Chinese-language underground markets expand across the dark web: report
Two new ransomware-as-a-service (RaaS) groups—KillSec and Funklocker—were linked to over 120 incidents.
Cybercrime in the Asia-Pacific and Japan (APJ) region has grown more aggressive, organised, and AI-driven, according to a report by CrowdStrike.
One of the most alarming trends is the persistence of Chinese-language underground markets such as Chang’an, FreeCity, and Huione Guarantee, which enable anonymous trade in stolen credentials, phishing kits, malware, and laundering services.
Despite repeated crackdowns, these platforms continue to operate across the clearnet, darknet, and encrypted messaging apps like Telegram.
Artificial intelligence is now a core tool in “Big Game Hunting” ransomware campaigns, where attackers target high-value organisations with precision and speed.
CrowdStrike observed a spike in AI-enhanced social engineering and automated malware tools, with India, Australia, and Japan among the hardest-hit countries.
Two new ransomware-as-a-service (RaaS) groups—KillSec and Funklocker—were linked to over 120 incidents, and 763 victims were named on leak sites. The most targeted sectors were manufacturing, technology, and financial services.
The report also uncovered a financial fraud operation in Japan, where Chinese-speaking actors hijacked Japanese trading accounts to run pump-and-dump schemes.
By inflating low-volume China-based stocks, the attackers manipulated markets using hijacked accounts and recycled phishing infrastructure. Stolen data was then sold on Chang’an, reinforcing the role of cross-platform criminal ecosystems.
Cybercrime services have become increasingly industrialised, with specialised providers supporting large-scale operations.
CDNCLOUD offered bulletproof hosting; Magical Cat provided phishing-as-a-service; and Graves International SMS enabled global spam campaigns. These providers helped scale phishing, malware distribution, and monetisation across APJ.
Likely Chinese-speaking threat actors are also deploying remote-access tools (RATs) including ChangemeRAT, ElseRAT, and WhiteFoxRAT.
These were spread via SEO poisoning, malvertising, and phishing emails disguised as purchase orders—mainly targeting Chinese- and Japanese-speaking users.