Jun 24 2008
Russian hackers working inside China…
Another great post over at Dancho’s on who is behind the GPcode Ransomware. Probably just an available proxy in Liaoning but worth keeping an eye to see if these groups eventually start working together:
The John Dow-ish Daniel Robertson is emailing from 58.38.8.211 (Liaoning Province Network China Network Communications Group Corporation No.156,Fu-Xing-Men-Nei Street, Beijing 100031), and Paul Dyke from 221.201.2.227(Liaoning Province Network China Network Communications Group Corporation No.156,Fu-Xing-Men-Nei Street, Beijing 100031), both Chinese IPs, despite that these campaigners are Russians.
Of course read the rest of this article but check out his other posts…fantastic!