Kazakhstan and Geedge
Based on the leaked documents, Kazakhstan appears to be Geedge’s first customer. Their
relationship begins around the time Kassym-Jomart Tokayev, who began his career as a
diplomat in China in the Soviet embassy in Beijing, was elected president in 2019.
Geedge’s product Tiangou Secure Gateway (TSG) is capable of implementing an attack
similar to the government-issued root certificate,26 which might have been a selling point
for Geedge’s initial approach to the Kazakhstan government.
An image dated October 16, 2020, lists IP addresses for a national center and 17 other
cities running three separate Geedge products: Bifang (central management), Galaxy (the
original name for TSG-Galaxy), and Nezha (an older name for Network Zodiac).27 An
incomplete network planning document from Geedge begins to record events related to a
Kazakh national center in September 2020. The log collects events until October 2022 and
includes a table listing revisions to the project, including the date, version number, changes
made, and the author responsible for each update.
Additionally, Amnesty International obtained this OSINT information about Geedge
shipments to Kazakhstan and shared this with the larger consortium. The data behind
these shipments was obtained from commercial trade aggregator websites. The shipment
data consists of two records, 25 September 2024, 21 October 2024 from China to
Kazakhstan. Both were received by Kazakhstan company, TOO TJJ-Company.28 One
shipment record identified the shipped products as “optical bypass protectors”. While TJJCompany appears to still be active, their mail server went offline a few months after
receiving these shipments and, at the time of the report, their website (tjj[.]kz) is no longer
available. The archive of their website, however, says their specialists participated in the
development and implementation of the “Cyber Shield of Kazakhstan”.29 A former TJJ
employee, who worked as a project manager until May 2024, lists responsibilities at the
company that include, “creating a successful integrated network security system including
deep packet inspection.”