From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools

A threat actor associated with China has been identified as responsible for a cyber attack on a U.S. non-profit organization, aiming to achieve long-term persistence as part of a wider campaign targeting U.S. entities connected to or involved in policy matters.

A report from Broadcom’s Symantec and Carbon Black teams indicates that the organization is working to sway U.S. government policy on international matters. In April 2025, the attackers succeeded in accessing the network for several weeks.

On April 5, 2025, the first indication of activity was observed as mass scanning attempts were identified against a server using various established exploits, such as CVE-2022-26134 (Atlassian), CVE-2021-44228 (Apache Log4j), CVE-2017-9805 (Apache Struts), and CVE-2017-17562 (GoAhead Web Server).

According to Symantec and Carbon Black, who spoke with The Hacker News, there is no evidence that these attempts at exploitation were successful read more about From Log4j to IIS China’s Hackers Turn Legacy Bugs into Global Espionage Tools.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *