Menu
Browse

Cyber Threat Actor: Xiaoqiying

Aliases: 3 aliases
Actor Type Location Known Incidents
 Icon
Activist
China
7 incidents
Profile

The threat actor is known by the aliases Xiaoqiying, Genesis Day and Teng Snake and is based in China. Researchers describe the group as a Chinese‑language hacktivist collective that is primarily motivated by patriotism toward China rather than financial gain. The actors have publicly denied any direct ties to the Chinese government, and no state sponsorship has been confirmed in open sources.

The group’s targeting has focused on academic and research institutions in South Korea, with additional claims of activity against organizations in Japan, Taiwan, the United States and Ukraine. Their stated objectives are ideological, aiming to demonstrate capability and promote a nationalist narrative, as evidenced by website defacements that proclaimed the “Korean Internet” had been “invaded.” While they have not pursued monetary profit, they have threatened to leak stolen data and have shared exfiltrated information on cybercriminal forums such as BreachForums and Ramp Forum.

Observed tactics include exploiting internet‑facing devices using publicly available penetration‑testing tools and proof‑of‑concept exploit code, followed by data exfiltration and website defacement. The actors have used Telegram channels for recruitment, announcements and the distribution of stolen data, later shifting to a clearnet website after the Telegram groups were shut down. They have also leaked data on underground forums and claimed partnerships with various cybercriminal entities, although these affiliations remain unverified.

Publicly reported operations include the January 2023 campaign that compromised dozens of South Korean academic sites, exfiltrating approximately 54 gigabytes of data and defacing multiple webpages. The group has also asserted responsibility for intrusions into Samsung’s internal employee platform and intranet in South Korea, and for compromising the National Taiwan University in April 2023, though the latter claim lacks independent verification. These incidents illustrate the actor’s pattern of ideologically driven, non‑financial attacks that rely on readily available tools and online communication platforms for coordination and publicity.

Incidents
Attributed incidents available to members
7 incidents
Sources
Sources available to members
3 sources