Tag: Cyber Espionage Campaign

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
News

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

A highly focused cyber espionage campaign has been traced to an advanced persistent threat (APT) group with ties to China. The adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks that targeted victims in China, India, and Turkey. According to Kaspersky, the action took place between November 2022 and November 2024. It has been connected to Evasive Panda, a hacker collective that goes by the names Bronze Highland, Daggerfly, and StormBamboo. It has been considered active since at least 2012. According to a detailed investigation by Kaspersky researcher Fatih Şensoy, the gang primarily carried out adversary-in-the-middle (AitM) attacks on certain victims. These included methods like storing encrypted portions of the malware on attack...
Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign
News

Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign

In mid-September 2025, Chinese state-sponsored threat actors employed AI technology created by Anthropic to carry out automated cyber attacks in a "highly sophisticated espionage campaign." The AI upstart stated that the assailants utilized AI's 'agentic' capabilities to an unparalleled extent, employing it not merely as a consultant but to carry out the cyberattacks directly. The operation is evaluated as having exploited Claude Code, the AI coding tool from Anthropic, in an effort to breach approximately 30 worldwide targets that include major tech firms, financial organizations, chemical manufacturing companies, and government bodies. Some of these intrusions were successful. Since then, Anthropic has prohibited the relevant accounts and implemented defensive measures to identify...
Winnti APT41 Targets Japanese Firms in RevivalStone Cyber Espionage Campaign
News

Winnti APT41 Targets Japanese Firms in RevivalStone Cyber Espionage Campaign

A new campaign called RevivalStone, which targeted Japanese corporations in the manufacturing, materials, and energy sectors in March 2024, has been traced to the China-affiliated threat actor Winnti. According to the Japanese cybersecurity firm LAC, the behavior is similar to a threat cluster that Trend Micro tracks under the name Earth Freybug, which has been determined to be a subset of the APT41 cyber espionage organization; Cybereason tracks under the name Operation CuckooBees; and Symantec tracks under the name Blackfly. APT41 has been characterized as a very competent and systematic actor that can both contaminate the supply chain and launch espionage strikes. Its campaigns are frequently created with stealth in mind, employing a variety of strategies and a unique set of inst...
Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign
News

Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign

As part of a coordinated cyber espionage effort to extract sensitive data, nation-state threat actors supported by Beijing breached a "handful" of American internet service providers (ISPs), according to a Wall Street Journal story published on Wednesday. The behavior has been linked to a threat actor known by the handles FamousSparrow and GhostEmperor, which Microsoft tracks as Salt Typhoon. According to persons familiar with the situation, the journal quoted investigators as stating that they are investigating if the hackers were able to access Cisco Systems routers, which are essential network components that route a significant portion of internet traffic read more about Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign. Get up to date on the late...
RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations
News

RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations

An apparent state-sponsored threat actor with ties to China has been connected to a cyberespionage campaign that targeted diplomatic, academic, technological, and government entities in Taiwan from November 2023 to April 2024. Under the moniker RedJuliett, Recorded Future's Insikt Group is monitoring the activity and characterizing it as a cluster that runs in Fuzhou, China, to serve Beijing's intelligence gathering objectives concerning the East Asian nation. It's also monitored as Ethereal Panda and Flax Typhoon. The antagonistic group has also targeted the United States, Djibouti, Hong Kong, Kenya, Laos, Malaysia, the Philippines, Rwanda, and South Korea. Up to 24 victim organizations—including government institutions in Taiwan, Laos, Kenya, and Rwanda—have all been seen corre...