Tag: china
-
US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate
The Justice Department said that the domain seizures made the botnet and its command and control servers “inoperable,” as the domains were hardcoded into the botnet’s code and were critical for the botnet’s communication and essential operations. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
-
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through…
-
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
The FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinese-qtfy-us-infrastructure-fbi/
-
FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure
The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms linked to China, QScan and QTRouter. This court-authorized operation aims to disrupt attacks against U.S. critical infrastructure and sensitive government networks. Unsealed court documents from the Southern District of California revealed that these platforms were operated by a state-sponsored group…
-
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/fbi-disrupts-china-linked-hacking-network/
-
FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/fbi-seizes-china-linked-qscan-and-qtrouter-platforms-used-to-target-u-s-critical-infrastructure
-
Officials disrupt Chinese espionage operation that hit multiple federal agencies
The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years. First seen on cyberscoop.com Jump to article: cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/
-
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need…
-
FBI, DOJ Seize Chinese Hacker Infrastructure on US Soil
QScan and QTRouter Used US-Registered Domains and Overseas Servers to Mask Operations. The FBI and DOJ seized domains supporting Chinese state-linked QScan and QTRouter infrastructure that used U.S.-registered services and compromised IoT devices to conceal attacks on federal agencies and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658
-
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. First seen on wired.com Jump to article: www.wired.com/story/fbi-disrupts-chinese-proxy-tools-used-in-mass-hacking-of-us-agencies-and-infrastructure/
-
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (å—京鑫玖维网络科技有é™å…¬å¸).&…
-
US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries. First seen on therecord.media Jump to article: therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools
-
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
-
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
Mysterious Ox Alpha Stealth AI Model Emerges for Coding and Agentic Work
A newly discovered AI system called Ox Alpha has emerged on OpenRouter, sparking widespread speculation within the AI community regarding its origin, technical capabilities, and potential connections to major Chinese or Western model developers. Released on Thursday as a free preview model, Ox Alpha is described on OpenRouter as “a reasoning model designed for coding,…
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate…
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an…
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing infrastructure. According to Unit 42, the actor tracked under the aliases knaithe and KnYuan built an AI-assisted offensive environment that combined DeepSeek’s reasoning capabilities with Hermes Agent’s terminal access,…
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services
SilkParasite, a long-running cyberespionage operation targeting government bodies across Central Asia through a compact but highly mature arsenal of remote access trojans. Assessed with medium confidence as China-nexus activity, the campaign stands out for using Google Drive as a command-and-control channel, allowing malware traffic to blend into cloud activity that many enterprises inherently trust. The…
-
T-Mobile cybersecurity staff cut cable to expel Chinese hackers
First seen on scworld.com Jump to article: www.scworld.com/brief/t-mobile-cybersecurity-staff-cut-cable-to-expel-chinese-hackers
-
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments. First seen on therecord.media Jump to article: therecord.media/china-cyber-espionage-central-asia
-
China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure”, Is the US Ready?
This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon First seen on wired.com Jump to article: www.wired.com/story/china-is-strapping-digital-bombs-to-civilian-infrastructure-is-the-us-ready/
-
China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure”, Is the US Ready?
This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon First seen on wired.com Jump to article: www.wired.com/story/china-is-strapping-digital-bombs-to-civilian-infrastructure-is-the-us-ready/
-
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
-
Spionage aus China: T-Mobile US soll Cyberangriff mit Schere bekämpft haben
Chinesische Hacker hatten sich 2024 tief in die Infrastruktur von US-Providern eingenistet. T-Mobile hat für die Cyberabwehr wohl sogar ein Kabel durchgeschnitten. First seen on golem.de Jump to article: www.golem.de/news/spionage-aus-china-t-mobile-us-soll-cyberangriff-mit-schere-bekaempft-haben-2608-212119.html
-
T-Mobile Physically Cuts Network Cable to Evict Chinese Salt Typhoon Hackers
In 2024, T-Mobile’s security team took an unusually direct approach to contain a cybersecurity threat: they physically cut a network cable to terminate suspected access by the Chinese state-backed hackers known as Salt Typhoon. According to CSN, this action came after months of incident response efforts within T-Mobile’s network, during which defenders investigated signs of…
-
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
The U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/

