Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: China

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

auto_post, september 22, 2026september 25, 2026

Volgens berichten heeft de groep UTA0565 begin september 2026 een keten van zero-days in Google Chrome en Windows gebruikt via nepwebsites om malware (CLEANGULP) te installeren. Dit laat zien dat ons basisverhaal — dat een browserlek op zichzelf beperkt blijft — niet altijd opgaat: wanneer meerdere kwetsbaarheden worden gecombineerd, kunnen…

Continue Reading

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

post, augustus 26, 2026september 4, 2026

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei…

Continue Reading

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

post, juli 23, 2026juli 27, 2026

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it…

Continue Reading

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection

post, april 7, 2026april 10, 2026

A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure. Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks. Unlike…

Continue Reading

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks

post, maart 26, 2026maart 27, 2026

A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as…

Continue Reading

Chinese state hackers target telcos with new malware toolkit

post, maart 5, 2026maart 9, 2026

A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. According to Cisco Talos researchers, the adversary is closely associated with the FamousSparrow and Tropic Trooper hacker groups, but is tracked as a separate activity cluster. This assessment…

Continue Reading

Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users

post, februari 2, 2026februari 2, 2026

The maintainer of Notepad++ has revealed that state-sponsored attackers hijacked the utility’s update mechanism to redirect update traffic to malicious servers instead. “The attack involved [an] infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org,” developer Don Ho said. “The compromise occurred at the hosting…

Continue Reading

Chinese State-Sponsored Threat Actors Used Anthropic’s Claude To Automate Global Cyberattacks

post, november 14, 2025november 17, 2025

Anthropic has disclosed a large-scale cyber operation in which a China-aligned threat actor leveraged the Claude Code model to automate exploitation, credential harvesting, and data exfiltration across approximately 30 global targets. The incident represents one of the first documented cases in which an LLM with agentic capabilities was weaponized to…

Continue Reading

Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year

post, oktober 14, 2025

Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity, per ReliaQuest, is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and…

Continue Reading

Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware

post, september 30, 2025oktober 3, 2025

Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42…

Continue Reading
  • 1
  • 2
  • …
  • 5
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes