Chinese Government Hackers Infiltrate U.S Telecommunications Companies post, oktober 6, 2024oktober 7, 2024 A group of hackers linked to the Chinese government has infiltrated multiple US telecommunications companies in recent months, likely in an effort to access sensitive national security information. The hacking activity was first reported by The Wall Street Journal (WSJ). US investigators suspect that the hackers may have gained access… Continue Reading
Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign post, september 26, 2024september 26, 2024 Nation-state threat actors backed by Beijing broke into a “handful” of U.S. internet service providers (ISPs) as part of a cyber espionage campaign orchestrated to glean sensitive information, The Wall Street Journal reported Wednesday. The activity has been attributed to a threat actor that Microsoft tracks as Salt Typhoon, which is also… Continue Reading
Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware post, september 23, 2024 A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. “They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and… Continue Reading
Hackers breach ISP to poison software updates with malware post, augustus 3, 2024augustus 19, 2024 A Chinese hacking group tracked as StormBamboo has compromised an undisclosed internet service provider (ISP) to poison automatic software updates with malware. Also tracked as Evasive Panda, Daggerfly, and StormCloud, this cyber-espionage group has been active since at least 2012, targeting organizations across mainland China, Hong Kong, Macao, Nigeria, and various Southeast… Continue Reading
Japanese space agency spotted zero-day attacks while cleaning up attack on M365 post, juli 11, 2024juli 12, 2024 The Japanese Space Exploration Agency (JAXA) discovered it was under attack using zero-day exploits while working with Microsoft to probe a 2023 cyberattack on its systems. But the space org’s statement also revealed the discovery of malware found and removed by an actor other than Microsoft. And then there’s the… Continue Reading
Cybersecurity Agencies Warn of China-linked APT40’s Rapid Exploit Adaptation post, juli 9, 2024juli 3, 2025 Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release. “APT40 has previously… Continue Reading
CISA and Partners join ASD’S ACSC to Release Advisory on PRC State-Sponsored Group, APT 40 post, juli 8, 2024juli 3, 2025 CISA has collaborated with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) to release an advisory, People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action outlining a PRC state-sponsored cyber group’s activity. APT 40 has previously targeted organizations in various countries, including Australia and the United… Continue Reading
Chinese Cyberspies Employ Ransomware in Attacks for Diversion post, juni 27, 2024juli 3, 2025 Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft. A joint report from SentinelLabs and Recorded Future analysts presents the case of ChamelGang, a suspected Chinese advanced persistent threat (APT) that… Continue Reading
China-Linked Cyber-Espionage Teams Target Asian Telecoms post, juni 25, 2024februari 24, 2025 In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack. At least three cyber-espionage groups have compromised telecommunications operators in multiple countries in the Asia-Pacific region, placing backdoors inside the communications providers’ networks, stealing… Continue Reading
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021 post, juni 20, 2024februari 24, 2025 Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021. “The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials,” the Symantec Threat Hunter Team,… Continue Reading