<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>EPCYBER — China OSINT &amp; Dark Web Intelligence</title>
    <link>https://epcyber.com/blog.html</link>
    <atom:link href="https://epcyber.com/feed.xml" rel="self" type="application/rss+xml"/>
    <description>China-focused OSINT, dark-web CTI, and offensive-OSINT tradecraft — investigations, methods, and findings from the EPCYBER Intelligence Team.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 09:00:00 +0000</lastBuildDate>
    <image>
      <url>https://epcyber.com/assets/author.png</url>
      <title>EPCYBER</title>
      <link>https://epcyber.com/blog.html</link>
    </image>
    <item>
      <title>Offensive OSINT Course Launch</title>
      <link>https://epcyber.com/blog-offensive-osint-china.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-offensive-osint-china.html</guid>
      <pubDate>Mon, 20 Jul 2026 09:00:00 +0000</pubDate>
      <description>Seeing foreign ecosystems through a different lens — a new advanced, corporate-verified course that brings penetration-testing tradecraft to China OSINT and surfaces what conventional analysts never see.</description>
    </item>
    <item>
      <title>Threat Intelligence Platforms Suck. Here's Why</title>
      <link>https://epcyber.com/blog-threat-intelligence-platforms-suck.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-threat-intelligence-platforms-suck.html</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 +0000</pubDate>
      <description>The sales deck shows pins on every underground ecosystem. What ships is machine-translated headlines and keyword alerts — coverage you can see, intelligence you can't.</description>
    </item>
    <item>
      <title>China OSINT: Intelligence Gaps in Vetting Processes</title>
      <link>https://epcyber.com/blog-intelligence-gaps-vetting.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-intelligence-gaps-vetting.html</guid>
      <pubDate>Mon, 06 Jul 2026 09:00:00 +0000</pubDate>
      <description>The résumé is the least trustworthy document in the room — and it's the one nearly every vetting process leans on hardest.</description>
    </item>
    <item>
      <title>Cyber Intelligence: C2 Infra Detection</title>
      <link>https://epcyber.com/blog-c2-infra-detection.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-c2-infra-detection.html</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 +0000</pubDate>
      <description>Operators leave default certificates, unchanged favicons, and framework credits sitting in the HTML. Every shortcut they take becomes a fingerprint — and fingerprints are searchable.</description>
    </item>
    <item>
      <title>China OSINT: Is The Name Fake?</title>
      <link>https://epcyber.com/blog-is-the-name-fake.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-is-the-name-fake.html</guid>
      <pubDate>Fri, 09 Jan 2026 09:00:00 +0000</pubDate>
      <description>张三 is China's John Doe. Before you build a profile on a Chinese name from a leak, make sure you're not chasing a placeholder.</description>
    </item>
    <item>
      <title>China OSINT: DouYin Military Activity</title>
      <link>https://epcyber.com/blog-douyin-military-activity.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-douyin-military-activity.html</guid>
      <pubDate>Tue, 30 Dec 2025 09:00:00 +0000</pubDate>
      <description>Some of the most valuable open-source intelligence on Chinese military activity isn't text — it's Douyin video. Here's how to work with it, even if you don't read Chinese.</description>
    </item>
    <item>
      <title>China OSINT: Mass Surveillance Tech</title>
      <link>https://epcyber.com/blog-china-mass-surveillance-tech.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-china-mass-surveillance-tech.html</guid>
      <pubDate>Fri, 19 Dec 2025 09:00:00 +0000</pubDate>
      <description>Leaked internal documents reveal 270 million monthly voiceprint collections, video analysis deployed to China's security apparatus, and deep integration with Huawei systems.</description>
    </item>
    <item>
      <title>China OSINT: Inside The CCP</title>
      <link>https://epcyber.com/blog-inside-the-ccp.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-inside-the-ccp.html</guid>
      <pubDate>Sat, 13 Dec 2025 09:00:00 +0000</pubDate>
      <description>Party members, veterans, grid watchers, militia warehouses, and 2,000 people whose every move is logged — a look inside a village-level CCP surveillance system on the North Korean border.</description>
    </item>
    <item>
      <title>Cyber Intelligence: Threat Actor Attribution</title>
      <link>https://epcyber.com/blog-threat-actor-attribution.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-threat-actor-attribution.html</guid>
      <pubDate>Thu, 11 Dec 2025 09:00:00 +0000</pubDate>
      <description>A new alias doesn't mean a new actor. Behavioral patterns, opsec failures and linguistic habits persist — here's a framework for collapsing personas back into one operator.</description>
    </item>
    <item>
      <title>PLA Unit Numbers: What They Tell You</title>
      <link>https://epcyber.com/blog-pla-unit-numbers.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-pla-unit-numbers.html</guid>
      <pubDate>Wed, 10 Dec 2025 09:00:00 +0000</pubDate>
      <description>Decode the structure of PLA unit designations — what the MUCD numbers reveal about branch, function, and command, and how to search them.</description>
    </item>
    <item>
      <title>Sanctions Evasion Patterns: Chinese Shell Company Playbook</title>
      <link>https://epcyber.com/blog-sanctions-evasion-shell-companies.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-sanctions-evasion-shell-companies.html</guid>
      <pubDate>Thu, 04 Dec 2025 09:00:00 +0000</pubDate>
      <description>The day after a Chinese company hits the Entity List, a new one is registered in Hong Kong. Same address, same directors. Here are the patterns that give the cutouts away.</description>
    </item>
    <item>
      <title>The Name Is a Lie: China OSINT</title>
      <link>https://epcyber.com/blog-the-name-is-a-lie.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-the-name-is-a-lie.html</guid>
      <pubDate>Wed, 03 Dec 2025 09:00:00 +0000</pubDate>
      <description>You search 'Zhang Wei' and get 50 million results. Chinese name OSINT runs on different logic — and if you don't understand it, you're drowning in false positives or missing your target.</description>
    </item>
    <item>
      <title>Tracking Chinese Dual-Use Tech: Patents, Registries, and Leaks</title>
      <link>https://epcyber.com/blog-tracking-dual-use-tech.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-tracking-dual-use-tech.html</guid>
      <pubDate>Tue, 02 Dec 2025 09:00:00 +0000</pubDate>
      <description>Beijing's military-civil fusion doesn't hide in secret networks — it files patents, registers companies, and occasionally leaks documents. Here's where to actually start looking.</description>
    </item>
    <item>
      <title>New Underground Forum</title>
      <link>https://epcyber.com/blog-new-underground-forum.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-new-underground-forum.html</guid>
      <pubDate>Tue, 12 Aug 2025 09:00:00 +0000</pubDate>
      <description>XSS shut down, BreachForums got compromised, and a new forum quietly emerged to absorb the fallout. Spotting these shifts early is what separates reactive monitoring from proactive intelligence.</description>
    </item>
    <item>
      <title>China's Dual Use Tech: AI</title>
      <link>https://epcyber.com/blog-chinas-dual-use-tech-ai.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-chinas-dual-use-tech-ai.html</guid>
      <pubDate>Mon, 04 Aug 2025 09:00:00 +0000</pubDate>
      <description>China's 2025 AI Security Governance draft reads like standard regulatory noise — until you notice it's a playbook for AI-assisted offensive cyber operations at scale.</description>
    </item>
    <item>
      <title>Is your target PLA?</title>
      <link>https://epcyber.com/blog-is-your-target-pla.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-is-your-target-pla.html</guid>
      <pubDate>Wed, 30 Jul 2025 09:00:00 +0000</pubDate>
      <description>No military background anywhere online. Then a routine 2019 civil-servant candidate list from Jingmen City gave up the whole profile.</description>
    </item>
    <item>
      <title>From Pastebin to Threat Actor</title>
      <link>https://epcyber.com/blog-pastebin-to-threat-actor.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-pastebin-to-threat-actor.html</guid>
      <pubDate>Tue, 22 Jul 2025 09:00:00 +0000</pubDate>
      <description>Some of the most actionable dark-web sources aren't buried in .onion forums — they're sitting in plain sight on paste sites. Here's how to pivot one overlooked paste into a live threat-actor network.</description>
    </item>
    <item>
      <title>Obtain +86 CN Number for OSINT — New Method June 2025</title>
      <link>https://epcyber.com/blog-obtain-plus86-number-osint.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-obtain-plus86-number-osint.html</guid>
      <pubDate>Sat, 21 Jun 2025 09:00:00 +0000</pubDate>
      <description>A new method to obtain and use a real +86 number independently — create verified accounts on Zhihu, QQ, Weibo, Douyin and more, no ID verification required.</description>
    </item>
    <item>
      <title>Bypass Blocked Sites (No VPN)</title>
      <link>https://epcyber.com/blog-bypass-blocked-sites.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-bypass-blocked-sites.html</guid>
      <pubDate>Sun, 01 Jun 2025 09:00:00 +0000</pubDate>
      <description>Wix-style geo/VPN/TOR blockers rely on simple logic. Understand how they work and two out-of-the-box methods open the door — no VPN required.</description>
    </item>
    <item>
      <title>Ultimate Guide to China OSINT: Gathering Intelligence Online</title>
      <link>https://epcyber.com/blog-ultimate-guide-china-osint.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-ultimate-guide-china-osint.html</guid>
      <pubDate>Sat, 31 May 2025 09:00:00 +0000</pubDate>
      <description>The complete field guide to China OSINT — every major domestic platform, what it exposes, and how analysts pull emails, phones, and usernames from it.</description>
    </item>
    <item>
      <title>Metadata Exposed Dark Web Forum Admin</title>
      <link>https://epcyber.com/blog-metadata-exposed-forum-admin.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-metadata-exposed-forum-admin.html</guid>
      <pubDate>Wed, 28 May 2025 09:00:00 +0000</pubDate>
      <description>A familiar-looking logo on a dark web forum led us to its admin — through the image metadata they forgot to strip.</description>
    </item>
    <item>
      <title>DeepSeek PLA Ties and Usage</title>
      <link>https://epcyber.com/blog-deepseek-pla-ties-usage.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-deepseek-pla-ties-usage.html</guid>
      <pubDate>Wed, 30 Apr 2025 09:00:00 +0000</pubDate>
      <description>Our DeepSeek AI × Chinese Military (PLA) ties and usage report — state influence, military adoption, and infrastructure abuse, from original EPCYBER research.</description>
    </item>
    <item>
      <title>Live bypass: QCC.com &amp; Tianyancha</title>
      <link>https://epcyber.com/blog-live-bypass-qcc-tianyancha.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-live-bypass-qcc-tianyancha.html</guid>
      <pubDate>Tue, 01 Apr 2025 09:00:00 +0000</pubDate>
      <description>QCC and Tianyancha block foreign traffic with DPI, not a geo-fence — which is why a VPN doesn't get you in. Live, unedited, the route through.</description>
    </item>
    <item>
      <title>Chinese Top Secret G0V files: OSINT in China</title>
      <link>https://epcyber.com/blog-chinese-top-secret-gov-files.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-chinese-top-secret-gov-files.html</guid>
      <pubDate>Fri, 21 Feb 2025 09:00:00 +0000</pubDate>
      <description>Over 50 exposed government documents marked top secret or confidential — found with a single method, somewhere keywords return nothing.</description>
    </item>
    <item>
      <title>Bypassing access to restricted Chinese networks</title>
      <link>https://epcyber.com/blog-bypass-restricted-chinese-networks.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-bypass-restricted-chinese-networks.html</guid>
      <pubDate>Sun, 16 Feb 2025 09:00:00 +0000</pubDate>
      <description>Seventy-five seconds. The technical restrictions that stop most Western practitioners cold, and the way through.</description>
    </item>
    <item>
      <title>Get Chinese mobile numbers for OSINT in China</title>
      <link>https://epcyber.com/blog-chinese-mobile-numbers.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-chinese-mobile-numbers.html</guid>
      <pubDate>Sun, 16 Feb 2025 09:00:00 +0000</pubDate>
      <description>The +86 is the join between an account and a person. Here is how to get one.</description>
    </item>
    <item>
      <title>RedNote is exposing users' mobile numbers</title>
      <link>https://epcyber.com/blog-rednote-exposing-numbers.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-rednote-exposing-numbers.html</guid>
      <pubDate>Tue, 21 Jan 2025 09:00:00 +0000</pubDate>
      <description>RedNote leaks its users' mobile numbers. What that opens up, and the databases sitting behind it.</description>
    </item>
    <item>
      <title>Methods to bypass Chinese government (gov.cn) site restrictions</title>
      <link>https://epcyber.com/blog-bypass-gov-cn-restrictions.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-bypass-gov-cn-restrictions.html</guid>
      <pubDate>Tue, 29 Oct 2024 09:00:00 +0000</pubDate>
      <description>Reaching gov.cn data past its technical restrictions. Methods we found ourselves — which is why they still work.</description>
    </item>
    <item>
      <title>Bypassing CSDN without an account</title>
      <link>https://epcyber.com/blog-bypassing-csdn.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-bypassing-csdn.html</guid>
      <pubDate>Wed, 23 Oct 2024 09:00:00 +0000</pubDate>
      <description>CSDN shows you enough to know the answer is there, then holds the rest behind a +86 login. Step by step, without an account.</description>
    </item>
    <item>
      <title>Cyber threat identification in China: the good, the bad, and what to do</title>
      <link>https://epcyber.com/blog-cyber-threat-identification-china.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-cyber-threat-identification-china.html</guid>
      <pubDate>Sun, 20 Oct 2024 09:00:00 +0000</pubDate>
      <description>Finding data, getting past site restrictions, and running CTI across China's landscape — tools, cases, and source development.</description>
    </item>
    <item>
      <title>Sneak peek: finding Chinese SOCMINT tools and methods</title>
      <link>https://epcyber.com/blog-socmint-sneak-peek.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-socmint-sneak-peek.html</guid>
      <pubDate>Mon, 14 Oct 2024 09:00:00 +0000</pubDate>
      <description>Twelve minutes of an actual lesson. How we explore, search, and pivot in China's ecosystem — including the wrong turns.</description>
    </item>
    <item>
      <title>Why CTI platforms fail to deliver, and what we do instead</title>
      <link>https://epcyber.com/blog-why-cti-platforms-fail-video.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-why-cti-platforms-fail-video.html</guid>
      <pubDate>Mon, 05 Aug 2024 09:00:00 +0000</pubDate>
      <description>90% of CTI reports scratch the surface. Two reasons nobody in the industry wants to name — and what actually fixes it.</description>
    </item>
    <item>
      <title>A new dark web Genesis Market, and a new leaks search engine</title>
      <link>https://epcyber.com/blog-new-genesis-market.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-new-genesis-market.html</guid>
      <pubDate>Tue, 23 Jul 2024 09:00:00 +0000</pubDate>
      <description>A Genesis Market successor and a new leaks search engine — both caught while still in early development, before anyone was watching.</description>
    </item>
    <item>
      <title>What skills you gain from our China OSINT trainings</title>
      <link>https://epcyber.com/blog-what-skills-you-gain.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-what-skills-you-gain.html</guid>
      <pubDate>Sat, 13 Jul 2024 09:00:00 +0000</pubDate>
      <description>For team leaders asking what their analysts will actually be able to do afterward. The full rundown — and an honest note on who it isn't for yet.</description>
    </item>
    <item>
      <title>Bypassing access without VPN</title>
      <link>https://epcyber.com/blog-bypassing-access-without-vpn.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-bypassing-access-without-vpn.html</guid>
      <pubDate>Sat, 06 Jul 2024 09:00:00 +0000</pubDate>
      <description>Ask a Western analyst how to reach a blocked Chinese site and you get one answer. Those platforms were built assuming you'd bring exactly that.</description>
    </item>
    <item>
      <title>China OSINT Advanced</title>
      <link>https://epcyber.com/blog-china-osint-advanced-overview.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-china-osint-advanced-overview.html</guid>
      <pubDate>Thu, 04 Apr 2024 09:00:00 +0000</pubDate>
      <description>An overview of the Advanced program — what it covers, and who it is built for.</description>
    </item>
    <item>
      <title>You need to know this Weibo OSINT trick</title>
      <link>https://epcyber.com/blog-weibo-osint-trick.html</link>
      <guid isPermaLink="true">https://epcyber.com/blog-weibo-osint-trick.html</guid>
      <pubDate>Mon, 28 Aug 2023 09:00:00 +0000</pubDate>
      <description>A manual route from a Weibo image to the account behind it. One episode of Bytes of Clues — and a drop in the ocean, by our own admission.</description>
    </item>
  </channel>
</rss>
