Skip to content

Threat actor

Landasoft

Last fetched

Landasoft is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Landasoft is a Shanghai-based private defense company and technology firm that contributes to China's mass surveillance infrastructure, particularly in the Xinjiang province. An Associated Press investigation revealed that the firm, which was a former partner of IBM, replicated IBM's i2 police analytics and launched its own platform to power the Integrated Joint Operations Platform (IJOP) in Xinjiang. Landasoft deployed software that scraped data from millions of cameras, police outposts, and personal records to build risk dossiers. The system categorized individuals using tags like "studied abroad" or "went on pilgrimage," computed risk scores, and enabled automatic “Push Alerts” to trigger detentions based on flawed predictions, often without human oversight. In one week in 2017 alone, IJOP flagged 24,412 people as "suspicious," leading to widespread detentions, with Uyghurs as a primary target.

Techniques by tactic

No ATT&CK techniques are recorded for Landasoft in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Landasoft today — this states the absence of a published link, not that Landasoft has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Landasoft into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.