Researchers have linked Guangdong Chanming Technology Co., Ltd., a little-known Chinese cybersecurity vendor, to RedRelay, a covert relay network allegedly used by China-linked threat actors.
The findings connect company records, software artifacts, patent filings, and PLA procurement documents to a wider cyber-espionage ecosystem.
Guangdong Chanming maintains almost no visible public presence. The company has no obvious marketing site, public product catalog, or consumer-facing security portfolio.
However, its registered software copyrights and patents describe tools with capabilities more consistent with surveillance, anonymity, data collection, and offensive cyber operations than conventional enterprise security products.
Registered product names include an Internet Security Access System, Multi-Functional Security Proxy System, File Transfer Network System, Security Tunnel Net anti-traceability system, Network Equipment Vulnerability Testing Analysis System, Android Secret Extraction System, and Telegram Data Collection System.

Chinese Vendor Linked RedRelay
These descriptions suggest software designed to conceal traffic, route communications through intermediary systems, assess network weaknesses, and collect data from mobile devices and messaging platforms.
While such functions can have legitimate security-testing uses, their combination creates concern when viewed alongside military procurement activity.
Publicly available PLA procurement documents list Guangdong Chanming as a supplier of an “Anonymous Network System” to a military customer in Beijing’s Haidian District.
The company’s apparent lack of commercial marketing, paired with military contracts, raises the possibility that its products are developed for state-linked users rather than the general cybersecurity market.
Corporate filings identify Dai Zhoujun and Wang Huiping as shareholders of Guangdong Chanming. Researchers focused on Wang Huiping after identifying a phone number reportedly associated with breach data and the email address boywhp@126.com.

That email address was linked to a GitHub account that previously hosted Free Connect, or FCN, a software project. Although the original repository is no longer available, archived forks remain online.
The remaining code and references point to the domain xfconnect.com, which has also been associated with FCN-related binaries.
One file identified through malware analysis platforms reportedly resembles stn.exe, described as an STN Security Tunnel component.
Extracted strings from the STN sample reportedly contain direct references to FCN, suggesting a possible technical or development relationship between the two tools.
Researchers also identified an unusual Linux command repeatedly used in FCN builds to identify a default network interface:
cat /proc/net/route | awk '{print $1,$2}' | awk '/00000000/ {print $1}'
This command sequence became a key pivot point. Searches for the distinctive code pattern reportedly identified a file called bulbature, also tracked as WHIPWEAVE malware, wordpress said.
Threat researchers have linked WHIPWEAVE to RedRelay, also known as ORBWEAVER, a covert network infrastructure used to relay malicious traffic through compromised systems.
Such networks can obscure the true origin of operators, complicate attribution, and provide resilient access for long-running espionage operations.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.