CCP Unmasked
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
CCP Unmasked is the alias used by a hacking group that claims to be based in China. The group first came to public attention in August 2020 when it alleged that it had breached three Chinese social media monitoring firms—Knowlesys, Yunrun Big Data Service, and OneSight—and leaked internal documents totaling approximately forty gigabytes. The leaked material included presentations, word files, and other internal communications that the group said revealed the companies’ work on surveillance and disinformation platforms for government and security clients. According to the group’s own statements and the reporting that followed, the hackers said their goal was to expose what they described as the Chinese Communist Party’s attempts to undermine democracy and freedom of expression through online monitoring and fake news operations. They specifically referenced the firms’ advertised capabilities to monitor foreign social media platforms such as Facebook and Twitter, which are blocked within China, and to track opposition parties, terrorists, and public opinion across various online forums.
The group’s tactics, as described in the available sources, consisted of gaining unauthorized access to the target companies’ networks, exfiltrating documents, and then publishing selected files on their Twitter account @CCP_Unmasked before the account was suspended under the platform’s hacked‑materials policy. No specific malware families, initial‑access vectors, or tooling styles are mentioned in the provided information, so no technical details about their methods can be confirmed. Public attribution or affiliations with a state sponsor, criminal consortium, or other threat‑actor network have not been established; the actors identify themselves solely as individuals seeking to challenge perceived government interference. The most notable operation attributed to CCP Unmasked remains the August 2020 leak of the alleged internal files from Knowlesys, Yunrun, and OneSight, which included a highly confidential presentation detailing the Intelligence Center product, its claimed eight‑year collaboration with intelligence agencies, and its ability to monitor websites and social media services for anti‑government activity. This incident prompted reputational scrutiny of the named firms and led to the removal of the group’s Twitter account for violating the platform’s policy on sharing hacked content.
Incidents
Attributed incidents are available to members.
3 incidents