Tag: chinese

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months
News

Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

A five-month intrusion targeting a Russian IT service provider has been linked to a threat actor with ties to China, marking the hacking group's entry into the nation outside of Southeast Asia and South America. Symantec, owned by Broadcom, has linked the January–May 2025 activity to a threat actor it monitors as Jewelbug, claiming that it overlaps with clusters called CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs). Despite growing military, economic, and political ties between Moscow and Beijing over the years, the results indicate that China is still able to conduct cyber espionage operations in Russia. In a report shared with The Hacker News, the Symantec Threat Hunter Team claimed that attackers had access to software d...
China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions
News

China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions

Researchers studying cybersecurity have revealed Earth Alux, a new threat actor with ties to China that has targeted a number of important industries in the Asia-Pacific (APAC) and Latin American (LATAM) areas, including government, technology, logistics, manufacturing, telecommunications, IT services, and retail. In a technical analysis released Monday, Trend Micro researchers Lenart Bermejo, Ted Lee, and Theo Chen stated that the first time its activity was spotted was in the second quarter of 2023, and that at that time, it was primarily seen in the APAC area. It was also seen in Latin America around the middle of 2024. Countries like Thailand, the Philippines, Malaysia, Taiwan, and Brazil are among the main targets of the hostile group. The exploitation of weak services in on...
Chinese hackers also breached Charter and Windstream networks
News

Chinese hackers also breached Charter and Windstream networks

A Chinese state-backed threat group known as Salt Typhoon has expanded its list of hacked telecoms corporations to include more U.S. companies. This follows the December 30 confirmation by AT&T, Verizon, and Lumen that the hackers had been removed from their networks. The Salt Typhoon hackers obtained the voicemails, phone conversations, and text messages of the targeted persons, as well as the wiretap data of those under investigation by U.S. law enforcement, after breaking into their networks. In November, T-Mobile also revealed that, after connecting from the network of a connected landline provider, unidentified attackers had gained access to some of its routers through a network reconnaissance attempt read more about Chinese hackers also breached Charter and Windstream netw...
U.S. Proposes Ban on Connected Vehicles Using Chinese and Russian Tech
News

U.S. Proposes Ban on Connected Vehicles Using Chinese and Russian Tech

The People's Republic of China (PRC) and Russia are two countries whose technology and software are integrated into connected cars that the U.S. Department of Commerce (DoC) announced it is planning to outlaw. According to a news release from the Bureau of Industry and Security (BIS), the proposed rule focuses on software and hardware incorporated into the Automated Driving System (ADS) and Vehicle Connectivity System (VCS). These are the vital components that enable external connectivity and autonomous driving in networked cars via certain hardware and software. According to the government, malicious access to these networks might provide enemies the ability read more about U.S. Proposes Ban on Connected Vehicles Using Chinese and Russian Tech. Get up to date on the latest cy...
Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware
News

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware

Between 2021 and 2023, ransomware and data encryption assaults targeting government and critical infrastructure sectors worldwide have been attributed to threat actors suspected of having ties to China and North Korea. The cybersecurity companies SentinelOne and Recorded Future said in a joint report with The Hacker News that while one cluster of activity has been linked to the ChamelGang (also known as CamoFei), the second cluster overlaps with activity that has previously been linked to state-sponsored groups in China and North Korea. This includes the 2022 CatB ransomware assaults by ChamelGang against the All India Institute of Medical Sciences (AIIMS) and the Brazilian Presidency, in addition to strikes on an East Asian government and an Indian subcontinent aviation company. ...
Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries
News

Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries

Details about Unfading Sea Haze, a previously unreported threat group that is thought to have been operational since 2018, have been made public by cybersecurity researchers. Bitdefender claimed in a report provided with The Hacker News that the intrusion targeted high-level organizations in South China Sea countries, including military and government targets. Martin Zugec, technical solutions director at Bitdefender, stated that the research found a concerning pattern that went beyond the historical background and that it had so far identified eight victims. Notably, access to infiltrated systems was frequently restored by the attackers. This exploitation draws attention to a serious weakness in the form of shoddy credential hygiene and insufficient patching procedures for expos...
Chinese Nationals Arrested for Laundering $73 Million in Pig Butchering Crypto Scam
News

Chinese Nationals Arrested for Laundering $73 Million in Pig Butchering Crypto Scam

Two Chinese nationals who were detained have been accused by the U.S. Department of Justice (DoJ) for allegedly masterminding a pig slaughtering scheme that diverted at least $73 million from victims by using shell corporations. On April 12 and May 16, respectively, the people, Daren Li, 41, and Yicheng Zhang, 38, were taken into custody in Atlanta and Los Angeles. According to Deputy Attorney General Lisa Monaco, the foreign nationals are accused of spearheading a plot to launder money totaling at least $73 million connected to a global cryptocurrency investment scam. Li, Zhang, and their accomplices are charged by the prosecution with running an international gang that laundered money acquired through cryptocurrency investment frauds read more Chinese Nationals Arrested for Lau...
Malicious Ads on Google Target Chinese Users with Fake Messaging Apps
News

Malicious Ads on Google Target Chinese Users with Fake Messaging Apps

As part of an ongoing malvertising attack, Chinese-speaking users have been targeted by fraudulent Google advertising for restricted messaging apps such as Telegram. Malwarebytes' Jérôme Segura stated in a research released on Thursday that "the threat actor is abusing Google advertiser accounts to create malicious ads and pointing them to pages where unsuspecting users will download Remote Administration Trojan (RATs) instead." "Such programs give an attacker full control of a victim's machine and the ability to drop additional malware." It is important to note that the activity, known by the codename FakeAPP, is an extension of an earlier round of attacks that went after Hong Kong consumers who were looking for messaging apps like Telegram and WhatsApp read more Malicious Ads on G...
Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor
News

Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor

As part of a recently noticed effort, threat actors connected to the hacking group known as Patchwork have been seen targeting universities and research organizations in China. According to the KnownSec 404 Team, the action involved the usage of a backdoor known as EyeShell. Patchwork, also known as Operation Hangover and Zinc Emerson, is thought to be an Indian-affiliated threat organization. Active at least since December 2015, the group's attack chains have a specific target in mind and frequently target Pakistan and China with tailored implants like BAD NEWS via spear-phishing and watering hole attacks read more Patchwork Hackers Target Chinese Research Organizations Using EyeShell Backdoor. Stay informed with the best cybersecurity news and raise your cybersecurity awarenes...
NCSC Warns Against Chinese Cyber Attacks on Critical Infrastructure
News

NCSC Warns Against Chinese Cyber Attacks on Critical Infrastructure

A fresh piece of advice alerting the public to Chinese cyber activities targeting crucial national infrastructure networks in the US was released by the UK's National Cyber Security Centre (NCSC) and a number of other international security organizations. The dossier claims that linked threat actors from the People's Republic of China (PRC) used advanced strategies to avoid detection while engaging in destructive actions. These strategies might likewise be used for vital infrastructure outside the US. The threat actors initially acquired access by taking advantage of apps with a public interface read more NCSC Warns Against Chinese Cyber Attacks on Critical Infrastructure. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity...