Tag: china
-
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts.The multi-stage campaign, codenamed Operation DragonReturn by Seqrite Labs, involves sending spear-phishing emails impersonating the Income Tax Department of India. First seen on thehackernews.com…
-
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried? First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/chinese-llms-broaden-gap-between-attackers-and-defenders
-
Alibaba Reportedly Bans Claude Code Over Alleged Backdoor Risk in AI Coding Tool
Alibaba is reportedly preparing to ban the use of Anthropic’s Claude Code across its internal environments starting July 10. This decision comes in light of allegations that the AI-powered coding assistant has a covert detection mechanism resembling a backdoor. The news, first reported by the Chinese financial outlet Yicai and later confirmed by Reuters, has…
-
Cryptohack Roundup: Chinese Fraudster Gets 30 Years in Prison
Also: Hollywood Director Jailed for $11M Fraud. This week, a Chinese fraudster got 30 years, Hollywood director jailed for $11M fraud, Florida crypto scam plea, China jailed five in FX case, South Korea fines Bithumb, Thailand hunted mining suspect, Poland arrested SIM swappers, Emurgo planned recovery, South Korea targeted manipulators. First seen on govinfosecurity.com Jump…
-
MeetingTV Sues Palo Alto Networks Over Koi Threat Report
Tags: ai, china, cybercrime, cybersecurity, infrastructure, intelligence, malware, network, threat, toolMeetingTV Says Koi’s AI Analysis Tool Wrongly Tied it to Malware Infrastructure. MeetingTV alleges an AI-assisted threat intelligence report published by Koi Security falsely linked its infrastructure to a Chinese cybercrime operation, while Koi parent Palo Alto Networks argues the report reflects protected cybersecurity analysis rather than actionable false statements. First seen on govinfosecurity.com Jump…
-
FCC Bans Chinese-Produced Network Equipment Linked to Cyber and Espionage Risks
The U.S. Federal Communications Commission (FCC) has implemented comprehensive new restrictions banning the import and marketing of Chinese-produced telecommunications and surveillance equipment identified as posing significant cybersecurity and espionage risks. Announced on June 26, 2026, this updated regulation addresses a longstanding loophole that previously allowed companies on the FCC’s “Covered List” to continue selling older,…
-
China-Linked Group Targets Southeast Asia Critical Systems
The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/china-linked-group-targets-southeast-asia-critical-systems
-
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
Read more in my article on the Hot for Security blog. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/usb-drives-carrying-china-linked-malware-infected-japanese-military-networks-for-nearly-a-year
-
Iran, Russia, China Target Water Systems for Sabotage
Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation, not sophisticated malware. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage
-
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with First seen on thehackernews.com Jump…
-
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App.The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation First seen on thehackernews.com Jump to article: thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
-
China’s Zhipu AI Model GLM-5.2 Detects Software Vulnerabilities Like Claude Mythos
Zhipu AI’s newly released GLM-5.2 model is attracting significant attention from the cybersecurity community due to its vulnerability detection capabilities, which are comparable to those of Anthropic’s restricted Claude Mythos system. This development raises new concerns about the effectiveness of U.S. export control policies on advanced artificial intelligence. Released on June 13, 2026, under a…
-
Chinese APT CL1062 targets Southeast Asia with new TinyRCT backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-apt-cl-sta-1062-targets-southeast-asia-with-new-tinyrct-backdoor
-
Malware-Laced USBs Breach Japanese Military Networks
Reused USB Drives Linked to China Spread Malware to Private Sector. Counterfeit flash drives embedded with a Chinese-linked computer virus and used by the Japanese army are now dispensing malware throughout other secure networks in the country. The virus went overlooked until February 2025, when military personnel reported slower device speeds. First seen on govinfosecurity.com…
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
Chinese Development Framework Linked to Global Scam Infrastructure
More than 236,000 scam domains were linked to the legitimate DCloud Uni-App framework. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chinese-development-framework-linked-to-global-scam-infrastructure/
-
Chinese Development Framework Linked to Global Scam Infrastructure
More than 236,000 scam domains were linked to the legitimate DCloud Uni-App framework. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chinese-development-framework-linked-to-global-scam-infrastructure/
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo…
-
Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran
Water and wastewater systems have become strategic gray”‘zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational”‘technology (OT) defenses that make these utilities easy to probe and exploit. Internet”‘facing human”‘machine interfaces (HMIs), exposed programmable logic controllers (PLCs), default credentials, and poor IT/OT segmentation create low”‘cost access paths whose impact is disproportionately…
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified information. According to findings reported by Nikkei, these compromised USB devices were acquired at significantly lower costs through unofficial channels. They were subsequently…
-
China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor
A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/china-hackers-asian-cni-backdoor/
-
Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure
A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infrastructure across Southeast Asia during 2025. The recent campaign combines common open-source tooling with bespoke malware. Operators consistently leverage publicly available utilities SoftEther VPN for tunneling, VNT and yuze for covert command-and-control,…
-
AI Firms Seek US Help Against China Model Distillation
Anthropic Says Legal Gaps Leave Frontier Labs Vulnerable to LLM Copying. U.S.-based AI companies are urging the U.S. government to crack down on alleged illicit model distillation by Chinese AI developers, arguing current protections lack enforcement. Anthropic and others say legal reforms and clearer antitrust rules are needed to deter theft of frontier AI models.…
-
Microsoft Weighs DeepSeek for Copilot Amid Security Debate
Lower-Cost AI Model Could Cut Agent Costs But Raise Enterprise Risks. Microsoft is testing alternative AI models, including China’s DeepSeek v4, to reduce the cost of running Copilot Cowork’s agentic workloads. While cheaper inference pricing could appeal to enterprises, security experts warn that governance, validation and oversight costs may offset any savings. First seen on…
-
Microsoft Weighs DeepSeek for Copilot Amid Security Debate
Lower-Cost AI Model Could Cut Agent Costs But Raise Enterprise Risks. Microsoft is testing alternative AI models, including China’s DeepSeek v4, to reduce the cost of running Copilot Cowork’s agentic workloads. While cheaper inference pricing could appeal to enterprises, security experts warn that governance, validation and oversight costs may offset any savings. First seen on…
-
Chinese Cyber Operations Shift From APT Groups to Composite Responsibility Model
Chinese state-linked cyber activity has moved decisively away from the neat, single-actor narratives that dominated early attribution toward an ecosystem model in which responsibility is distributed across military units, intelligence services, private firms, and criminal-style intermediaries. Official advisories characterized some companies as providers of cyber-related products and services to Chinese intelligence; the UK’s NCSC said…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
Tags: ai, android, attack, china, cyber, defense, intelligence, international, malware, supply-chain, threatSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter OptinMonster supply chain attack hits 1.2 million sites Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Rokarolla : Android Banker with Complete Device…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 102
Tags: ai, android, attack, china, cyber, defense, intelligence, international, malware, supply-chain, threatSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter OptinMonster supply chain attack hits 1.2 million sites Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Rokarolla : Android Banker with Complete Device…
-
JPMorgan Pulls Anthropic Claude Access in Hong Kong
Restrictions Highlight Growing U.S.-China AI Security Tensions. JPMorgan Chase removed Anthropic’s Claude models from its approved AI platform for employees in Hong Kong, following restrictions tied to Greater China access rules and underscoring how U.S. export controls and geopolitical concerns are reshaping enterprise AI adoption in global financial markets. First seen on govinfosecurity.com Jump to…
-
CISA Urges OT Resilience in Dark Remarks About Cyberattacks
Tags: banking, china, cisa, cyber, cyberattack, defense, infrastructure, Internet, military, resilience, russia, serviceVital Service Providers Need a Plan to Work Through Internet Outages, CISA Says. Critical U.S. infrastructure like water, power and even banking systems will be successfully hacked by enemy cyber warriors in the event of a military confrontation with a peer adversary like Russia or China, officials from the nation’s civilian cyber defense agency said.…

