Xiaoqiying
Attribution profile
- Type
- Activist
- Location
- China
- Known incidents
- 7 incidents
- Sources
- 3 sources
- First seen
- 2023-01-17
- Last seen
- 2023-01-25
- Updated
- 2026-08-01 05:33
- Aliases
- 3 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Xiaoqiying is a self‑described Chinese hacking group that first appeared in public Telegram posts claiming responsibility for a series of cyberattacks against South Korean targets. No alternative names or aliases are mentioned in the source material. The group presents itself as openly anti‑South Korea and denies any connection to the Chinese government.
The actors state that they have compromised seventy‑nine websites belonging to academic organizations in South Korea and have threatened to release personal data allegedly taken from those sites. They also claim to have breached the National Taiwan University in April 2023, exfiltrating approximately twenty‑five gigabytes of data, and have warned that they intend to expand their activity to as many as two thousand South Korean government‑run websites. These statements indicate a motive focused on political signaling and the public disclosure of information rather than financial gain.
The group’s described tactics involve using Telegram to announce their operations and registering a domain in early January 2023 that resolved to a Cloudflare IP address associated with the APT36 threat cluster; the sources do not reference any specific malware families, exploit kits, or custom tools. Their reported actions consist of website defacement and data exfiltration, but no detailed technical procedures are provided in the available reports.
Regarding attribution, Xiaoqiying explicitly denies ties to any state sponsor, and the cited sources do not provide evidence linking the group to a Chinese governmental entity. The material notes that independent researchers have observed Chinese military‑linked actors targeting South Korean corporations and that Chinese criminal gangs have distributed Android banking trojans in the region, but no public assessment connects those observations to Xiaoqiying itself.
The only campaigns explicitly attributed to Xiaoqiying in the provided information are the alleged compromise of seventy‑nine academic‑sector websites during the 2023 Lunar New Year holiday, the claimed breach of National Taiwan University with a twenty‑five gigabyte data leak, and the public threat to broaden attacks to two thousand South Korean government sites. These are the specific operations referenced in the source material.
Incidents
Attributed incidents are available to members.
7 incidentsSources
Sources available to members: 3 sources.