Tag: china
-
Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer…
-
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape. Rather than deploying the country’s more familiar banking malware, the attackers are…
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.Check Point Research said it has tracked the campaign since mid-2025.The modules First seen on…
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
ey Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor firstdocumentedtargeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, and familiar offensive utilities.…
-
China-linked campaign targets high-value networks, critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/fire-ant-campaign-targets-high-value-networks-and-critical-infrastructure
-
Suspected Chinese actor targets Philippine nuclear and naval entities using known vulnerabilities
First seen on scworld.com Jump to article: www.scworld.com/brief/suspected-chinese-actor-targets-philippine-nuclear-and-naval-entities-using-known-vulnerabilities
-
China’s ‘Fire Ant’ campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant “didn’t just compromise systems,” according to researchers. “It compromised the trust layer those systems depend on.” First seen on therecord.media Jump to article: therecord.media/router-hacks-fire-ant-group-china
-
China-Linked Hackers Turn Cisco Routers Into Covert Network Gateways
China-linked Fire Ant hackers compromised Cisco IOS XR routers, management hosts, and authentication systems to create covert paths into other networks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-fire-ant-hackers-cisco-ios-xr-routers/
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
-
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese…
-
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted.Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department…
-
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints. First seen on wired.com Jump to article: www.wired.com/story/microsoft-teams-is-becoming-a-haven-for-chinese-scammers/
-
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of First…
-
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.The implants, named SPEAKINGSTONE and DARKLANTERN by the company’s zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233. First seen…
-
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT) to targets likely associated with Chinese academic and technical research environments. The attack uses a custom 32-bit Go loader that performs sandbox checks, opens a legitimate-looking Word document as a decoy, and…
-
Chinese Routers Sold Worldwide Contain Backdoors
An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve
U.S. authorities have disabled two hacking platforms allegedly operated by a China-based company whose customers included Chinese intelligence and military organizations, disrupting a cyber campaign that targeted major U.S. government agencies and critical infrastructure. The Justice Department and FBI seized domains supporting QScan and QTRouter, two platforms operated by a state-sponsored hacking group known as..…
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
FBI Seizes Domains Behind China-Linked Hacking Operation
The FBI and DOJ seized QScan and QTRouter domains allegedly used by China-linked hackers to target U.S. agencies and critical infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-fbi-china-hacking-qscan-qtrouter-takedown/
-
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Compromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/federal-authorities-disrupt-china-hacking-US-critical-infrastructure/828913/
-
Chinese and Russian spies stepping up cyberattacks, German companies report
Foreign intelligence services, particularly those from China and Russia, are increasingly behind cyberattacks on German companies, according to a new survey of the country’s private sector. First seen on therecord.media Jump to article: therecord.media/germany-cyberattacks-china-russia

