NetAskari Profile picture
May 19 13 tweets 7 min read Read on X
EXCLUSIVE: How the track foreigners in China - We got rare access to demo system developed by the Ministry of Public Security in China for the prefecture of Zhangjiakou, to track and surveil foreigners visiting or being residents ( actually it applies to most nationals as well, but in this case it seems to be aimed at foreigners ). It is officially known as "Dynamic control platform for overseas personnel". 1/12Image
The test-system is fed with real world data it seems. We confirmed with some individuals that the data in the system were theirs, including some data of our own. The system provides a wide range of functionality, not all implemented. 2/12 Image
In China, locals as well as foreigners have to be registered with local authorities. So your general whereabouts are known. If you are a traveler, usually this is done via your hotel. This is how it was for most of ht time in the past. Digital tools have streamlined this process, but also opened up a complete new possibility of real time tracking. Camera's with face detection can track your location in real time, going from one place in a town to another. 3/12Image
But the system also stores your travel data, like when riding a train. Your seat, carriage etc. is kept on record for later analysis. This information can be access in real time and, as we later see, will go into a general profile of you. 4/ Image
Image
The system differs between residents who stay in the region for work or study and temporary residents, like Tourists and other travelers. It stores most data of the residents, like passport data, visa data and cellphone numbers. Each resident will receive a detailed profile that can be inspected via a "quick view", including a "risk factor". 5/12Image
Image
But the system provides much more details on the individual. It should be mentioned that this don't seem to be specific target persons ( we come to that later ) but just every foreigner in a region X. That includes medical records, movement data, job and residential information, consumption of petrol (?), daily routines and "social interactions". 6/12Image
This "social interactions" are interesting as the system has a relationship model functionality that puts people into relationship on how often they appear on visual surveillance footage together. In the case of this "demo", they seemed to have taken people with Pakistani nationality as their test case mostly. 7/12Image
Image
It also has a pre-compiled database of "fugitives", "key personnel", ( euphemism for people under dedicated surveillance ) foreign students and foreign journalists. This seem to be used to run interference against to warn local administration and security organs that those "special" visitors have made it to the town/prefecture/sub-district. All the data of the journalists in this database used were legit, but focused only on the foreign journalists based in Beijing. 8/12Image
Image
A statistical functionality has been also integrated ( albeit a little bit basic ). In the spreadsheets apart from classical statistical numbers on general visitor numbers, there is a particular focus on citizens from "5 eyes countries". That tracks with the general suspicion in the Chinese security bodies, that nationally equals to "general suspicion". 9/Image
But do the information just come from official surveillance tech that the police operates ? No. It also gets its data input from cameras from a ski lift access system. As Zhangjiakou is a popular winter sport location, why not incorporate this data stream as well !? This hints that not just "official surveillance infrastructure" is contributing to the overall system, but that sensors from other, more private settings are incorporated too. A journalist who was detected while skiing, was flagged immediately. 10/12Image
A "bird's eye view" of the information is also available showing interconnection of different nationalities, how "travelers" are related to each other under "companion statistics". Plus general stats on violations, police cases etc. It should be mentioned again, this is a test demo and how much of it has been implemented in a functional way or have made it into real life scenarios, we don't know. 11/12Image
Image
If you want to get a proper deep dive come over here to read up on the PART 1 on the "Dynamic Control Platform for obsess personnel" ( PART 2 will be out soon too with more technical details of our investigation ). Judging by what we could find in the dashboard, the system was tested at around 2023 but some of the underlying data is from 2021. Although some minor changes were made on the UI this year, it seems by pretty much abandoned and has now been taken offline. - netaskari.substack.com/p/sharp-eyes-h… 12/12Image
And @sophia_yan wrote about it too as someone who was more or less directly "involved : telegraph.co.uk/world-news/202…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with NetAskari

NetAskari Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @NetAskari

Apr 21
Longxin Technology, one of the many players in China's expansive digital forensics eco system offers a new iteration of its "mobile phone evidence collection system" that aims for analyzing Telegram messages and Uyghur language content. 1/12 Image
Founded in 2017, Longxin has expanded quickly with over a dozen sub-bureaus across the country, lodging itself firmly into the world of over-regional service providers for Public Security Bureaus. 2/12 Image
One of their main products is the LX-line of multi-channel digital device mirroring and analytics systems. They come as stand-alone tools, mobile versions or full data-forensics laboratories. 3/12 Image
Read 12 tweets
Feb 15
After having a run through some of the sample files, here is what we know so far from the massive data leak that seems to be on sale ( or has ben already sold ) on Breach Forums. We did not have access to the full list of all the files ( would love to, but not cashing out 10 XMR ). 1/7Image
The data seems to be truly taken from the NSCC, the National Super Computer Centre in Tianjin. This is a government owned datacenter, designed to let SOE's and universities run complex data simulations, virtual test systems, scientific computation models etc. 2/7 Image
Image
Many of the documents are actually proprietary binaries for scientific software and hold test results, simulation setups. For us it is hard to identify how confidential or special they are. There seem to be no cyber security related topics as far as we can see, but it would have been slightly surprising for an institution like the NSCC to hold data on that. 3/7
Read 7 tweets
Feb 7
In June 2025 we found complete tender for a "cyberspace security training platform" issued by the Police Training college in Xinjiang, China.
The document is rather detailed about the requirements, services, size and technical aspects and capabilities of this project. Setup timeframe
was about 3 months, value 530k U$. Lets dive in via this long thread will be >PART 1< ... 1/10Image
Image
Starting with the institution: the Xinjiang Police Academy is the main undergraduate training and education facility for the Ministry of Public Security
in the region and has quietly become a powerhouse in the CN hackathon ecosystem as the following wins confirm:
* 2025 Pangu Stone Cup by Qi’anxin: 3rd place
* 2023 Pangu Stone Cup by Qi'anxin: 1st place
* 2022 “Blue Hat” Cup: 2nd prize
* 2021 National College Student Cyber Security Elite Competition: silver medal
They are also running their own CTF competition, called "Yijing Cup CTF Competition". 2/10Image
In its essence, the project is a complete digital teaching setup plus integrated "cyber shooting range" to conduct red/blue operations, data forensics, building elaborate training exercises and labs. The whole documen is 90 pages long, so we will just look at some selected topics. We will post the original excerpt plus a machine translation of it. 3/10Image
Image
Read 10 tweets
Feb 2
In 2024 we traveled to the Chinese city of Chengdu to find follow the trails of three APT groups: I-Soon, No Sugar Tech, Chengdu404 and Sichuan Silence. In this thread we will do some site visits, getting "thrown out" and talking to a former member of top management, all the while we are trailed by security. 1/10Image
Let's start with I-Soon: Gaining fame during a rather juicy leak of internal chats in 2024, that presented proof of their involvement in cyber attacks and information theft on behalf of regional Public Security Bureaus. After the story broke, the company got closed down and they abandoned their office. 2/10Image
Image
Chengdu was just one of their offices country wide, but by now the company seems defunct. In one chat they mentioned though that they acquired technology from a company named "No Sugar Tech", to get access to QQ accounts. 3/10 Image
Read 11 tweets
Jan 5
We got our hand on a Chinese DLP program the government and national security agencies use to monitor state employees computers for leakage and usage of confidential documents. Meet 保密管理系统. 1/9 Image
Designed mainly for WinXP and Win7, it lodges itself rather deep inside the system to have full file system access, controls hardware/USB devices, dynamic content analysis and enumeration, provides network traffic proxies and enables remote control and granular file behavior. 2/9 Image
It was build by the well known Chinese cyber security government SuperRed but relies heavily on open source technology to provide its core functionality. 3/9 Image
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(