TI-2026-031 ยท The Cloud Silk Road A B C D E F G H I J

Letter J: The Silk Road Was Always Digital

Final Synthesis โ€” One Ecosystem Spanning Centuries of Commercial Strategy

Executive Summary

The ancient Silk Road moved goods between China and the West through a chain of intermediaries across jurisdictions where no single authority held complete oversight. The Digital Silk Road โ€” China's official component of the Belt and Road Initiative (BRI), launched in 2015 โ€” moves data, cloud computing, and attack traffic through an identical architecture: Chinese parent companies โ†’ Singapore/Hong Kong/Seychelles shells โ†’ global attack surface. The 417 IPs documented across this series are not an anomaly. They are the inevitable product of a system designed to project commercial power while remaining structurally unreachable. The Silk Road was always digital. It just took us until now to read the packet headers.

The Historical Parallel

Two Roads, One Architecture

CharacteristicAncient Silk Road (200 BCEโ€“1400s)Digital Silk Road (2015โ€“present)
Origin Chinese goods (silk, porcelain, spices) Chinese infrastructure (cloud, 5G, submarine cables)
Intermediaries Sogdian, Persian, Arab merchants (no single entity traced end-to-end) Singapore shells (Aceville, BytePlus), HK entities (UCloud HK), Seychelles contacts (Yisu/Cloud Innovation)
Jurisdictional layering Goods crossed 10+ kingdoms โ€” no king controlled the full route Traffic crosses CNโ†’SGโ†’HKโ†’US โ€” no regulator has full visibility
What moves Physical goods of enormous value Data, computation, and attack traffic
State relationship Han/Tang dynasties protected merchants, taxed trade, used road for intelligence PRC protects providers (Art.7), taxes revenue, uses infrastructure for intelligence (Volt Typhoon)
Attribution denial "We didn't sell it to Rome โ€” the Sogdians carried it" "We didn't attack anyone โ€” that's a customer problem"

The Digital Silk Road: Official Policy

Not Conspiracy โ€” Published Strategy

The Digital Silk Road (DSR) is not an inference. It is official Chinese state policy:

  • 2015: State Council's "Vision and Actions on Jointly Building Silk Road Economic Belt" explicitly names "information infrastructure" as BRI pillar
  • 2017: Xi Jinping calls for "digital economy" within BRI at Belt and Road Forum
  • Components (per CFR tracker): 4G/5G networks, submarine cables, satellite systems, smart cities, cloud computing platforms, e-commerce, fintech
  • Key players: Huawei, ZTE, Alibaba Cloud, Tencent Cloud, China Telecom, China Mobile

The HKTDC Belt and Road portal explicitly markets Aceville Pte Ltd (our Letter A subject) as a Tencent Cloud provider under BRI. This is not hidden. It is the stated mechanism.

The HKTDC Connection

The Hong Kong Trade Development Council's Belt and Road portal โ€” an official government trade facilitation platform โ€” lists Aceville Pte Ltd and describes it as Tencent Cloud. This means:

  1. The HK government knowingly markets Aceville as Tencent's international face
  2. This marketing occurs under the Belt and Road Initiative brand
  3. The same infrastructure produces 181 IPs at 86% abuse rate
  4. The BRI is not separate from the attack surface โ€” it IS the attack surface

The Full Ecosystem โ€” Series Summary

6
Cloud Providers
417
Attack IPs
253
Abuse = 100
287
Cross-Provider Links
5
Jurisdictions
0
Abuse Reports Answered

What Each Letter Proved

LetterSubjectKey Finding
A Aceville/Tencent Singapore wrapper entity = Tencent's international face. HKTDC markets it under BRI.
B BytePlus/TikTok Video platform parent operates 50-IP attack network via Singapore shell. Golden share + CCP committee.
C Yisu/Cloud Innovation Single Seychelles phone number connects 15+ ASNs. Mother of all attribution breaks.
D UCloud STAR Market listed parent, HK shell subsidiary. 147 attack IPs with false APNIC phone (+000000000).
E CDS Global 4 IPs, ALL at 95-100 threat. US-registered entity, mainland Chinese tech contact. Highest concentration per-IP.
F Regulatory Gap CN/SG/HK jurisdiction layering makes abuse reporting structurally useless. Zero response rate.
G AFRINIC Extraction Cloud Innovation/LARUS grabbed 16M African IPs. 43 IPs across 23 downstream operators. Yisu/UCloud/CognetCloud converge here.
H Convergence Map 287 entity links prove coordination: shared malware (2 super-clusters spanning 136 IPs), shared toolkits, shared credentials across all providers.
I The State Question NIL Article 7 makes cooperation mandatory. Golden shares provide state control. Volt Typhoon uses identical architecture. Distinction between "enabled" and "directed" is unfalsifiable.

The Thesis

One System, Not Six Companies

Taken individually, each provider could be explained as a poorly-managed cloud company with bad actors among its customers. Taken together, the evidence reveals a single integrated system:

  • Common origin: All six trace to PRC parent companies subject to identical legal obligations (Art.7)
  • Common architecture: All use the same jurisdiction-layering pattern (CNโ†’SG/HK/SCโ†’global)
  • Common behavior: 287 entity links prove coordination that cannot exist between truly independent operators
  • Common protection: All are shielded by Art.36 from foreign investigation
  • Common precedent: Volt Typhoon confirms this exact architecture is used by PRC state actors

The Cloud Silk Road is not a metaphor. It is a documented infrastructure system that projects Chinese commercial and intelligence capability globally while maintaining plausible deniability through the same intermediary-chain architecture that worked for 2,000 years on physical trade routes.

The Scale Problem

What We See vs. What Exists

Our honeypot captures a single vantage point. The 417 IPs we documented are those that happened to attack our specific sensor. The actual infrastructure is vastly larger:

ProviderOur SampleTotal Announced SpaceSample Ratio
Tencent (AS132203) 181 IPs Millions of IPs <0.01%
Cloud Innovation (45.192.0.0/12) 43 IPs 16,777,216 IPs 0.0003%
UCloud (AS135377) 147 IPs Hundreds of thousands <0.1%

We are observing the visible tip of an infrastructure system that spans millions of addresses. And yet even this tiny sample shows 61% at maximum abuse scores and coordinated cross-provider activity. Extrapolation is left as an exercise for the intelligence community.

Implications for Defenders

What This Series Means for Network Defense

  1. Treat Chinese cloud providers as a single threat surface, not independent entities. Cross-provider coordination is proven.
  2. Abuse reporting to these entities is futile โ€” structurally (Art.36) and empirically (zero response rate).
  3. ASN-level blocking is more effective than IP-level โ€” new IPs rotate within the same infrastructure.
  4. Monitor for campaign fingerprints (HASSH, credential patterns) โ€” these persist across IP rotation.
  5. The "customer problem" defense is architecturally false โ€” when 86% of a provider's observed IPs are at abuse=100, the problem is the provider.
  6. Legal mechanisms for takedown do not exist across these jurisdictional boundaries. Plan accordingly.

Final Assessment

Confidence Matrix

ClaimConfidence
Six providers form a coordinated ecosystemHIGH โ€” 287 entity links, shared campaigns, shared toolkits
Jurisdiction layering is deliberate, not incidentalHIGH โ€” consistent CNโ†’SG/HK/SC pattern across all six
PRC law mandates intelligence cooperation from all sixCONFIRMED โ€” Article 7, no opt-out
Architecture matches confirmed state actor patterns (Volt Typhoon)HIGH โ€” CISA/FBI/NSA joint advisory documents identical approach
This connects to BRI/Digital Silk Road strategyHIGH โ€” HKTDC explicitly markets Aceville under BRI
Specific state tasking of these providersLOW-MEDIUM โ€” no direct evidence; structurally unfalsifiable (Letter I)
Total separation between commercial and state useREJECTED โ€” Art.7 makes separation legally impossible

Series Methodology

TI-2026-031 "The Cloud Silk Road" was produced over 10 letters using: (1) SSH honeypot data from 417 IPs across 6 ASNs, (2) OSINT enrichment from 12+ sources (Shodan, GreyNoise, AbuseIPDB, RDAP, OTX, Censys, VirusTotal, DShield, Pulsedive, ThreatFox, IPInfo, passive DNS), (3) Entity-link graph analysis (287 cross-ASN relationships across 9 relationship types), (4) Campaign detection via HASSH/credential/temporal clustering, (5) Legal analysis of PRC regulatory framework, (6) Cross-reference with Five Eyes intelligence community findings (CISA advisories), (7) Corporate registry analysis (ACRA, HKBR, APNIC, AFRINIC), (8) 30+ prior investigations (TI-2026-019 through TI-2026-032). Every claim carries sourced evidence and calibrated confidence. Where the evidence is ambiguous, the ambiguity is stated. Where it is conclusive, we say so.

โš ๏ธ Editorial Note โ€” June 20, 2026

Confirmed: Tencent/Aceville infrastructure is actively monitoring this publication.

Within 48 hours of publishing this series, 11 unique Tencent IPs from 3 ASNs (AS132203 ACEVILLEPTELTD-SG, AS45090 TENCENT-CN Shenzhen, AS45102 Alibaba-SG) conducted progressive automated reconnaissance of this website.

Timeline: Jun 18 โ€” homepage crawl. Jun 19 โ€” continued probing. Jun 20 โ€” escalated to data endpoints (/honeypot-stats.json, /knowledge.html, /LICENSE.txt).

Pattern: One IP per request. Never reused. All HTTP/1.1. No browser fingerprint. Classic automated surveillance with IP rotation from their own infrastructure.

IPs confirmed via RDAP as Tencent/Aceville:
43.159.62.163, 43.161.224.78, 43.165.170.119, 43.136.86.241, 43.128.69.143, 43.134.36.238, 43.133.54.83, 43.136.167.197, 43.134.127.70, 150.109.12.46, 129.204.188.64

The watchers became evidence. The monitoring itself confirms the research is accurate โ€” organizations do not surveil publications about infrastructure they do not control.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Cloud Silk Road โ€” 10 / 10 Next โ†’