The banality on the invoice¶
China, and espionage read from the paperwork
The cinematic account of Chinese hacking favours the long game and the silent professional. APT1, the group a 2013 Mandiant report tied to a People’s Liberation Army unit in Shanghai, and APT41 after it, arrive in the literature as advanced persistent threats: patient, sophisticated, dwelling undetected in a network for months. The register is one of admiration dressed as alarm, the adversary as a kind of dark craftsman.
Read from the paperwork rather than the intrusion, Chinese cyber activity looks less like a dark craft and more like procurement: a large, price-sensitive acquisition programme, staffed by underpaid contractors, buying and stealing technology against a published shopping list. The paperwork exists, unusually, because a great deal of it leaked at once.
Procurement at economy scale¶
The substrate here is industrial policy. China has named, in successive economic plans, the sectors in which it intends to move from low-grade manufacturing to the technological frontier: aviation, semiconductors, biotech, advanced materials and the rest, gathered under headings such as Made in China 2025 and the strategic emerging industries of the thirteenth Five-Year Plan. Cyber operations mapped to those headings are not an intelligence sideline. They are one instrument of an acquisition programme running at the scale of an economy.
The organisational form follows from that. Where the earlier PLA model put hacking inside a uniformed military unit, much of the current activity runs through a market: nominally private companies performing intrusion under the direction of provincial bureaus of the Ministry of State Security. The contractor model gives the state deniable access to a private technical workforce, and it gives the workforce something to compete over. What looks from outside like a shadowy apparatus is, structurally, a procurement chain with vendors, contracts and unit prices.
The coupling: theft that maps to the plan¶
The coupling shows most cleanly where a theft can be laid against a named plan priority. Commercial aviation is the standard case. China’s first domestically built airliner, the COMAC C919, was a declared objective of the industrial programme, and over roughly 2010 to 2015 a cluster of operations tracked as Turbine Panda, run out of the Jiangsu bureau of the MSS, worked through the Western firms supplying the aircraft’s engine and components. One of the officers involved, Xu Yanjun, was later lured to Belgium, extradited, and in 2021 convicted in a US court of economic espionage against GE Aviation, one of the few times an MSS officer has been tried in person. Analysts assessing the campaign concluded the stolen material likely trimmed several years, and potentially billions of dollars, off the development time of a jet the plan had called for. Theft in, plan priority advanced: the coupling is legible because the shopping list was published in advance.
Breadth and patience, in this light, are not signatures of craft. They are what an acquisition programme looks like from outside. The dual-mandate group APT41, tied by US prosecutors to the front company Chengdu 404, was charged in 2020 with intrusions against more than a hundred organisations across a long list of industries and countries, conducting state espionage and private profit-making at the same time. A threat-intelligence account of the group put its usefulness to the state plainly: intelligence services lean on actors like this because they are an expedient, cost-effective and deniable capability. Not a craftsman. A supplier.
The paperwork itself¶
In February 2024 an anonymous upload to GitHub exposed the internal files of i-Soon, a Shanghai contractor also known as Anxun, and the trove holds contracts, target lists, product marketing, and years of employee chat logs. What it depicts is not a nest of dark craftsmen. It is a mediocre software firm. Staff complain about low pay, reportedly around a thousand dollars a month, and gamble over mahjong in the office. Targets carry prices: access to one Vietnamese ministry appears to have been valued at around fifty-five thousand dollars, others at much less. The leak shows government targeting requirements driving a competitive marketplace of hackers-for-hire, bidding for low-value contracts against one another.
The clerical texture goes all the way down. In one exchange an employee is recorded breaking into a university that was not on the target list, the supervisor waving it off as an accident, because in this arrangement contractors proactively hunt for access that might sell later rather than only filling named orders. The marketplace even has internal accounts receivable: Chengdu 404, the company behind APT41, fell into a contract dispute with i-Soon over an unpaid six-figure sum. Vendors invoicing vendors. The operations are dull on the page because the substrate producing them is procurement, and procurement is dull by design.
Where the tidy version breaks¶
Two complications cut against the neatest version of the procurement story.
The first is that the marketplace is not a dirigiste blueprint executed from the top. The i-Soon files show targets chosen speculatively for their resale value, victim sets that sit awkwardly against any single intelligence objective, and freelancers scrambling for whatever access might find a buyer. That is a bottom-up scramble the state harvests, not a plan handed down and carried out to the letter. The aviation case, where theft lines up against a named priority, is the clean end of a spectrum whose other end is closer to a bazaar. The procurement is real, but messier, more entrepreneurial and less centrally directed than the phrase implies.
The second is that the signature itself has begun to shift. The activity now tracked as Volt Typhoon does not fit the acquisition programme at all: US and allied agencies assess that it is pre-positioning inside critical infrastructure rather than stealing anything, its target choice deliberately inconsistent with espionage, its purpose to hold access that could disrupt services in a future crisis. That is contingency planning for conflict, a different substrate from industrial policy. Procurement runs through a large and long-running part of Chinese cyber activity, not the newer turn.
What stays open¶
The edge that closes best is the aviation one, where a theft can be set against a published objective and the return traced. The edge that stays open is the contractor market’s incentive structure, which became legible almost entirely through a single leak. One disgruntled upload is a narrow evidentiary base for a general claim about how the whole ecosystem is paid and motivated, and i-Soon reads as one richly documented sample rather than proof of the average firm.
The naming of these actors runs the opposite way to the Russian case. The vocabulary of the advanced persistent threat personifies: it gives a procurement pipeline a codename, a nickname and a face on a wanted poster, and invites the reader to picture a singular adversary of great sophistication. The i-Soon paperwork de-personifies it back into what it structurally is, a competitive market of mediocre vendors under state patronage. That the five men named in the APT41 indictment all remain at large in China is not a failure of enforcement. It is the contractor model working as intended: the deniability the state buys by keeping the operators nominally private is the same deniability that keeps them beyond reach.
What survives is a single deflation. The operational signature is not sophistication, whatever the threat-intelligence register prefers to see. It is a supply chain: underpaid, competitive, occasionally litigious, tied at one end to a published industrial plan and at the other to a room of people playing mahjong between intrusions. The dark craftsman was always an artefact of watching the operation instead of reading the invoice.