Cybersecurity company CrowdStrike has revealed a spike in Chinese-language underground market and the increasing use of artificial intelligence (AI) in ransomware operations across Asia Pacific and Japan (APJ).
In its 2025 APJ eCrime Landscape Report, CrowdStrike said that despite China’s internet restrictions and government crackdowns on cybercrime, online marketplaces continue to serve as key hubs for illegal activity.
“This ecosystem provides a safe haven for Chinese-speaking actors to buy and sell stolen credentials, phishing kits, malware, and money-laundering services, processing billions in illicit transactions,” the company said.
“eCrime actors are industrializing cybercrime across APJ through thriving underground markets and complex ransomware operations,” said Adam Meyers, head of counter adversary operations at CrowdStrike.
CrowdStrike found that Chinese underground markets such as Chang’an, FreeCity, and Huione Guarantee remain active despite tighter oversight, with Huione Guarantee alone processing about $27 billion before it was disrupted in 2025.
The report also noted that Chinese-speaking actors hijacked Japanese trading accounts to manipulate the prices of China-based stocks, using shared phishing infrastructure and selling stolen data on underground forums. Other cybercrime service providers, including CDNCLOUD, Magical Cat, and Graves International SMS, helped scale phishing and malware operations throughout the region.
CrowdStrike said that Chinese-speaking groups used tools such as ChangemeRAT, ElseRAT, and WhiteFoxRAT to target users in China and Japan through fake ads, phishing, and search engine manipulation.
The report also found that AI is transforming the ransomware landscape, with tools now used for social engineering, automated malware creation, and large-scale attacks on high-value organizations. CrowdStrike said this shift has enabled a new wave of attackers to launch “Big Game Hunting” campaigns across the region.
The surge in AI-enhanced ransomware attacks are evident in India, Australia, and Japan being among the most affected countries. New Ransomware-as-a-Service operators, including KillSec and Funklocker, were linked to more than 120 incidents, mostly targeting manufacturing, technology, and financial services sectors.
“Defenders must meet this new pace of attack with decisive action, powered by AI, informed by human experience, and unified in response,” Meyers said.