Tag: Chinese hackers

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
News

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

For over a year, a China-affiliated espionage outfit surreptitiously stole confidential research and defense emails from North American medical, academic, and military research networks. A backdoor on their REDCap research servers was used to gain access and steal login information. The interesting portion was the exfiltration, where the attackers copied each communication that matched their keywords to an inbox they controlled by rewiring the victims' own Google Workspace policies. In a study released this week, Google's Threat Intelligence Group (GTIG) described the effort and highly confidently linked it to a cluster it monitors as UNC6508. Google initially mentioned the actor and its REDCap backdoor in a broader study on state-sponsored attacks on the defense industry in Febr...
Chinese hackers use new Atlas RAT malware in European cyberattacks
News

Chinese hackers use new Atlas RAT malware in European cyberattacks

Using previously undiscovered malware and the Atlas backdoor, a Chinese-speaking cybercrime ring has extended its targeting to the European region. The threat actor, identified as TA4922, is linked to financially driven attacks that target networks in order to commit fraud, steal data, and sell access. While TA4922 has traditionally targeted East Asian organizations, more recent attacks have concentrated on organizations in Germany, Italy, the UK, and South Africa. TA4922 shares have similarities with behavior previously described as "Silver Fox" and "Void Arachne," according to researchers at cybersecurity firm Proofpoint. However, because it is more consistent with cybercrime than espionage, the activity cluster is monitored independently. The activity of TA4922 has expanded...
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware
News

Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware

As part of a state-sponsored campaign that began at least in 2020, a suspected cyber espionage operation based in China has targeted military groups in Southeast Asia. The threat behavior is being monitored by Palo Alto Networks Unit 42 under the code CL-STA-1087, where CL stands for cluster and STA for state-backed motivation. According to security researchers Lior Rochberger and Yoav Zemah, the behavior showed strategic operational patience and a focus on highly focused intelligence collection rather than bulk data theft. This cluster's attackers carefully sought out and gathered extremely specific files about military capabilities, organizational structures, and joint ventures with Western armed forces. The campaign demonstrates characteristics that are frequently linked to ad...
Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign
News

Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign

In mid-September 2025, Chinese state-sponsored threat actors employed AI technology created by Anthropic to carry out automated cyber attacks in a "highly sophisticated espionage campaign." The AI upstart stated that the assailants utilized AI's 'agentic' capabilities to an unparalleled extent, employing it not merely as a consultant but to carry out the cyberattacks directly. The operation is evaluated as having exploited Claude Code, the AI coding tool from Anthropic, in an effort to breach approximately 30 worldwide targets that include major tech firms, financial organizations, chemical manufacturing companies, and government bodies. Some of these intrusions were successful. Since then, Anthropic has prohibited the relevant accounts and implemented defensive measures to identify...
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
News

China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats

Between September and October 2025, a new round of assaults targeting European government and diplomatic institutions have been traced to a China-affiliated threat actor called UNC6384. These attacks take advantage of an unpatched Windows shortcut vulnerability. According to a technical assessment released Thursday by Arctic Wolf, the operation targeted government entities in Serbia as well as diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands. According to the cybersecurity firm, the attack chain starts with spear-phishing emails that have an embedded URL. This is the first of multiple steps that culminate in the delivery of malicious LNK files that are themed around meetings of the European Commission, workshops connected to NATO, and events involving multila...
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
News

CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks

Following indications of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity security weakness affecting VMware Aria Operations and Broadcom VMware Tools to its Known Exploited Vulnerabilities (KEV) list on Thursday. CVE-2025-41244 (CVSS score: 7.8) is the vulnerability in question, which an attacker might use to get root level privileges on a vulnerable system. According to a CISA alert, there is a privilege defined with dangerous actions vulnerability in Broadcom VMware Aria Operations and VMware Tools. This vulnerability allows a malevolent local actor with non-administrative credentials to get root access to a virtual machine (VM) that has VMware Tools installed and is managed by Aria Operations with SDMP enable...
OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks
News

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks

Three activity clusters were terminated by OpenAI on Tuesday for abusing its ChatGPT artificial intelligence (AI) tool to aid in the creation of malware. Among them is a Russian-speaking threat actor who allegedly utilized the chatbot to assist in the creation and improvement of a remote access trojan (RAT), a credential stealer designed to avoid detection. Additionally, the operator prototyped and debugged technical elements that facilitate credential theft and post-exploitation using multiple ChatGPT accounts. We saw that these accounts posted proof of their activity in a Telegram channel devoted to Russian-speaking criminal gangs, suggesting that these accounts are associated with those actors, according to OpenAI. Although the threat actor's direct requests for malicious cont...
Microsoft links Sharepoint ToolShell attacks to Chinese hackers
News

Microsoft links Sharepoint ToolShell attacks to Chinese hackers

A recent round of massive attacks targeting a Microsoft SharePoint zero-day vulnerability chain has implicated a number of hacker groups with connections to the Chinese government. After breaking into their on-premise SharePoint servers, they exploited this chain of exploits (named "ToolShell") to compromise dozens of companies throughout the globe. In a research released on Tuesday, Microsoft noted that it had seen two specific Chinese nation-state actors, Linen Typhoon and Violet Typhoon, take use of these flaws to target SharePoint systems that are accessible over the internet. Furthermore, we have seen that Storm-2603, a threat actor based in China, is taking advantage of these weaknesses. The use of these exploits by other actors is still being investigated. We conclude that...
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms
News

Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms

The French cybersecurity agency said Tuesday that a malicious campaign by a Chinese hacker group that weaponized multiple zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices affected several organizations in the country's governmental, telecommunications, media, finance, and transportation sectors. The campaign was discovered in early September 2024 and has been linked to a unique intrusion set nicknamed Houken. It is estimated that this intrusion set shares certain level overlaps with a threat cluster that Google Mandiant tracks under the designation UNC5174 (also known as Uteus or Uetus). According to the French National Agency for the Security of Information Systems (ANSSI), its operators use a variety of open-source tools, most of which were created by Chin...
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks
News

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

Cobalt Strike and VShell were delivered by a Chinese-speaking threat actor known as UAT-6382, who took advantage of a now-patched remote-code-execution vulnerability in Trimble Cityworks. In an investigation released today, Cisco Talos researchers Asheer Malhotra and Brandon White said that UAT-6382 effectively exploited CVE-2025-0944, carried out reconnaissance, and quickly installed a range of web shells and specially designed malware to sustain long-term access. After being granted access, UAT-6382 made it apparent that they wanted to switch to utility management systems. According to the network security firm, beginning in January 2025, it saw attacks on the enterprise networks of local government entities in the US. The deserialization of untrusted data vulnerability that af...