Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware auto_post, september 22, 2026september 25, 2026 Volgens berichten heeft de groep UTA0565 begin september 2026 een keten van zero-days in Google Chrome en Windows gebruikt via nepwebsites om malware (CLEANGULP) te installeren. Dit laat zien dat ons basisverhaal — dat een browserlek op zichzelf beperkt blijft — niet altijd opgaat: wanneer meerdere kwetsbaarheden worden gecombineerd, kunnen… Continue Reading
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations post, augustus 26, 2026september 4, 2026 The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei… Continue Reading
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks post, juli 23, 2026juli 27, 2026 An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it… Continue Reading
New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection post, april 7, 2026april 10, 2026 A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks. Unlike… Continue Reading
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks post, maart 26, 2026maart 27, 2026 A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as… Continue Reading
Chinese state hackers target telcos with new malware toolkit post, maart 5, 2026maart 9, 2026 A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. According to Cisco Talos researchers, the adversary is closely associated with the FamousSparrow and Tropic Trooper hacker groups, but is tracked as a separate activity cluster. This assessment… Continue Reading
Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users post, februari 2, 2026februari 2, 2026 The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility’s update mechanism to redirect update traffic to malicious servers instead. “The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” developer Don Ho said. “The compromise occurred at the hosting… Continue Reading
Chinese State-Sponsored Threat Actors Used Anthropic’s Claude To Automate Global Cyberattacks post, november 14, 2025november 17, 2025 Anthropic has disclosed a large-scale cyber operation in which a China-aligned threat actor leveraged the Claude Code model to automate exploitation, credential harvesting, and data exfiltration across approximately 30 global targets. The incident represents one of the first documented cases in which an LLM with agentic capabilities was weaponized to… Continue Reading
Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year post, oktober 14, 2025 Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity, per ReliaQuest, is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and… Continue Reading
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware post, september 30, 2025oktober 3, 2025 Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42… Continue Reading