{"id":72011,"date":"2025-10-22T16:43:39","date_gmt":"2025-10-22T08:43:39","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=72011"},"modified":"2025-10-22T16:44:07","modified_gmt":"2025-10-22T08:44:07","slug":"chinese-underground-marketplaces-drive-billions-in-illicit-transactions-ai-accelerated-ransomware-surges","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/10\/22\/chinese-underground-marketplaces-drive-billions-in-illicit-transactions-ai-accelerated-ransomware-surges\/","title":{"rendered":"Chinese underground marketplaces drive billions in illicit transactions; AI-accelerated ransomware surges"},"content":{"rendered":"<div><strong><u><a id=\"m_-5892694995811172712OWAf3b54b60-110f-8ac7-4b3e-13aa1b45ac0c\" href=\"https:\/\/www.crowdstrike.com\/en-us\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.crowdstrike.com\/en-us\/&amp;source=gmail&amp;ust=1761176796195000&amp;usg=AOvVaw1mo-PVJqM_qLiLLExfM4DB\">CrowdStrike<\/a><\/u> released the\u00a0<u><a id=\"m_-5892694995811172712OWA7e9fa238-522b-2042-4ff1-26eb639d89b8\" href=\"https:\/\/www.crowdstrike.com\/en-us\/resources\/reports\/2025-apj-ecrime-landscape-report\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.crowdstrike.com\/en-us\/resources\/reports\/2025-apj-ecrime-landscape-report\/&amp;source=gmail&amp;ust=1761176796195000&amp;usg=AOvVaw3YWBcCWA23my5JWYtF5b1B\">2025 APJ eCrime Landscape Report<\/a><\/u>, exposing a thriving Chinese-language underground ecosystem and the rise of AI-enhanced ransomware operations.<\/strong><\/div>\n<div><\/div>\n<div>Despite the Chinese government\u2019s internet restrictions and eCrime crackdown, anonymized marketplaces remain central to cybercrime activity across Asia Pacific and Japan (APJ). This ecosystem provides a safe haven for Chinese-speaking actors to buy and sell stolen credentials, phishing kits, malware, and money-laundering services \u2013 processing billions in illicit transactions.<\/div>\n<div><\/div>\n<div>At the same time, AI is transforming the ransomware economy. From AI-enhanced social engineering to automated malware development, AI is accelerating every stage of the attack chain \u2013 representing a new wave of adversaries executing Big Game Hunting campaigns against high-value organizations across APJ.<\/div>\n<div><\/div>\n<div>Based on frontline intelligence from CrowdStrike\u2019s elite threat hunters and intelligence analysts tracking more than 265 named adversaries, the report revealed:<\/div>\n<ul>\n<li>\n<div role=\"presentation\">Chinese eCrime Marketplaces Evade Oversight:\u00a0Amid tightened restrictions, Chinese underground markets \u2014 including Chang\u2019an, FreeCity, and Huione Guarantee \u2014 preserve anonymity across clearnet, darknet, and Telegram channels. This decentralized ecosystem remains a hub for Chinese-speaking actors focused on operational security (OPSEC), with Huione Guarantee alone processing an estimated $27 billion USD before its 2025 disruption.<\/div>\n<\/li>\n<li>\n<div role=\"presentation\">AI Escalates Big Game Hunting Ransomware Campaigns:\u00a0AI-accelerated ransomware on high-value targets surged, with India, Australia, and Japan among the most impacted countries. Emerging Ransomware-as-a-Service providers\u00a0<i>KillSec<\/i>\u00a0and\u00a0<i>Funklocker<\/i>\u00a0\u2013 leveraging AI-developed malware \u2013 accounted for more than 120 incidents. Top targeted sectors included manufacturing, technology, and financial services, with 763 victims publicly named on dedicated leak sites.<\/div>\n<\/li>\n<li>\n<div role=\"presentation\">Chinese-Speaking Actors Exploit Japanese Trading Accounts:\u00a0Coordinated account takeover (ATO) campaigns targeting Japanese securities platforms compromised users to artificially inflate the value of thinly traded China-based stocks. This pump-and-dump scheme, traced to Chinese-speaking threat actors, used shared phishing infrastructure to sell victim data on underground forums, including Chang\u2019an Marketplace.<\/div>\n<\/li>\n<li>\n<div role=\"presentation\">eCrime Service Providers Industrialize Attacks: Providers such as CDNCLOUD (Bulletproof Hosting),\u00a0<i>Magical Cat\u00a0<\/i>(Phishing-as-a-Service), and Graves International SMS (Global Spam Service) enabled scalable phishing, malware distribution, and monetization operations throughout the region.<\/div>\n<\/li>\n<li>\n<div role=\"presentation\">Remote Access Tools Target Regional Users: Likely Chinese-speaking eCrime actors deployed tools like\u00a0<i>ChangemeRAT<\/i>,\u00a0<i>ElseRAT<\/i>, and\u00a0<i>WhiteFoxRAT<\/i>\u00a0to exploit Chinese- and Japanese-speaking users through SEO poisoning, malvertising, and phishing attacks masquerading as purchase orders.<\/div>\n<\/li>\n<\/ul>\n<div>\u201ceCrime actors are industrializing cybercrime across APJ through thriving underground markets and complex ransomware operations. Simultaneously, AI-developed malware enables adversaries to launch high-velocity, high-volume attacks,\u201d said Adam Meyers, head of counter adversary operations at CrowdStrike. \u201cDefenders must meet this new pace of attack with decisive action, powered by AI, informed by human experience, and unified in response.\u201d<\/div>\n<div><\/div>\n<div>Download the\u00a0<u><a id=\"m_-5892694995811172712OWAc08a044a-2589-3f40-75a0-330ded3ac67a\" href=\"https:\/\/www.crowdstrike.com\/en-us\/resources\/reports\/2025-apj-ecrime-landscape-report\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/www.crowdstrike.com\/en-us\/resources\/reports\/2025-apj-ecrime-landscape-report\/&amp;source=gmail&amp;ust=1761176796195000&amp;usg=AOvVaw3YWBcCWA23my5JWYtF5b1B\">2025 APJ eCrime Landscape Report<\/a><\/u>\u00a0to explore in-depth insights, adversary profiles, and expert strategies for defending against APJ\u2019s evolving cyber threats.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Despite the Chinese government\u2019s internet restrictions and eCrime crackdown, anonymized marketplaces remain central to cybercrime activity across Asia Pacific and Japan (APJ).<\/p>\n","protected":false},"author":6,"featured_media":59262,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[7574,1481,54],"class_list":["post-72011","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-crowdstrike","tag-cybersecurity","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=72011"}],"version-history":[{"count":2,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72011\/revisions"}],"predecessor-version":[{"id":72013,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72011\/revisions\/72013"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/59262"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=72011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=72011"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=72011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}