1. Executive summary
Intrusion Truth has identified Guangdong Chanming, a previously undisclosed Chinese IT company, as the likely developer of RedRelay (aka ORBWEAVER), an ORB proxy botnet used by nearly a dozen Chinese APT groups — including APT15 and Ke3chang — to obscure attack infrastructure origins. Attribution of Guangdong Chanming as the contractor and of Red Vulture as a consumer of the botnet is unconfirmed: neither entity has a MITRE ATT&CK profile, and the claims rest on a single source (Intrusion Truth). For EMEA financial services, the operational risk is that egress traffic to RedRelay/ORBWEAVER nodes may indicate an active or staging intrusion by a state-sponsored actor using shared proxy infrastructure.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The advisory describes threat-actor infrastructure and attribution, not an incident at a client or a specific ICT third-party provider relationship that would trigger a distinctive obligation under the articles in scope.
3. Technical analysis & attack chain
This item is a strategic threat-identification report, not a vulnerability or breach with a kill-chain. The following is what the source establishes about the operation.
How the proxy network works (from source facts)
- Guangdong Chanming, a Chinese IT company, allegedly developed RedRelay (aka ORBWEAVER), an ORB network — a proxy botnet designed to route attacker traffic through compromised or deployed relay nodes to hide the true origin of network activity.
- The botnet was built on top of Free Connect, a now-defunct Chinese VPN tool initially developed by one of Guangdong Chanming's employees.
- RedRelay is referenced internally and in procurement documents as "Anonymous Network System."
- The botnet was used by approximately a dozen Chinese APT groups, including APT15, Ke3chang (MITRE G0004 — confirmed), Vixen Panda, Playful Dragon, and Nylon Typhoon.
- Guangdong Chanming's alleged customers include the Chinese People's Liberation Army (PLA) and the Ministry of Public Security.
- Beyond RedRelay, the company has developed and patented additional tools referencing: tunneling capabilities, multi-functional proxy systems, network vulnerability testing, Android secrets extraction, Telegram data collection, and a file transfer network.
Attribution caveats
- Guangdong Chanming — no MITRE ATT&CK profile; attribution as a state cyber contractor is unconfirmed and single-sourced (Intrusion Truth). Verify before enforcement.
- Red Vulture — no MITRE ATT&CK profile; listed as a RedRelay consumer but attribution is unconfirmed.
- Ke3chang — MITRE G0004; confirmed ATT&CK profile exists.
- The broader claim that Chinese cyber capabilities have shifted to private contractor networks is an analytical assessment by the source, not a verifiable technical fact.
4. Mitigation & containment
P1 — Within 24 hours
- Query egress firewall, proxy, and DNS logs for any historical traffic associated with the term "Free Connect" VPN client or connections consistent with ORB/proxy botnet relay patterns. The source does not provide specific IPs, domains, or hashes, so pivot on behavioural anomalies: unexpected outbound connections from server estates to residential or non-corporate IP ranges, sustained tunneling traffic, and connections from endpoints that should not have VPN/proxy software installed.
- Review endpoint inventories for the presence of Free Connect or any legacy Chinese VPN clients; quarantine any discovered instances.
P2 — Within 72 hours
- Brief threat-hunting and SOC teams on the RedRelay/ORBWEAVER proxy botnet and the "Anonymous Network System" procurement label. If your organisation holds intelligence-sharing memberships (FS-ISAC, UK NCSC CISP), request any shared IOCs related to ORBWEAVER.
- Assess whether your organisation is in the target profile of the listed APT groups (APT15, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon). EMEA financial services with operations in or supply-chain links to the Asia-Pacific region are at elevated relevance.
P3 — Within 7 days
- Update threat-actor profiles and intelligence requirements to include Guangdong Chanming as a tracked contractor entity and RedRelay/ORBWEAVER as a tracked infrastructure set. Monitor for subsequent IOC disclosures from Intrusion Truth or follow-on vendor reports.
- Review egress filtering posture: enforce default-deny outbound from server VLANs, restrict direct internet egress from internal endpoints through enforced corporate proxies, and alert on any SOCKS/HTTP-tunnel traffic to non-sanctioned destinations.
5. Indicators of compromise
No indicators of compromise available in the source material. The source names the tool (RedRelay / ORBWEAVER), its internal label ("Anonymous Network System"), and its base technology (Free Connect VPN) but provides no atomic network indicators (IPs, domains, hashes, URLs).
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Outbound proxy/tunnel traffic consistent with ORB network relay nodes | Egress firewall, proxy logs, NetFlow | Medium — inferred from tool description, not from observed traffic |
| Presence of Free Connect VPN client on endpoints | EDR, endpoint inventory, installed-software reports | Medium — named in source as the botnet's base technology |
| Sustained outbound connections from servers to residential/non-corporate IP ranges | SIEM, NetFlow analytics | Low — generic ORB indicator, not specific to RedRelay |
6. Detection
Insufficient indicators to author detection rules. The source provides no file hashes, no C2 domains or IPs, no distinctive strings from binaries, no registry keys, no scheduled-task names, and no command-line artefacts. The tool names ("RedRelay," "ORBWEAVER," "Anonymous Network System," "Free Connect") are product labels and procurement references, not threat artefacts embedded in malicious files or traffic. Authoring YARA or Sigma rules from these labels would detect reporting about the threat, not the threat itself.
Threat actor context
Ke3chang · G0004 · aka APT15, Mirage, Vixen Panda, GREF, Playful Dragon
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
No MITRE ATT&CK profile for: Red Vulture, Guangdong Chanming.
7. Sources
- Risky Business / Risky Bulletin, "New Chinese cyber contractor identified," https://news.risky.biz/risky-bulletin-new-chinese-cyber-contractor-identified/, 2026-07-29
8. Adverse Trace position
This is a strategic threat-identification item, not an active-exploitation alert. The core claim — that Guangdong Chanming developed the RedRelay/ORBWEAVER proxy botnet used by multiple Chinese APT groups — is single-sourced (Intrusion Truth) and the company has no MITRE ATT&CK profile; treat the attribution as unconfirmed until corroborated. The operational takeaway for EMEA financial services is defensive: the proxy infrastructure is shared across nearly a dozen APT groups, meaning detection of egress to RedRelay nodes could indicate activity by any of them, including APT15 or Ke3chang, both of which have historically targeted financial-sector and government entities. We will monitor for follow-on reporting from Intrusion Truth and other vendors that may release atomic IOCs, and we will issue a supplemental advisory if actionable indicators emerge.
Published via PulseTrace — Adverse Trace threat intelligence.