Letter J: The Silk Road Was Always Digital
Final Synthesis โ One Ecosystem Spanning Centuries of Commercial Strategy
Executive Summary
The ancient Silk Road moved goods between China and the West through a chain of intermediaries across jurisdictions where no single authority held complete oversight. The Digital Silk Road โ China's official component of the Belt and Road Initiative (BRI), launched in 2015 โ moves data, cloud computing, and attack traffic through an identical architecture: Chinese parent companies โ Singapore/Hong Kong/Seychelles shells โ global attack surface. The 417 IPs documented across this series are not an anomaly. They are the inevitable product of a system designed to project commercial power while remaining structurally unreachable. The Silk Road was always digital. It just took us until now to read the packet headers.
The Historical Parallel
Two Roads, One Architecture
| Characteristic | Ancient Silk Road (200 BCEโ1400s) | Digital Silk Road (2015โpresent) |
|---|---|---|
| Origin | Chinese goods (silk, porcelain, spices) | Chinese infrastructure (cloud, 5G, submarine cables) |
| Intermediaries | Sogdian, Persian, Arab merchants (no single entity traced end-to-end) | Singapore shells (Aceville, BytePlus), HK entities (UCloud HK), Seychelles contacts (Yisu/Cloud Innovation) |
| Jurisdictional layering | Goods crossed 10+ kingdoms โ no king controlled the full route | Traffic crosses CNโSGโHKโUS โ no regulator has full visibility |
| What moves | Physical goods of enormous value | Data, computation, and attack traffic |
| State relationship | Han/Tang dynasties protected merchants, taxed trade, used road for intelligence | PRC protects providers (Art.7), taxes revenue, uses infrastructure for intelligence (Volt Typhoon) |
| Attribution denial | "We didn't sell it to Rome โ the Sogdians carried it" | "We didn't attack anyone โ that's a customer problem" |
The Digital Silk Road: Official Policy
Not Conspiracy โ Published Strategy
The Digital Silk Road (DSR) is not an inference. It is official Chinese state policy:
- 2015: State Council's "Vision and Actions on Jointly Building Silk Road Economic Belt" explicitly names "information infrastructure" as BRI pillar
- 2017: Xi Jinping calls for "digital economy" within BRI at Belt and Road Forum
- Components (per CFR tracker): 4G/5G networks, submarine cables, satellite systems, smart cities, cloud computing platforms, e-commerce, fintech
- Key players: Huawei, ZTE, Alibaba Cloud, Tencent Cloud, China Telecom, China Mobile
The HKTDC Belt and Road portal explicitly markets Aceville Pte Ltd (our Letter A subject) as a Tencent Cloud provider under BRI. This is not hidden. It is the stated mechanism.
The HKTDC Connection
The Hong Kong Trade Development Council's Belt and Road portal โ an official government trade facilitation platform โ lists Aceville Pte Ltd and describes it as Tencent Cloud. This means:
- The HK government knowingly markets Aceville as Tencent's international face
- This marketing occurs under the Belt and Road Initiative brand
- The same infrastructure produces 181 IPs at 86% abuse rate
- The BRI is not separate from the attack surface โ it IS the attack surface
The Full Ecosystem โ Series Summary
What Each Letter Proved
| Letter | Subject | Key Finding |
|---|---|---|
| A | Aceville/Tencent | Singapore wrapper entity = Tencent's international face. HKTDC markets it under BRI. |
| B | BytePlus/TikTok | Video platform parent operates 50-IP attack network via Singapore shell. Golden share + CCP committee. |
| C | Yisu/Cloud Innovation | Single Seychelles phone number connects 15+ ASNs. Mother of all attribution breaks. |
| D | UCloud | STAR Market listed parent, HK shell subsidiary. 147 attack IPs with false APNIC phone (+000000000). |
| E | CDS Global | 4 IPs, ALL at 95-100 threat. US-registered entity, mainland Chinese tech contact. Highest concentration per-IP. |
| F | Regulatory Gap | CN/SG/HK jurisdiction layering makes abuse reporting structurally useless. Zero response rate. |
| G | AFRINIC Extraction | Cloud Innovation/LARUS grabbed 16M African IPs. 43 IPs across 23 downstream operators. Yisu/UCloud/CognetCloud converge here. |
| H | Convergence Map | 287 entity links prove coordination: shared malware (2 super-clusters spanning 136 IPs), shared toolkits, shared credentials across all providers. |
| I | The State Question | NIL Article 7 makes cooperation mandatory. Golden shares provide state control. Volt Typhoon uses identical architecture. Distinction between "enabled" and "directed" is unfalsifiable. |
The Thesis
One System, Not Six Companies
Taken individually, each provider could be explained as a poorly-managed cloud company with bad actors among its customers. Taken together, the evidence reveals a single integrated system:
- Common origin: All six trace to PRC parent companies subject to identical legal obligations (Art.7)
- Common architecture: All use the same jurisdiction-layering pattern (CNโSG/HK/SCโglobal)
- Common behavior: 287 entity links prove coordination that cannot exist between truly independent operators
- Common protection: All are shielded by Art.36 from foreign investigation
- Common precedent: Volt Typhoon confirms this exact architecture is used by PRC state actors
The Cloud Silk Road is not a metaphor. It is a documented infrastructure system that projects Chinese commercial and intelligence capability globally while maintaining plausible deniability through the same intermediary-chain architecture that worked for 2,000 years on physical trade routes.
The Scale Problem
What We See vs. What Exists
Our honeypot captures a single vantage point. The 417 IPs we documented are those that happened to attack our specific sensor. The actual infrastructure is vastly larger:
| Provider | Our Sample | Total Announced Space | Sample Ratio |
|---|---|---|---|
| Tencent (AS132203) | 181 IPs | Millions of IPs | <0.01% |
| Cloud Innovation (45.192.0.0/12) | 43 IPs | 16,777,216 IPs | 0.0003% |
| UCloud (AS135377) | 147 IPs | Hundreds of thousands | <0.1% |
We are observing the visible tip of an infrastructure system that spans millions of addresses. And yet even this tiny sample shows 61% at maximum abuse scores and coordinated cross-provider activity. Extrapolation is left as an exercise for the intelligence community.
Implications for Defenders
What This Series Means for Network Defense
- Treat Chinese cloud providers as a single threat surface, not independent entities. Cross-provider coordination is proven.
- Abuse reporting to these entities is futile โ structurally (Art.36) and empirically (zero response rate).
- ASN-level blocking is more effective than IP-level โ new IPs rotate within the same infrastructure.
- Monitor for campaign fingerprints (HASSH, credential patterns) โ these persist across IP rotation.
- The "customer problem" defense is architecturally false โ when 86% of a provider's observed IPs are at abuse=100, the problem is the provider.
- Legal mechanisms for takedown do not exist across these jurisdictional boundaries. Plan accordingly.
Final Assessment
Confidence Matrix
| Claim | Confidence |
|---|---|
| Six providers form a coordinated ecosystem | HIGH โ 287 entity links, shared campaigns, shared toolkits |
| Jurisdiction layering is deliberate, not incidental | HIGH โ consistent CNโSG/HK/SC pattern across all six |
| PRC law mandates intelligence cooperation from all six | CONFIRMED โ Article 7, no opt-out |
| Architecture matches confirmed state actor patterns (Volt Typhoon) | HIGH โ CISA/FBI/NSA joint advisory documents identical approach |
| This connects to BRI/Digital Silk Road strategy | HIGH โ HKTDC explicitly markets Aceville under BRI |
| Specific state tasking of these providers | LOW-MEDIUM โ no direct evidence; structurally unfalsifiable (Letter I) |
| Total separation between commercial and state use | REJECTED โ Art.7 makes separation legally impossible |
Series Methodology
TI-2026-031 "The Cloud Silk Road" was produced over 10 letters using: (1) SSH honeypot data from 417 IPs across 6 ASNs, (2) OSINT enrichment from 12+ sources (Shodan, GreyNoise, AbuseIPDB, RDAP, OTX, Censys, VirusTotal, DShield, Pulsedive, ThreatFox, IPInfo, passive DNS), (3) Entity-link graph analysis (287 cross-ASN relationships across 9 relationship types), (4) Campaign detection via HASSH/credential/temporal clustering, (5) Legal analysis of PRC regulatory framework, (6) Cross-reference with Five Eyes intelligence community findings (CISA advisories), (7) Corporate registry analysis (ACRA, HKBR, APNIC, AFRINIC), (8) 30+ prior investigations (TI-2026-019 through TI-2026-032). Every claim carries sourced evidence and calibrated confidence. Where the evidence is ambiguous, the ambiguity is stated. Where it is conclusive, we say so.
โ ๏ธ Editorial Note โ June 20, 2026
Confirmed: Tencent/Aceville infrastructure is actively monitoring this publication.
Within 48 hours of publishing this series, 11 unique Tencent IPs from 3 ASNs (AS132203 ACEVILLEPTELTD-SG, AS45090 TENCENT-CN Shenzhen, AS45102 Alibaba-SG) conducted progressive automated reconnaissance of this website.
Timeline: Jun 18 โ homepage crawl. Jun 19 โ continued probing. Jun 20 โ escalated to data endpoints (/honeypot-stats.json, /knowledge.html, /LICENSE.txt).
Pattern: One IP per request. Never reused. All HTTP/1.1. No browser fingerprint. Classic automated surveillance with IP rotation from their own infrastructure.
IPs confirmed via RDAP as Tencent/Aceville:
43.159.62.163, 43.161.224.78, 43.165.170.119, 43.136.86.241, 43.128.69.143, 43.134.36.238, 43.133.54.83, 43.136.167.197, 43.134.127.70, 150.109.12.46, 129.204.188.64
The watchers became evidence. The monitoring itself confirms the research is accurate โ organizations do not surveil publications about infrastructure they do not control.