Menu
Browse

Cyber Threat Actor: Zhengquan Zhang

Updated 2026-07-31 19:33
Actor Type Location Known Incidents
 Icon
Insider - Disgruntled
China
1 incident
Characteristics
Threat actor characteristics available to members
Profile

Zhengquan Zhang, also known by his full name Zhengquan Zhang, is an individual identified as a former IT engineer who worked for KCG Holdings, Inc., a Wall Street securities firm, with locations in New York and San Francisco. According to publicly available sources, he is of Chinese origin and was employed at the company from March 2010 until his arrest in April 2017. Zhang held positions ranging from a DevOps engineer to a supervisor overseeing other engineers, giving him privileged access to the firm’s source code repositories and Unix‑based network infrastructure. In March 2017 he installed malware on KCG’s servers to capture employee credentials and subsequently used those credentials to access and exfiltrate portions of the proprietary trading platform source code and associated trading algorithms. His activities were uncovered after a quantitative analyst detected anomalous remote access and reported the incident to the company’s security team, leading to the revocation of his access and an FBI investigation. Zhang admitted to the intrusions in an email to a former supervisor, stating that he feared job loss amid acquisition rumors and sought information about the company’s future plans.

The targeting demonstrated by Zhang was limited to the financial services sector, specifically a U.S.–based securities firm, indicating a regional focus on the United States. His strategic objective, as evidenced by the charges filed against him, was the theft of trade secrets, namely the source code and trading algorithms that constitute valuable intellectual property for the firm. The tactics, techniques, and procedures observed in this case include the deployment of credential‑harvesting malware on internal servers, the misuse of legitimate privileged accounts for lateral movement, and the rerouting of network traffic through backup proxy servers to evade detection by third‑party monitoring tools. No specific malware family or external tooling is named in the reporting, but the described behavior reflects an insider threat approach that leveraged existing access rather than relying on external phishing or exploit vectors.

Attribution to any state sponsor or criminal consortium is not present in the available information; Zhang acted as an individual employee without publicly linked affiliations. The incident involving KCG Holdings represents the sole publicly reported operation associated with him, notable for the combination of insider access, custom malware for credential capture, and proxy manipulation to conceal data exfiltration. The case resulted in federal charges of trade secret theft, highlighting the potential impact of privileged insider actions on corporate intellectual property security.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
1 source