Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Report Links Chinese Companies to Tools Used by State-Sponsored Hackers

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

SentinelLabs’ July 2025 investigation linked companies employing people indicted in the Hafnium—now commonly called Silk Typhoon—case to patents and products for digital forensics, surveillance and data collection. The evidence shows an ecosystem of Chinese contractors and state-security relationships. It does not prove that every patented capability was deployed in a known intrusion, or that every linked company was government-owned.

What the report actually established

SentinelLabs examined the July 2025 U.S. indictment of Xu Zewei and Zhang Yu, earlier indictments involving Yin Kecheng and Zhou Shuai, company registrations, leaked i-Soon materials, patent filings and public biographies. Its central finding was an association between indicted hackers, several Chinese companies and more than 10 patents covering highly intrusive forensic and data-collection capabilities.

The strongest defensible conclusion is that people tied to alleged Hafnium activity worked in a broader contracting ecosystem that developed tools consistent with offensive cyber operations and maintained relationships with Chinese state-security bodies. A patent establishes that an invention was claimed or registered. It does not, by itself, establish a customer, operational maturity or use in a particular breach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The people and companies in the evidence chain

Person Company or connection Documented or alleged link What remains uncertain
Xu Zewei Shanghai Powerock Network Company The DOJ says Xu participated in intrusions targeting COVID-19 research and Microsoft Exchange systems. SentinelLabs says he completed tasking at Powerock. He was arrested in Milan on July 3, 2025. His full operational role and the extent of Powerock’s involvement.
Zhang Yu Shanghai Firetech Information Science and Technology Company The indictment alleges that Zhang supervised and coordinated hacking under the direction of the Shanghai State Security Bureau (SSSB), an MSS regional office. He was described as at large in the DOJ’s July 8 announcement. The allegations have not been adjudicated, and the company’s complete role is not public.
Yin Wenji Shanghai Firetech SentinelLabs identifies Yin as Firetech’s founder or chief executive and links the company to patents for remote evidence collection, Apple forensics, router collection, decryption and mobile-device evidence. Whether each patented capability was deployed operationally.
Yin Kecheng iSoon and related companies Named in a March 2025 DOJ indictment concerning a long-running hacking conspiracy. How his alleged activity relates to the Xu-Zhang operations.
Zhou Shuai iSoon and Shanghai Heiying Information Technology Company The DOJ charged Zhou in the same broader set of cases; SentinelLabs uses the case to map a multi-company ecosystem. Which particular tools, customers or accesses he allegedly supplied.

These associations should not be flattened into a claim that all the companies were Chinese government fronts. SentinelLabs separately describes Wuhan Xiao Rui Zhi (Wuhan XRZ) as a front company established by the Hubei State Security Department. That is contextual evidence of one model, not proof that every company in the report had the same legal status.

What the patents and products were designed to do

SentinelLabs grouped the identified capabilities into several operationally important categories:

  • Endpoint and file acquisition: remote recovery of files from Apple computers, Apple-device evidence collection, FileVault-related collection and hard-drive decryption.
  • Mobile forensics: remote cellphone evidence collection and extraction of information from mobile devices.
  • Network and appliance collection: router evidence collection, traffic or information gathering from network devices, and reverse-engineering-related work.
  • Household and close-access surveillance: analysis of intelligent home appliances and remote control or analysis of household computer networks, capabilities that could support human-intelligence collection.
  • Training and support: cyber-range or “actual confrontation” training software and related services.

The practical implication is breadth. A contractor may possess a toolkit for endpoints, phones, routers and encrypted data even when public reporting identifies only one campaign. That latent capability is relevant to defenders, but it is not proof that every tool was weaponized.

Hafnium, Silk Typhoon and the naming problem

Hafnium was Microsoft’s designation for the China-linked activity publicly associated with the 2021 Microsoft Exchange Server attacks. Microsoft later changed the alias to Silk Typhoon, according to SentinelLabs. Other vendors may use different names for overlapping or partially overlapping activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A threat-actor label is normally a shorthand for observed infrastructure, malware, victimology and behavior. It is not necessarily the name of a legally established organization. The activity publicly associated with this cluster has included defense contractors, policy organizations, universities, infectious-disease and COVID-19 research groups, healthcare, legal, government and nongovernmental organizations.

What the Justice Department alleges

In a nine-count indictment, the DOJ alleges that Xu and Zhang conducted intrusions between February 2020 and June 2021 under the supervision and direction of SSSB officers. The allegations cover attacks on COVID-19 research and the Microsoft Exchange campaign. The DOJ says Xu reported successful intrusions and received further instructions from SSSB personnel.

The department also claimed that the campaign compromised thousands of computers worldwide and that more than 12,700 U.S. entities were victimized within a broader set of more than 60,000 targeted U.S. entities. Those are government allegations and attributed counts, not independently adjudicated incident-response totals. The defendants are presumed innocent unless proven guilty.

How ProxyLogon fits

SentinelLabs places Hafnium exploitation of the relevant Exchange flaws in January 2021. Security researcher Orange Tsai was publicly discussing a powerful pre-authentication remote-code-execution flaw around the same period. That timing prompted questions about how the attackers obtained or developed the exploit chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SentinelLabs raises the possibility that an MSS bureau acquired vulnerability research through an insider, close-access operation or another collection method and passed it to operators. That is an investigative hypothesis, not a proven chain of events. Microsoft warned in March 2021 that multiple malicious actors were exploiting the Exchange vulnerabilities after the initial activity became public; not every ProxyLogon incident should therefore be attributed to Hafnium.

China’s cyber-contracting ecosystem

SentinelLabs’ model is better understood as tiers than as one centrally branded organization:

  • State-directed operations: activity directly tasked by an MSS regional office.
  • Prime contractors: established firms developing tooling and conducting assigned operations.
  • Brokers and subcontractors: companies such as iSoon that sought government customers, brokered access or supplied capabilities.
  • Dual-use developers: firms whose products may be described as forensic or defensive while also being useful for collection.

These categories can overlap. A company can employ an operator, develop a capability and subcontract for more than one customer without every employee or product being part of the same campaign.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why conventional attribution can fail

Tracking only “Hafnium” or “Silk Typhoon” can hide the operational relationships underneath. The same company may support different MSS offices, sell a tool to multiple customers, or develop capabilities that never appear in public incident reporting. Conversely, an employee’s association with a company does not prove that the company’s entire product line was used in a specific intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For analysts and policymakers, the useful evidence map is:

individuals → companies → patents and capabilities → state-security relationships → observed campaigns → limits of attribution.

Defensive implications

  • Correlate infrastructure, malware, tooling, victimology and access methods across vendor labels rather than treating each APT name as a sealed compartment.
  • Prioritize internet-facing Exchange and network appliances, patching and configuration validation, and preserve evidence such as web shells, credentials, lateral-movement traces and post-compromise collection.
  • Include Apple endpoints, mobile devices, routers and encrypted data in threat models where those assets are material to the organization.
  • Validate commercial threat intelligence against primary indicators and incident-response evidence.
  • Use exposure management, endpoint telemetry, identity monitoring and retained forensic data together; no single product can establish attribution or replace incident response.

Allegation, finding and inference

DOJ allegation: Xu and Zhang conducted intrusions under SSSB direction.

SentinelLabs finding: Companies linked to the individuals held patents and developed capabilities with offensive potential.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SentinelLabs inference: Some capabilities may have supported other MSS offices or undisclosed campaigns.

Keeping those three levels separate is essential. The report materially strengthens the case for examining the companies and people behind threat-actor labels, while leaving deployment of particular patented tools—and the full chain behind ProxyLogon—unproven in public evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.