Blog

OSINT ON CHINA BLOG, DARK WEB, TOOLS, INSIGHTS, METHODS AND RESOURCES.

Members only

Get the full investigations

Our complete articles — methods, sources, and redacted case studies — are sent by email to verified members. Enter your corporate email to request access.

Corporate email addresses only. Free personal domains (Gmail, Outlook, etc.) are not accepted. Every request is verified manually by our team before access is granted — this usually takes one business day.
2:56
July 28, 2026

New China OSINT Video Lessons: July–August 2026

Anyone can tell you which Chinese platforms matter. Almost nobody will show you an analyst sitting in front of one and working it — the pivot, the wrong turn, the field everyone else scrolls straight past. New lessons land through August, and a couple of minutes of one is already up.

Watch
July 28, 2026

No Friends Required: Reading Maimai User's Phone Number Without Connecting

You lock your contact details to friends, read it as a wall, and never think about it again. The gap between what feels private on these platforms and what actually stays private is wider than almost anyone on them realizes.

Read post
July 27, 2026

The Location RedNote Shows You Is a Lie

The platform prints an IP location on every profile. It says Vietnam. The feed is wall-to-wall Chinese military parades. The tag only tells you so much — so we go digging into the platform for where they really are.

Read post
July 25, 2026

It's Not Happening in an Embassy. It's Happening Two Blocks From You.

It never looks like espionage at first. It looks like an opportunity — a message, an invite, a friendly recruiter two blocks from your office.

Read post
July 25, 2026

Thousands of Accounts. A Handful of Real People. We Close the Gap.

Thousands of accounts. A handful of real people. Every shortcut they take to fake a crowd is a thread you can pull.

Read post
July 20, 2026

The Intelligence 95% of Analysts Will Never Find

Seeing foreign ecosystems through a different lens — a new advanced, corporate-verified course that brings penetration-testing tradecraft to China OSINT and surfaces what conventional analysts never see.

Read post
July 8, 2026

Seven Things No CTI Platform Will Ever Find for You

The sales deck shows pins on every underground ecosystem. What ships is machine-translated headlines and keyword alerts — coverage you can see, intelligence you can't.

Read post
July 6, 2026

Your Vetting Came Back Clean. That's Exactly the Problem.

The résumé is the least trustworthy document in the room — and it's the one nearly every vetting process leans on hardest.

Read post
January 14, 2026

Stop Searching for What It Claims to Be. Fingerprint How It Was Built.

Operators leave default certificates, unchanged favicons, and framework credits sitting in the HTML. Every shortcut they take becomes a fingerprint — and fingerprints are searchable.

Read post
January 9, 2026

Before You Profile Him — Is That Even a Real Name?

张三 is China's John Doe. Before you build a profile on a Chinese name from a leak, make sure you're not chasing a placeholder.

Read post
December 30, 2025

The PLA Is Posting Its Own Movements to DouYin. We Read Them.

Some of the most valuable open-source intelligence on Chinese military activity isn't text — it's Douyin video. Here's how to work with it, even if you don't read Chinese.

Read post
December 19, 2025

270 Million Voiceprints a Month: Inside China's Listening Machine

Leaked internal documents reveal 270 million monthly voiceprint collections, video analysis deployed to China's security apparatus, and deep integration with Huawei systems.

Read post
China OSINT · Capture the Flag

Trace a real target through China's underground.

A free, hands-on investigation that chains the clues from the surface web down to the source — the same tradecraft, as a challenge. No course required to play.

Enter the CTF
Designed by EPCYBER · in collaboration with
Hacktoria UK OSINT
CSDN .ONION TELEGRAM QQ PHONE WEIBO TARGET
13Objectives6Platforms90MinutesEasy
QQ 百度 MOBILE 微博 微信 TARGET
10Objectives5Platforms120MinutesEasy
December 13, 2025

We Got Inside a CCP Village Surveillance System

Party members, veterans, grid watchers, militia warehouses, and 2,000 people whose every move is logged — a look inside a village-level CCP surveillance system on the North Korean border.

Read post
December 11, 2025

He Changed His Name. He Didn't Change These Four Things.

A new alias doesn't mean a new actor. Behavioral patterns, opsec failures and linguistic habits persist — here's a framework for collapsing personas back into one operator.

Read post
December 10, 2025

The Five Digits the PLA Doesn't Want You to Decode

Decode the structure of PLA unit designations — what the MUCD numbers reveal about branch, function, and command, and how to search them.

Read post
December 4, 2025

How the Shells Hide — and the One Character That Exposes Them

The day after a Chinese company hits the Entity List, a new one is registered in Hong Kong. Same address, same directors. Here are the patterns that give the cutouts away.

Read post
December 3, 2025

Your Chinese Name Search Is Wrong Before You Hit Enter

You search 'Zhang Wei' and get 50 million results. Chinese name OSINT runs on different logic — and if you don't understand it, you're drowning in false positives or missing your target.

Read post
December 2, 2025

It Files Patents in Plain Sight. Nobody Reads Them. We Do.

Beijing's military-civil fusion doesn't hide in secret networks — it files patents, registers companies, and occasionally leaks documents. Here's where to actually start looking.

Read post
August 12, 2025

The Old Forum Died Friday. We Already Found Where They Went.

XSS shut down, BreachForums got compromised, and a new forum quietly emerged to absorb the fallout. Spotting these shifts early is what separates reactive monitoring from proactive intelligence.

Read post
August 4, 2025

The Chinese AI Tools Built to Attack — Documented, Figure by Figure

China's 2025 AI Security Governance draft reads like standard regulatory noise — until you notice it's a playbook for AI-assisted offensive cyber operations at scale.

Read post
July 30, 2025

He Scrubbed Every Trace. One Government File Gave Him Up.

No military background anywhere online. Then a routine 2019 civil-servant candidate list from Jingmen City gave up the whole profile.

Read post
July 22, 2025

One Untitled Paste. Two Links. A Whole Network Behind It.

Some of the most actionable dark-web sources aren't buried in .onion forums — they're sitting in plain sight on paste sites. Here's how to pivot one overlooked paste into a live threat-actor network.

Read post
June 21, 2025

Get a Real Chinese Number — No ID, No Middleman, Full Control

A new method to obtain and use a real +86 number independently — create verified accounts on Zhihu, QQ, Weibo, Douyin and more, no ID verification required.

Read post
June 1, 2025

The Block Was Never Real. Two Ways Through, No VPN.

Wix-style geo/VPN/TOR blockers rely on simple logic. Understand how they work and two out-of-the-box methods open the door — no VPN required.

Read post
May 31, 2025

Everything QQ, WeChat, Weibo and Baidu Quietly Give Away

The complete field guide to China OSINT — every major domestic platform, what it exposes, and how analysts pull emails, phones, and usernames from it.

Read post
May 28, 2025

Metadata Exposed Dark Web Forum Admin

A familiar-looking logo on a dark web forum led us to its admin — through the image metadata they forgot to strip.

Read post
April 30, 2025

What DeepSeek Won't Tell You About Who It Answers To

Our DeepSeek AI × Chinese Military (PLA) ties and usage report — state influence, military adoption, and infrastructure abuse, from original EPCYBER research.

Read post
10:55
April 1, 2025

Watch Us Walk Past China's Corporate Data Wall — Live, Unedited

QCC and Tianyancha block foreign traffic with DPI, not a geo-fence — which is why a VPN doesn't get you in. Live, unedited, the route through.

Watch
1:21
February 21, 2025

50+ Files Marked Top Secret. Keyword Search Finds None. We Found Them.

Over 50 exposed government documents marked top secret or confidential — found with a single method, somewhere keywords return nothing.

Watch
1:15
February 16, 2025

75 Seconds on the Wall That Stops Every Western Analyst

Seventy-five seconds. The technical restrictions that stop most Western practitioners cold, and the way through.

Watch
5:58
February 16, 2025

No +86, No China OSINT. Here's How You Get One.

The +86 is the join between an account and a person. Here is how to get one.

Watch
13:01
January 21, 2025

RedNote Is Handing Out Its Users' Real Phone Numbers

RedNote leaks its users' mobile numbers. What that opens up, and the databases sitting behind it.

Watch
6:02
October 29, 2024

gov.cn Doesn't Delete the Data. It Bets You Can't Reach It.

Reaching gov.cn data past its technical restrictions. Methods we found ourselves — which is why they still work.

Watch
8:24
October 23, 2024

CSDN Shows You Just Enough to Know You're Missing the Rest. Here's the Rest.

CSDN shows you enough to know the answer is there, then holds the rest behind a +86 login. Step by step, without an account.

Watch
16:56
October 20, 2024

Cyber threat identification in China: the good, the bad, and what to do

Finding data, getting past site restrictions, and running CTI across China's landscape — tools, cases, and source development.

Watch
11:41
October 14, 2024

Twelve Minutes of a Real Investigation Going From Wrong to Right

Twelve minutes of an actual lesson. How we explore, search, and pivot in China's ecosystem — including the wrong turns.

Watch
6:26
August 5, 2024

Buy a Better Tool, Get the Same Blind Spots

90% of CTI reports scratch the surface. Two reasons nobody in the industry wants to name — and what actually fixes it.

Watch
4:23
July 23, 2024

There's a New Genesis Market. You'll Hear About It in Months. We Found It Now.

A Genesis Market successor and a new leaks search engine — both caught while still in early development, before anyone was watching.

Watch
10:18
July 13, 2024

What Your Analysts Will Actually Be Able to Do When They're Done

For team leaders asking what their analysts will actually be able to do afterward. The full rundown — and an honest note on who it isn't for yet.

Watch
3:54
July 6, 2024

Everyone Reaches for a VPN. That's Exactly Why They Fail.

Ask a Western analyst how to reach a blocked Chinese site and you get one answer. Those platforms were built assuming you'd bring exactly that.

Watch
7:10
April 4, 2024

The Full Discipline — Taught Until You Can Run It Yourself

An overview of the Advanced program — what it covers, and who it is built for.

Watch
5:18
August 28, 2023

One Weibo Image. One Trick. The Account Behind It.

A manual route from a Weibo image to the account behind it. One episode of Bytes of Clues — and a drop in the ocean, by our own admission.

Watch

GOT A QUESTION ABOUT OUR TRAININGS?

Not sure which program fits, or whether we cover what you need? Just ask.

We're happy to tell you whether a specific platform, or focus area is included in a given course — and if it's not, whether we can build it in.

Reach out to sales@epcyber.com about:

  • Whether we cover a specific platform (Weibo, Xiaohongshu, Douyin, CSDN, or anything not listed)
  • A particular focus area you need
  • Group rates, team enrollment, and custom corporate bundles
  • Eligibility — if you're unsure whether your organization qualifies
  • Payment options — wire transfer and other methods for organizations
  • Custom or tailored training built around your team's mission
  • Whatever you're trying to accomplish, tell us where you're headed and we'll point you to the right program.
All contact routes