The Great Firewall of China (GFW) has suffered the largest internal data leak in its history. Over 500 GB of sensitive material, including source code, working files, configuration files, and internal communications, were extracted and published online.
See also: 45 domains reveal long-term cyberespionage by Salt Typhoon

The leak comes from Geedge Networks and the MESA Laboratory at the Institute of Information Engineering of the Chinese Academy of Sciences.
The leaked file reveals GFW’s R&D workflows, development processes, and tracking models used in Xinjiang, Jiangsu, and Fujian provinces, as well as export deals under China’s “Belt and Road” initiative to Myanmar, Pakistan, Ethiopia, Kazakhstan, and other undisclosed countries.
Analysts warn that revealing internal components, such as the DPI engine, packet filtering rules, and update signing certificates, will allow for both evasion techniques and a deep understanding of censorship tactics.
Given the sensitivity of the leak, obtaining or analyzing this data poses significant security and legal risks. The files may contain proprietary encryption keys, monitoring setup scripts, or malicious installers that could enable remote monitoring or defensive countermeasures.
See also: US: Malware campaign targets trade talks with China

Researchers must adopt strict operational security protocols:
- Analyze inside an isolated virtual machine or sandbox with no internet connection that runs minimal services.
- Use network-level packet capture and snapshot-based recovery to detect and mitigate malicious payloads.
- Always verify file hash values (SHA-256 provided in mirror/filelist.txt) before exporting.
- Avoid executing binaries or running build scripts without code review. Many objects include custom kernel modules for deep package inspection that could compromise system integrity.
The obfuscation techniques discovered in mesalab_git.tar.zst use polymorphic C code and encrypted configuration blocks. Reverse engineering without a secure lab infrastructure can enable anti-debugging routines.
See also: B30A: Nvidia is preparing a new AI chip for China

Researchers are encouraged to collaborate with trusted malware analysis platforms and disclose findings responsibly. This unprecedented leak provides the security community with an unusual look behind the opaque infrastructure of GFW.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
