Executive Summary

UCloud Technology Co., Ltd (ไผ˜ๅˆปๅพ—็ง‘ๆŠ€่‚กไปฝๆœ‰้™ๅ…ฌๅธ) is publicly listed on the Shanghai STAR Market since January 2020. It is not a shadowy operator. It is a PRC-incorporated, state-regulated, stock-market-listed company โ€” fully subject to the 2017 Cybersecurity Law, the 2021 Data Security Law, and the 2017 National Intelligence Law. Its international operations route through UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED, a thin Hong Kong subsidiary that registered AS135377 with APNIC using phone number +000000000. That phone number appears in the APNIC RDAP record. It is false. This is not an oversight โ€” it is a deliberate attribute designed to break the contact chain. Behind this fabricated contact, we track 147 IPs across 11 countries, with 48 at maximum abuse confidence and 8 flagged as actively malicious by GreyNoise.

The Parent: Shanghai STAR Market

UCloud Technology (stock code: 688158.SH) completed its IPO on January 20, 2020 on the Shanghai Stock Exchange's Science and Technology Innovation Board (STAR Market). Key corporate facts:

  • Jurisdiction: People's Republic of China (Shanghai)
  • Listing: Shanghai STAR Market (็ง‘ๅˆ›ๆฟ) โ€” requires full PRC regulatory compliance
  • Website: ucloud.cn (PeeringDB confirms)
  • Services: IaaS, PaaS, Big Data, AI cloud services
  • Legal obligations: PRC Cybersecurity Law (Art. 28: must provide "technical support" to state security organs), National Intelligence Law (Art. 7: must "support, assist and cooperate" with state intelligence work)

This is not a startup operating from a co-working space. This is a publicly listed, state-supervised corporation whose legal obligations include cooperation with Chinese intelligence services โ€” operating attack infrastructure across 11 countries through a Hong Kong shell with a fake phone number.

The Shell: Hong Kong Subsidiary

UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED

The Hong Kong entity serves exactly one purpose: jurisdictional separation between the PRC parent and international IP allocations. Key indicators of shell status:

  • APNIC phone: +000000000 โ€” fabricated contact (9 zeros, no valid country code)
  • PeeringDB policy: "Open" โ€” accepts any peer without verification
  • IRR reference: AS-135377 (self-referential, no upstream policy objects)
  • Website: Points to ucloud.cn (mainland parent) โ€” no independent HK web presence
  • Allocated: 2016 (pre-IPO, during expansion phase)

A legitimate international subsidiary would have verifiable contact information, independent corporate registration, and a compliance team. This entity has none of these. It exists to hold APNIC-allocated IP space outside PRC jurisdiction while remaining operationally controlled from Shanghai.

The Archipelago: 147 IPs Across 11 Countries

MetricValueSignificance
Total tracked IPs147Third-largest Chinese cloud in our DB
AbuseIPDB = 1004833% at maximum abuse confidence
GreyNoise "malicious"8Actively targeting internet infrastructure
Max threat score95Near maximum (165.154.6.119)
Total honeypot hits563Active SSH brute-forcing
Countries claimed11HK, US, SG, VN, JP, RU, GB, IN, MY, DE, TW
Average threat score26Diluted by low-activity IPs โ€” top tier is devastating

The Geographic Fabrication

Country distribution reveals the archipelago strategy:

CountryIPs%Note
Hong Kong ๐Ÿ‡ญ๐Ÿ‡ฐ11377%Actual routing location
United States ๐Ÿ‡บ๐Ÿ‡ธ1812%Claims US but routes HK
Singapore ๐Ÿ‡ธ๐Ÿ‡ฌ53%Partner jurisdiction
Vietnam ๐Ÿ‡ป๐Ÿ‡ณ32%BRI partner state
Japan ๐Ÿ‡ฏ๐Ÿ‡ต21%Key market
Russia ๐Ÿ‡ท๐Ÿ‡บ1<1%Cloud Innovation Support crosslink!
Others (GB, IN, MY, DE, TW)53%Scattered presence

77% route through Hong Kong regardless of claimed geolocation. The 18 "US" IPs are particularly interesting โ€” they claim American jurisdiction (where abuse reporting has teeth) while routing through HK (where it doesn't). This is geolocation fraud in service of jurisdictional arbitrage.

The Cloud Innovation Crosslink

45.195.221.26: The Bridge IP

One UCloud IP โ€” 45.195.221.26 โ€” has rdap_org = "Cloud Innovation Support". This is the same entity documented in 031C (The Seychelles Phone) that uses phone +248-4-610-795 across 15+ ASNs.

This IP claims to be in Russia, has threat score 61, abuse score 100, and routes through AS135377 (UCloud HK). The presence of Cloud Innovation Support as the RDAP registrant on a UCloud-routed IP proves infrastructure sharing between the Yisu Cloud/Cloud Innovation network and UCloud. They are not merely parallel operators โ€” they share address space.

The "Benny Huang" Anomaly

IP 103.210.21.178 (threat=81, hits=27) has rdap_org = "Benny Huang" โ€” not a corporate entity but a personal name. This IP also shows:

  • abuse_country: HK
  • cymru_country: SG (Singapore!)
  • rdap_country: CN
  • Geo status: DISCREPANT โ€” three different countries across three data sources

A single IP claiming to be Chinese (registration), Singaporean (BGP routing), and Hong Kong (abuse reports) โ€” registered to a personal name rather than a corporate entity on an ASN that belongs to a Shanghai-listed corporation. This is either an intermediary reseller or a deliberate registration obfuscation.

The AI Credential Connection

Prior investigation TI-019F identified UCloud Hong Kong as a major infrastructure provider for AI credential-hunting campaigns. These campaigns specifically target Claude, ChatGPT, and other AI API endpoints โ€” attempting to steal API keys through SSH compromise.

The connection is documented: AI credential-hunting campaign --uses_infrastructure--> UCloud Hong Kong. A Shanghai STAR Market listed company's infrastructure is being used โ€” demonstrably and repeatedly โ€” to attack AI services. The company's legal obligations under PRC law make this doubly significant: they cannot refuse state requests to maintain this access even if they wanted to.

The Legal Framework

What PRC Law Requires

As a PRC-incorporated, STAR Market-listed company, UCloud Technology is bound by:

  • Cybersecurity Law Art. 28: "Network operators shall provide technical support and assistance to public security organs and national security organs..."
  • National Intelligence Law Art. 7: "All organizations and citizens shall support, assist, and cooperate with national intelligence work..."
  • National Intelligence Law Art. 14: Intelligence agencies "may demand that relevant organs, organizations, and citizens provide necessary support, assistance, and cooperation"
  • Data Security Law Art. 36: Cannot provide data stored in China to foreign judicial/enforcement bodies without PRC government approval

The legal architecture is clear: UCloud must cooperate with state intelligence if asked. It cannot respond to foreign law enforcement requests without PRC approval. The Hong Kong shell with its fake phone number is not just commercial convenience โ€” it is the technical implementation of this legal asymmetry.

Scale Comparison

147
IPs tracked
48
At max abuse (100)
11
Countries claimed
+000000000
The fake phone

Methodology & Sources

Data from: LSN Honeypot (563 SSH sessions), threat_intel database (147 IPs on AS135377), AbuseIPDB (48 IPs at confidence 100), GreyNoise (8 classified malicious), PeeringDB (UCloud profile confirming ucloud.cn parent), APNIC RDAP (phone +000000000 in ASN registration), Team Cymru (BGP routing verification), prior investigations TI-019F (AI credential hunting), TI-2026-031C (Cloud Innovation Support crosslink). Corporate data from Shanghai Stock Exchange STAR Market listings (688158.SH). Legal citations from official PRC law translations.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Cloud Silk Road โ€” 4 / 10 Next โ†’