Intrusion Truth Methods: How Can They Get It Right Again and Again?
Who are the mysterious hacker whisperers Intrusion Truth? What kinds of tradecraft have they used? What can cyber threat analysts learn from them?
In late March 2024 the United States Department of Justice (US DoJ) unsealed an indictment alleging that seven Chinese hackers operated as part of Advanced Persistent Threat (APT)31 group “in support of China’s Ministry of State Security’s transnational repression, economic espionage and foreign intelligence objectives.” At the same time, the US Department of the Treasury imposed sanctions on APT31-affiliated company Wuhan Xiaoruizhi Science and Technology Company (武汉晓睿智科技有限公司) (Wuhan XRZ) and on two of the seven hackers. Many of us who follow the whereabouts of Chinese threat actors had an aha moment; we recalled that Intrusion Truth, an anonymous group that hosts a blog unmasking the real identities of Chinese threat actors, identified some of those hackers and WuhanXRZ back in May 2023. Wow, Intrusion Truth was right (again)! Since its first post in April 2017, Intrusion Truth has revealed actors and companies associated with four Chinese APT groups…


