< ciso
brief />
Tag Banner

All news with #china nexus tag

240 articles

Weekly cybersecurity recap: espionage, AI, and breaches

⚠️ This week’s recap highlights major disruptions and ongoing campaigns, from an FBI takedown of a Chinese proxy network to AI agents and supply-chain failures. Coverage includes router backdoors, chained PaperCut flaws, malware delivered via fake CAPTCHAs, and the evolving tactics of China-linked actors like Fire Ant. Patch and verify trusted infrastructure controls to reduce risk.
read more →

DoJ Revises Statement on China-Linked Hacking Targets

🛡️ The U.S. Department of Justice corrected a prior press release to state several federal agencies were "among the targets" of QTFY, a China-linked threat actor, rather than confirmed victims. The update clarifies the government affidavit and follows disruptions by the FBI of domains tied to QTFY's tools. The actor, tied to Nanjing Xinjiuwei and allegedly funded by the MSS, provided reconnaissance and proxy services to enable espionage.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

AI accelerates attacks on exposed internet-facing servers

🔍 Cisco Talos reports a Chinese-speaking cybercrime group, tracked as UAT-10147, is using AI-driven tools to compromise internet-facing Windows and Linux web servers. Researchers found AI-generated operational guidance, tooling to refine exploits, and automation that accelerates post-access activity, with a target list of about 170,000 URLs. The group exploits publicly disclosed vulnerabilities for financially motivated goals like data theft and SEO fraud.
read more →

Weekly cyber recap: exploits, ransomware, and browser attacks

⚡ This week’s roundup highlights multiple active exploit chains, supply-chain ripple effects, and opportunistic attacks that abused exposed services and old vulnerabilities. Notable incidents include exploitation of a severe VMware vCenter directory-traversal flaw linked to a suspected China-nexus APT, a macOS Screen Sharing flaw used to drop crypto miners, and a Windows privilege-escalation zero-day deployed by Lazarus. The report emphasizes how access already present and weak assumptions about visibility continue to amplify small gaps into large intrusions.
read more →

Jewelbug hacks webmail, runs parallel crypto fraud

🛡️ Symantec attributes a dual campaign to the China-based Jewelbug group, which injected malicious scripts into a shared government webmail installation to compromise 15 tenants. The actors exfiltrated cookies and credentials, deployed the Antino backdoor and browser-stealing extensions, and used a separate infrastructure to run large-scale cryptocurrency fraud. Researchers found ties between espionage tooling and a fraud operation that used AI-generated pages, click-fraud bots, and fake exchange sites.
read more →

Leaked DarkSword kit exploited to target iOS

🛡️ Censys has identified a campaign run by an unknown Chinese-linked actor using a leaked version of the DarkSword exploit kit to target Apple iOS devices. The actor operated over 100 web properties, many impersonating AWS sign‑in pages, to host the toolkit and lure victims into watering‑hole attacks. Successful exploitation of iOS 18.4–18.7 triggers the DarkSword chain and deploys GHOSTBLADE modules to exfiltrate credentials and files. The infrastructure spans Hong Kong, Singapore, Japan, the US, Europe, and includes multiple admin panels and exposed tooling.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

Chinese actor used AI agent to automate exploit campaigns

🛡️ Palo Alto Networks' Unit 42 reports a Chinese-speaking actor leveraging DeepSeek through the open-source Hermes Agent to autonomously discover and exploit internet-facing systems. After a Telegram instruction, the agent selected public exploits, probed hundreds of targets, and conducted both autonomous and manual attacks against multiple products including Langflow, n8n, Marimo and NetScaler appliances. Researchers recovered session artifacts and recommend patching and removing unnecessary public access.
read more →

Cruciferra Crypter Enables Advanced BYOVD and Evasion

🛡️ Proofpoint reveals that the China-linked crypter Cruciferra is being used to deliver diverse RATs and stealers, employing advanced evasion like BYOVD-based EDR tampering, IAT unhooking, and a custom Process Ghosting variant. The service, advertised since fall 2025, offers polymorphic encryption and modular payload delivery via DLL side-loading, affecting sectors such as finance, healthcare, government, and education.
read more →

Hackers Abuse ViPNet Updates to Target Russian Agencies

🔍 Researchers at Kaspersky say an advanced threat actor, tracked as HelloNet, has abused the ViPNet update mechanism since at least May to deliver a loader and proxy targeting Russian organizations, including government agencies. Attackers dropped a malicious DLL (wtsapi32.dll, "HelloInjector") into the local ViPNet Update System to be sideloaded by the legitimate updater, gaining persistence and elevated privileges. The campaign delivers additional modules—HelloProxy, HelloExecutor, HelloCleaner, and a Rust-based HelloBackdoor—enabling command execution, file transfer, reconnaissance, and log removal. Kaspersky assigns low-confidence attribution to a Chinese-speaking APT and recommends close monitoring of systems running ViPNet, especially traffic on ports 5003, 5060, and 443.
read more →

Rival Chinese and Indian Cyber Espionage Hits Pakistan

🔒 SentinelLabs reports that suspected China- and India-linked cyber operators targeted multiple Pakistani law enforcement systems between February 2024 and April 2026, focusing on Balochistan Police. The compromise affected servers hosting biometric records, case files and tenant registrations, and included implants in a public Complaint Management System. Analysts linked PlugX, ShadowPad and Cobalt Strike to China-nexus activity and Remcos to a suspected India-nexus actor. The incidents underscore risks from centralized police IT systems and concentrated intelligence value.
read more →

Multiple nation-linked groups target Pakistani police

🛡️ Cybersecurity researchers disclosed sustained espionage targeting Pakistani law enforcement between February 2024 and April 2026, impacting Balochistan Police and other agencies. Compromised assets included network appliances, web servers for police applications, and a Fortinet FortiMail gateway, with a Complaint Management System used to host implants. Four threat clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, linking the activity to China- and India-nexus actors. The dual targeting by adversaries and partners underscores the high intelligence value of law enforcement systems.
read more →

New MODBEACON Rust RAT Uses gRPC Streaming

🛡️ QiAnXin attributes a new Rust-based remote access trojan named MODBEACON to the China-linked Silver Fox cluster. The memory-resident implant uses a modular, plugin-based architecture and leverages gRPC tunnel streaming with transport borrowed from open-source proxy tools (Xray/V2Ray) for its C2 channel. Distributors push the malware via counterfeit installers promoted through SEO poisoning and host C2 infrastructure on Amazon and Cloudflare CDNs.
read more →

Winning 54% of the Time: SOC Decisions and Threats

🎾 This week’s Threat Source reflects on decision-making in cybersecurity through a tennis analogy, arguing defenders need context and resilience rather than perfection. Cisco Talos details the China-nexus actor UAT-7810 expanding ORB networks by exploiting Ruckus and ASUS router vulnerabilities and deploying new backdoors like LONGLEASH and DOGLEASH. Additional briefs cover an AI-assisted ransomware incident, AirDrop/Quick Share flaws, a Tenda firmware backdoor, Estonia’s AI agent IDs, and new phishing and coinminer detections.
read more →

China-linked APT expands relay network and malware

🔍 Cisco Talos reports a China-nexus APT tracked as UAT-7810 has expanded a network of hijacked routers and devices called Operational Relay Boxes (ORBs) to hide other attackers' traffic. The group maintained a long-running LapDogs relay infrastructure and exploited unpatched Ruckus and ASUS router vulnerabilities to recruit devices. Researchers uncovered an upgraded backdoor, LONGLEASH, plus two new tools, DOGLEASH and JARLEASH, with evidence suggesting Chinese-speaking operators. Talos says the group's servers and malware remain active.
read more →

China‑Aligned Cluster Exploits Roundcube Mail Servers

🔒 New research from Proofpoint identified a suspected China-aligned cluster, tracked as UNK_MassTraction, exploiting vulnerable Roundcube webmail instances at US and Canadian universities. The attackers targeted physics and engineering departments using known Roundcube vulnerabilities to steal credentials, deploy webshells and establish persistent access. The campaign leveraged malicious JavaScript (IceCube) and exploited CVE-2025-49113 to load the VShell backdoor in memory, enabling lateral movement and espionage-focused intrusions.
read more →

Universities targeted via Roundcube zero‑day chain

🛡️ A suspected China-aligned threat cluster exploited patched and unpatched Roundcube webmail flaws to target physics and engineering departments at U.S. and Canadian universities. The campaign, tracked as UNK_MassTraction and first seen in May 2026, used CVE-2024-42009 XSS to steal credentials and a follow-up RCE CVE-2025-49113 to drop web shells or deploy VShell. The payload, dubbed IceCube, siphons credentials, 2FA tokens and cookies, then attempts persistent access via SquareShell or VShell.
read more →

Suspected China-Nexus Campaign Targets Indian Taxpayers

🛡️ Seqrite Labs uncovered a targeted multi-stage phishing operation, dubbed Operation DragonReturn, impersonating India's Income Tax Department to deliver a remote access trojan. First observed on May 18, 2026, the campaign uses carefully crafted bilingual lures, malicious PDF attachments, and a ZIP-based DLL side-loading chain to install persistence and exfiltrate sensitive financial and credential data. The activity shows links to China-hosted infrastructure and overlaps with known tax-themed threat groups.
read more →

Counterfeit USBs Infected JGSDF Networks Nearly Year

🔍 Leaked documents reveal that counterfeit USB flash drives carrying malware entered Japan's Ground Self-Defense Force (JGSDF) networks after being distributed during 2024 earthquake relief operations. The malicious drives, traced to sellers in China and priced below market rates, were discovered in February 2025 and found on over 50 computers, nearly half handling classified data. Investigators linked the malware to a strain previously associated with a China-linked hacking group, while authorities maintain the infection showed only self-replication behavior.
read more →