CSIDB logo
Threat actor

Xiaoqiying

Attribution profile

Type
Activist
Location
China
Known incidents
7 incidents
Sources
3 sources
First seen
2023-01-17
Last seen
2023-01-25
Updated
2026-08-01 05:33
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Xiaoqiying is a self‑described Chinese hacking group that first appeared in public Telegram posts claiming responsibility for a series of cyberattacks against South Korean targets. No alternative names or aliases are mentioned in the source material. The group presents itself as openly anti‑South Korea and denies any connection to the Chinese government.

The actors state that they have compromised seventy‑nine websites belonging to academic organizations in South Korea and have threatened to release personal data allegedly taken from those sites. They also claim to have breached the National Taiwan University in April 2023, exfiltrating approximately twenty‑five gigabytes of data, and have warned that they intend to expand their activity to as many as two thousand South Korean government‑run websites. These statements indicate a motive focused on political signaling and the public disclosure of information rather than financial gain.

The group’s described tactics involve using Telegram to announce their operations and registering a domain in early January 2023 that resolved to a Cloudflare IP address associated with the APT36 threat cluster; the sources do not reference any specific malware families, exploit kits, or custom tools. Their reported actions consist of website defacement and data exfiltration, but no detailed technical procedures are provided in the available reports.

Regarding attribution, Xiaoqiying explicitly denies ties to any state sponsor, and the cited sources do not provide evidence linking the group to a Chinese governmental entity. The material notes that independent researchers have observed Chinese military‑linked actors targeting South Korean corporations and that Chinese criminal gangs have distributed Android banking trojans in the region, but no public assessment connects those observations to Xiaoqiying itself.

The only campaigns explicitly attributed to Xiaoqiying in the provided information are the alleged compromise of seventy‑nine academic‑sector websites during the 2023 Lunar New Year holiday, the claimed breach of National Taiwan University with a twenty‑five gigabyte data leak, and the public threat to broaden attacks to two thousand South Korean government sites. These are the specific operations referenced in the source material.

Incidents

Attributed incidents are available to members.

7 incidents

Sources

Sources available to members: 3 sources.

CSIDB