Skip to content

Threat actor

Geedge Networks

Last fetched

Geedge Networks is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Geedge Networks is a Chinese cybersecurity firm that helped build China’s "Great Firewall" and now sells a commercialized version of that system abroad. Founded in 2018, the company’s Tiangou Secure Gateway can filter websites and apps, conduct real-time surveillance, throttle or shut down entire regions of the internet, pinpoint anonymous users, and automatically block circumvention tools such as VPNs and Tor. Leaked internal files show Geedge exporting these capabilities to authoritarian clients, including Kazakhstan, Ethiopia, Myanmar and Pakistan. In Pakistan, Geedge tech replaced Sandvine equipment in 2023 to create “WMS 2.0,” the country’s upgraded national firewall. Engineers at Geedge actively reverse-engineer popular privacy tools, listing commercial VPNs as “resolved” problems and rolling out blockers like the Psiphon detector deployed after Myanmar’s 2021 coup.

Techniques by tactic

No ATT&CK techniques are recorded for Geedge Networks in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Geedge Networks today — this states the absence of a published link, not that Geedge Networks has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Geedge Networks into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.