Dear Diary, Today I found a Ghost in the Network
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

A hidden seller
Guangdong Chanming. If you were looking for them, you’d be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. It made us wonder what their marketing team spends their days doing – if they even have one.
On the surface, they are a ghost. But for those of us that know how to look for the cracks in the Great Firewall, the breadcrumbs they leave behind are more than enough to suggest that this “ghost” is actually a vital gear in China’s cyber machinery.
While they may lack a marketing strategy, their patent filings and software copyrights speak volumes. And they don’t speak of consumer products — they speak of offence. A few of the registered titles alone would raise the eyebrows of any security professional:
• 互联网安全接入系统 – Internet Security Access System
• 多功能安全代理系统 – Multi functional Security Proxy System
• 文件传输密网系统 – File Transfer Network System (FTN)
• Security Tunnel Net防溯源密网系统 – Anti traceability Network System (STN)
• 网络设备脆弱性测试分析系统 – Network Vulnerability Testing System
• Android终端秘取平台 – Android Secret Extraction System
• Telegram数据采集落查系统 – Telegram Data Collection System
‘Android Secret Extraction System’? ‘Telegram Data Collection System’? Subtle, Guangdong Chanming. Very subtle.
We scoured the web for a sales page, a demo, or even a single product listing. Nothing. These interesting tools Guangdong Chanming seem to offer clearly aren’t sold to the everyday consumer. However, we did find something far more interesting: a series of PLA procurement contracts naming them as the supplier. The implication is clear – they don’t sell to the public; they sell directly to the state.
A not so hidden developer
So how does a ‘ghost’ company leave a footprint? Simple: they employ people who are much clumsier. Enter Wang Huiping.
We started our investigation by going straight to the corporate filings. Guangdong Chanming lists two shareholders: Dai Zhoujun (代兆军) and Wang Huiping (王慧平). With a bit of digging, we were able to find phone numbers for each of them: 13927279060 and 13760865234 respectively. By pulling the thread of the number attached to Wang it didn’t take long to hit a breakthrough — the number appears in multiple data breach dumps, repeatedly paired with the email address boywhp[at]126.com.
This email address is a key that unlocks a piece of the puzzle: a software tool known as FCN (Free Connect). FCN once lived on GitHub under the handle boywhp. The repository has since been wiped, but traces can still be found in various forks, pointing us toward the domain xfconnect.com. A VirusTotal search on that domain revealed multiple FCN binaries, one of which bears a striking similarity to a file named stn.exe — described as the “STN Security Tunnel.” The strings extracted from the STN file even make direct references to FCN.
Coincidence? Or just another example of China’s cyber industrial complex at work? If it is a coincidence, Wang might want to consider filing a copyright complaint.
boywhp + WHIPWEAVE = whiplash
As we dug deeper, we noticed that almost every Linux build of FCN employs a highly unusual command to identify an interface name.
cat /proc/net/route | awk '{print $1,$2}' | awk '/00000000/ {print $1}'
</div>
</div>
We searched for this specific digital signature, and it led us straight to a file known as bulbature — also known in the wild as the WHIPWEAVE malware. WHIPWEAVE is a core component of the RedRelay covert network (also known as ORBWEAVER), a tool used by several known Chinese cyber actors.
The overlap isn’t just coincidental; it is systemic. Two of Guangdong Chanming’s patents describe a multi-hop, anonymizing traffic flow that aligns with what we know about RedRelay. We’re not the first to spot the link either. A handful of security outlets have already tied bulbature/WHIPWEAVE to the Chinese VPN tool Free Connect (FCN).
Either the FCN’s unusual commands coincidentally match those of a covert‑network malware which matches patent descriptions that name the FCN developer. Or FCN is a variant of the malware and the patents are an attempt to legitimise it.
Despite the attempts to hide, we are starting to see a clearer picture: FCN, a solo project by Wang Huiping, morphing into Guangdong Chanming’s STN product, sold to Chinese hackers who found the company despite their approach to marketing.
A (Red)Relay from Haidian to Guangdong
If RedRelay is indeed the product being sold, then the APTs using it should align with the company’s customers. This steered our investigation and led to us uncovering a customer roster that included the likes of the PLA and the Ministry of Public Security. We already saw evidence of this in procurement listings, where Guangdong Chanming provided an “Anonymous Network System” (presumably RedRelay) to a military unit in Beijing’s Haidian District.
Haidian is home to many, but none more significant than the PLA Cyberspace Force — the very branch responsible for China’s military cyber operations. Because of this, we decided to focus on customers that we could connect to Haidian and the CSF. We then looked at RedRelay users to see which APTs they could possibly be connected to. Here we ran into an APT that seems to have many different names: Red Vulture, APT15, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon, and many others. Now we are able to add two more aliases to the list: Unit 61046 and CSF 8th Bureau. This military unit has been utilizing Guangdong Chanming’s RedRelay network to conduct cyber campaigns that span the globe.
The dots are connected. Our next article will show you exactly how.
Article Link: Dear Diary, Today I found a Ghost in the Network – Intrusion Truth