned in critical infrastructure. An increase in published industrial priorities raises state collection tasking, by human intervention. An increase in state collection tasking raises contractor-market activity, by human intervention. An increase in contractor-market activity raises access and data obtained. An increase in access and data obtained raises domestic industrial capability, by human intervention. An increase in access and data obtained raises stockpiled data holdings, by human intervention. An increase in state collection tasking raises access pre-positioned in critical infrastructure, by human intervention.

Laid out as edges, the spine is what closes and the branches are what do not. Priorities, tasking, market, access, capability: each step is a deliberate one, human intervention most of the way down, and the value lands at industrial capability. The two grey branches, data stockpiled and access pre-positioned, are sourced but their return is not, which is why they hang open. China’s diagram is a spine that lands and two branches that wait, nothing looping back.

What the invoice does not show

The first open edge is the evidentiary base: the contractor market’s incentive structure became legible almost entirely through a single leak, and i-Soon reads as one richly documented sample rather than proof of the average firm. The second is intent behind non-prosecution. That the five men named in the APT41 indictment all remain at large in China is compatible with the deniability the contractor model provides, but it does not by itself establish that non-prosecution is a designed feature rather than the ordinary fact that they sit beyond Western reach.

The vocabulary of the advanced persistent threat personifies: it gives a procurement pipeline a codename, a nickname and a face on a wanted poster, and invites the picture of a singular adversary of great sophistication. The i-Soon paperwork de-personifies it back into what it structurally is, a competitive market of mediocre vendors under state patronage.

The operational signature is not sophistication, whatever the threat-intelligence register prefers to see. It is a supply chain: underpaid, competitive, occasionally litigious, tied at one end to a published industrial plan and at the other to a room of people playing mahjong between intrusions. China has not industrialised espionage by making espionage more sophisticated. It has industrialised the supply of espionage, turning offensive capability into a purchasable service. China has opened the state’s own capability outward, into a procurement market of vendors, contracts and competing suppliers. The paperwork is not the secret command structure behind every intrusion. It is the more mundane and more consequential fact: intelligence collection has become something a state can buy.