Investigation: Russian censorship systems (TMCT) expose Chinese DPI signatures

Hacker News Top News

Summary

Investigation reveals that Russian TMCT internet censorship systems are generating blocking pages with Chinese characters, indicating the equipment is supplied by China Unicom.

No content available
Original Article
View Cached Full Text

Cached at: 06/05/26, 02:08 PM

# How Runet Became an Appendage of the Great Chinese Firewall — FreeNet Monster Source: https://freenet.monster/china-unicom.html?lang=en Since the beginning of 2026, Roskomnadzor has sharply intensified its blocking of foreign internet resources. Thousands of websites — from social networks to news portals — have become inaccessible to users in Russia. You can track the current availability status of popular resources from Russia on our Honest Monitoring (https://freenet.monster/) page. A few months ago, users of Russian internet providers began encountering a strange anomaly. When trying to open sites blocked by Roskomnadzor, instead of the standard "Access Restricted" banner or the provider's placeholder page, they suddenly got a white screen with a terse message in Chinese: **该URL已被列入黑名单** (Translated from Chinese: "This URL has been blacklisted") At first glance, this looked like a ridiculous configuration error by some local provider. But reports of mysterious Chinese characters on block screens started coming in from different regions of Russia and from clients of completely different telecom operators. We decided to investigate where this digital trail leads and how Chinese characters ended up inside the Russian sovereign traffic filtering system. ## The Trail Leads to China Unicom Analysis of HTTP response headers and IP routes showed that the requests were being blocked not by the providers' own servers. The page with Chinese characters was generated by TMCT (Technical Means of Countering Threats) hardware complexes. These are the same "black boxes" that Roskomnadzor installed at the nodes of all telecom operators in the Russian Federation in accordance with the "sovereign Runet" law. But why did the TMCTs start speaking the language of the Middle Kingdom? The answer lies in the origin of the equipment. The blocking text strings and HTML response structure matched exactly the standard behavior of deep packet inspection (DPI) systems supplied by the Chinese telecommunications giant **China Unicom**. Sometimes the equipment provider's signature is found directly in the HTTP response headers: **中国联通(China Unicom)**. **China Unicom (中国联通)** is one of China's three largest state-owned telecommunications companies. It serves over 320 million mobile subscribers and is a key developer and operator of the "Golden Shield" — a system of total internet censorship better known as the Great Firewall of China. ## The MSS Information Surveillance System The deployment of China Unicom's filtering systems in Russian infrastructure raises serious questions not only about censorship but also about security. In China, all state-owned operators, including China Unicom, are required by law to provide full access to their technology, data, and code to the Ministry of State Security of the PRC (MSS). This agency performs the functions of China's foreign intelligence and domestic counterintelligence. U.S. regulators have long taken note of this. The U.S. Federal Communications Commission (FCC) completely revoked China Unicom's license to operate in America and blacklisted the company as a threat to national security. The official reason given was: "The company's equipment and services are directly influenced and controlled by the Chinese government, creating extremely high risks of espionage, traffic interception, and unauthorized access to critical infrastructure by PRC state intelligence agencies." By purchasing and deploying deep packet inspection (DPI) hardware-software complexes from Chinese partners, Russian agencies have effectively installed Chinese-made backdoors on the main highways of Runet. Due to haste or engineer negligence, they didn't even bother to translate the default Chinese block templates into Russian, exposing the system's true creators. It is also possible that the situation is even simpler: there may actually be no "black boxes" at the nodes of Russian providers, and traffic is analyzed directly through filtering systems located in China. This is evidenced by the rather long round-trip time of requests, and it also explains the appearance of the original Chinese characters not as someone's negligence but as an inevitable pattern. ## The Digital Colonization of Runet The irony of the situation is that the concept of a "sovereign Runet" was created under slogans of achieving complete digital independence from foreign technologies. But reality turned out to be the opposite. Russia was unable to create its own reliable, high-performance solutions for filtering gigabit traffic flows across the entire country. Instead, TMCTs were built on the basis of Chinese hardware equipment that is in some way controlled by Chinese intelligence services. In an effort to shield its citizens from the global internet, Russian authorities have effectively turned Runet into a technological appendage of the Chinese internet network. ## Protection Against Censorship, Surveillance, and Espionage For users, this means that methods of bypassing blocks in Russia now face top-tier technologies. Ordinary old VPN protocols (PPTP, L2TP, OpenVPN, WireGuard) are easily detected and blocked by this equipment. That's why **FreeNet Monster** uses advanced protocols such as VLESS Reality. Reality is designed to completely disguise the VPN connection as a regular visit to a Russian website, leaving no digital signatures for blocking. With us, you can not only bypass Roskomnadzor's restrictions but also remain invisible to Chinese intelligence services. Stay free and don't let censorship limit you.

Similar Articles

@Saccc_c: Saw an interesting post on L站 about completely blocking CC Chinese users: "You can do triangulation by testing the network latency from the current machine to the US, Japan, and Southeast Asia, etc. This way, unless you run Claude directly on a US VPS, any disguise methods will be completely useless — after all, the speed of light cannot be faked." Indeed, if the test shows...

X AI KOLs Following

Discusses the technical method of triangulation by testing network latency to identify and block Chinese users from using AI services (like Claude).

@Khazix0918: https://x.com/Khazix0918/status/2072235797592658395

X AI KOLs Timeline

The article exposes that Anthropic secretly detects and marks Chinese users in Claude Code using steganography (modifying Unicode characters and separators in date strings) for account bans, sparking strong community concerns about privacy and trust.

@AISuperDomain: Breaking news! Claude Code allegedly has a built-in 'hidden backdoor' specifically designed to detect Chinese users. The reason for Claude account bans has finally been found!!! According to a Reddit leak: Starting from version 2.1.91, Claude Code checks whether the system timezone is Asia…

X AI KOLs Timeline

According to a Reddit leak, starting from version 2.1.91, Claude Code has a built-in hidden detection logic that checks system timezone, proxy URL, and modifies system prompt encoding methods, allegedly to specifically identify Chinese users, sparking serious concerns about developers' trust boundaries.

@xiangxiang103: Wow, Anthropic really dropped the ball this time. Someone dug up hidden code in the Claude Code binary — specifically designed to detect whether you're a Chinese user or routing through China. Not ordinary telemetry, but deliberately obfuscated, not mentioned in release notes, and completely unknown to users. The process goes like this: - Detects you...

X AI KOLs Timeline

Hidden code was discovered in the Claude Code binary that specifically detects Chinese users or proxy routes, and secretly modifies system prompts to add watermarks, sparking widespread concerns about trust in developer tools.