AI-Powered Analysis Exposes Massive 5,000-Domain Chinese Malware Operation
DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally. Active since June 2023, the network now comprises approximately 5,000 domains, with over 1,900 new domains…
DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally. Active since June 2023, the network now comprises approximately 5,000 domains, with over 1,900 new domains identified between May and November 2025.
Recent investigations reveal the network's shift from centralized infrastructure, primarily hosted on Alibaba Cloud Hong Kong, to a fragmented model utilizing domestic Chinese registrars and randomized domain naming patterns. This strategic move aims to enhance operational security and evade detection. Despite these efforts, analysts have identified recurring patterns in Service Oriented Architecture (SOA) emails, tracking IDs, and unique registrant names, linking the 1,900 new domains to the existing network. The infrastructure now spans five countries and employs eight unique registrars, compared to three registrars noted in early 2025.
To manage the extensive volume of malicious infrastructure, researchers deployed an experimental "agentic AI" system. This system features a two-layer architecture with an orchestration agent and specialized sub-agents for tasks such as code analysis and binary retrieval. The AI system processed over 1,900 malware delivery websites in the time usually required for 200 to 400 manual investigations.
In a bulk processing test, three AI agents analyzed 2,000 domains in approximately 10 hours, averaging 1 to 10 minutes per domain depending on complexity. The system effectively handled sites with anti-automation JavaScript and bot-detection mechanisms. AI agents identified malicious code, retrieved payloads, and generated YARA rules autonomously, altering the economics of defense against large-scale campaigns.
The malware cluster is specifically targeting Chinese-speaking demographics, using sophisticated spoofing of popular software to deliver trojans and credential stealers. Analysis of 2,393 recent domains shows a focus on communication tools and VPN services, likely to exploit users bypassing internet restrictions. Malware is often delivered via large files (100–250MB) to evade standard antivirus scanning.
Top Spoofed Application Categories (May–Nov 2025)
DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally.
Category Domain Count Share Key Spoofed Brands
Communication Tools 391 24.2% WhatsApp, WhatsApp Web
VPN Services 363 22.4% LetsVPN (Kuailian), Kuailian Variants
Productivity 229 14.2% Google Services, Youdao, WPS Office
Web Browsers 109 6.7% Google Chrome
Crypto & Finance 105 6.5% ImToken, AICoin
The persistence of this network, along with its shift toward domestic infrastructure and complex evasion techniques, indicates its evolution into a potential service platform where affiliates may introduce their own malware. However, the deployment of agentic AI suggests that defenders can now effectively counteract large-scale threat operations.
Based on reporting by GBHackers.
