Tag: china
-
Chinese hackers hijack auth flow, spy on isolated network for a decade
Chinese hackers took control of a target organization’s authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/
-
China-nexus group hid in Linux login system for nearly a decade
First seen on scworld.com Jump to article: www.scworld.com/brief/china-nexus-group-hid-in-linux-login-system-for-nearly-a-decade
-
FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage
First seen on scworld.com Jump to article: www.scworld.com/news/fbi-shuts-down-13-consulting-websites-used-for-suspected-chinese-espionage
-
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
Outsider provided phishing kits and infrastructure for cybercriminals to scam victims with lures claiming they missed packages, had unpaid tolls or parking violations. First seen on cyberscoop.com Jump to article: cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/
-
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
Outsider provided phishing kits and infrastructure for cybercriminals to scam victims with lures claiming they missed packages, had unpaid tolls or parking violations. First seen on cyberscoop.com Jump to article: cyberscoop.com/outsider-cybercrime-network-takedown-china-fbi-google-lumen/
-
Chinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by Google
The tech giant said a group called “Outsider Enterprise” used AI to scam hundreds of thousands of victims, sending 2.5 million text messages over a span of two weeks. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/
-
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself.Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary…
-
Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
Google on Friday said it’s pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans.The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant.”The operation weaponized Gemini…
-
Google Sues Chinese Phishing Service Over Gemini Abuse
Complaint Says Service Generated More Than 1.5 Million Malicious URLs. Google has sued a Chinese phishing-as-a-service provider accused of teaching customers to use Gemini to generate and customize scam websites, a campaign linked to more than 1.59 million phishing URLs, over 100,000 victims, and widespread credential and financial theft. First seen on govinfosecurity.com Jump to…
-
Google sues alleged Chinese cybercrime operation that used AI to send scam texts
The tech giant said a group called “Outsider Enterprise” used AI to scam hundreds of thousands of victims, sending 2.5 million text messages over a span of two weeks. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/12/google-sues-alleged-chinese-cybercrime-operation-that-used-ai-to-send-scam-texts/
-
Google sues China-based scammers over Gemini AI abuse
Google has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/12/google-china-based-cybercrime-network-lawsuit/
-
DOJ, FBI Seize 13 Domains in Chinese Recruitment Op
Fake Recruiting Sites Used for Info Gathering. The Department of Justice and FBI seized 13 websites tied to an alleged Chinese intelligence gathering operation, using fake recruiting firms and deceptive job offers to target current and former U.S. government employees and security clearance holders. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/doj-fbi-seize-13-domains-in-chinese-recruitment-op-a-31952
-
University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft
According to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, potentially including those in its foreign campuses in Malaysia and China as well as in Nottingham. First seen on therecord.media Jump to article: therecord.media/university-of-nottingham-cyber-incident-shiny-hunters
-
FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort
Federal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/11/fake-consulting-websites-target-us-security-clearance-holders-china/
-
JDY Botnet Evolves After KV Takedown, Targets Military Networks
JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The network was first spotted in late 2023 as a cluster inside KV-botnet. The U.S. government…
-
Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials
Chinese-language “guarantee” marketplaces hosted mainly on Telegram have become a core conduit for buying, selling, and laundering stolen credentials and a wide range of criminal services. These platforms modeled explicitly on consumer escrow systems such as Alipay’s æ‹…ä¿äº¤æ˜“ (dÄnbÇŽo jiÄoyì) operate as third-party guarantors: the marketplace operator holds buyer funds in escrow, releases them only…
-
China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits
A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices and now functions as a high-performance, centrally controlled scanner that accelerates vulnerability discovery…
-
Chinese APTs have made identity part of the intrusion path
First seen on scworld.com Jump to article: www.scworld.com/perspective/chinese-apts-have-made-identity-part-of-the-intrusion-path
-
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
North Korea’s gross domestic product (GDP) has grown, in part because of the cybercrime gains of groups linked to the nation, which target business and financial firms. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/chinese-korean-threat-groups-asia-pacific-success
-
FBI Seizes China-Linked Fake Consulting Sites Targeting US Clearance Holders
The Justice Department and FBI seized 13 fake consulting websites that officials say targeted US clearance holders with paid research work designed to obtain sensitive government information. First seen on hackread.com Jump to article: hackread.com/fbi-seizes-china-fake-consulting-sites-us-clearance/
-
‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
The company says there’s little evidence it influenced any real policy discussion. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-china-influence-campaign-chatgpt/
-
‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
The company says there’s little evidence it influenced any real policy discussion. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-china-influence-campaign-chatgpt/
-
TechnologyLandscape-Report 2026: China stiehlt KI-Kompetenzen, die es selbst nicht entwickeln kann
Crowdstrike veröffentlicht den <>, der aufzeigt, dass China-nahe Angreifer ihre Spionageaktivitäten gegen Technologieunternehmen ausweiten, um KI-Kompetenzen und geistiges Eigentum zu stehlen, die sie selbst nicht schnell genug entwickeln können. Da die weltweit wertvollsten KI-Ressourcen in Technologieunternehmen konzentriert sind, ist der Sektor inzwischen die am stärksten ins Visier genommene Branche der Welt. […] First seen on netzpalaver.de…
-
IT sector faces growing threats from IP-hungry China, AI-enabled cybercriminals
Businesses also need to watch out for North Korean remote IT worker schemes, according to a new CrowdStrike report. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/china-cyberattacks-it-sector-crowdstrike-report/822366/
-
The security questions around Chinese AI coding models in U.S. software
Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/09/chinese-ai-coding-models-security/
-
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems.The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking…
-
China-Linked OP-512 Targets IIS Servers With Unique Web Shell Framework
A suspected China-linked espionage cluster dubbed OP-512 after rapidly correlating many low-fidelity events into a single high-priority incident that human analysts then validated. OP-512 compromised an Internet Information Services (IIS) server and deployed a custom web shell framework built to evade signature-based detection. Each web shell instance is cryptographically unique, restricts access with layered encryption,…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 100
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Malware Targeting WordPress Abuses Steam Community Profiles for Command & Control Operations Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan…
-
Chinese Spies Using LinkedIn, Job Sites to Recruit Western Workers
Five Eyes agencies warn that fake online recruiters linked to Chinese intelligence are targeting workers for sensitive policy and defense information. The post Chinese Spies Using LinkedIn, Job Sites to Recruit Western Workers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-five-eyes-fake-recruiters-chinese-intelligence/
-
Crypto-Funded Chinese Peptide Labs Are Booming
Plus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-crypto-funded-chinese-peptide-labs-are-booming/

