Posts and conversations on Russian-language hacking forums indicate that Russian cybercriminals are seeking partnerships with Chinese hackers.

Security researchers have noticed that hackers on Russian-language hacking forums are seeking Chinese cybercriminals for collaboration.
See also: Chinese hackers behind attacks on ten Israeli hospitals?
These efforts to recruit Chinese hackers are primarily seen on the RAMP hacking forum, which encourages criminals who speak Mandarin to engage in conversations with Chinese, share tips, and collaborate on attacks.
Chinese users on Russian hacking forums
According to a new report by Flashpoint, well-known users and administrators of the RAMP hacking forum are attempting to communicate with new forum members in Chinese.
The forum reportedly had at least thirty new user registrations that appear to come from China, so this could be the beginning of possible collaborations between Russian and Chinese hackers.
Researchers suggest that Russian cybercriminals, and particularly ransomware gangs, may be seeking to form alliances with Chinese hackers to carry out attacks against US targets, exchange vulnerabilities, or even recruit new talent for Ransomware-as-a-Service (RaaS) operations.
A threat analyst told BleepingComputer that this initiative was started by a RAMP administrator known as Kajit, who claims to have recently spent some time in China and can speak the language.
See also: The Russian Nobelium hackers who hacked SolarWinds strike again!
In the past, he had stated that he would invite Chinese hackers to the forum, which seems to be happening now.
However, Russian cybercriminals attempting to collaborate with Chinese hackers are not limited to the RAMP hacking forum. Researchers have seen similar attempts at collaboration on the XSS hacking forum.
“ In the screenshot below, the XSS user, “hoffman,” welcomes two forum members who presented themselves as Chinese ,” explains the new Flashpoint research
"The language (Chinese) seems to come from some kind of translation system.".

However, previous incidents with RAMP administrators show that we cannot be sure about this presence of Chinese hackers on the forum and the collaboration with Russian ransomware gangs.
Last month, a RAMP administrator known as “Orange” or “boriselcin” published a post calling on threat actors to attack the US.
After the media covered this news, the hacker claimed that the operation was fake from the start and was created to troll the media and security researchers.
Therefore, in this case too we must be cautious about cooperation.
See also: Costco confirms it suffered a card skimming attack
However, the operators of the Conti ransomware recently posted on the RAMP hacking forum asking for collaborators. The gang said that they usually only work with Russian-speaking hackers, but make an exception for Chinese threat actors.
Therefore, it appears that the RAMP forum is actively inviting Chinese-speaking threat actors to participate in conversations and attacks.
RAMP continues to strengthen
Now that RAMP is back online, it seems to be going steadily stronger.
RAMP was created last summer by a key member of the original Babuk ransomware gang. It serves as a new place to leak valuable data stolen in cyberattacks and as a place to recruit ransomware collaborators.
Source: Bleeping Computer
