Cybercrime Man Helped Individuals in China Get Jobs Involving Sensitive US Government Projects Minh Phuong Ngoc Vong pleaded guilty to defrauding US companies of roughly $1 million in a fake IT worker scheme. Ionut ArghireApril 17, 2025
Nation-State Chinese APT Mustang Panda Updates, Expands Arsenal The Chinese state-sponsored group Mustang Panda has used new and updated malicious tools in a recent attack. Ionut ArghireApril 17, 2025
Malware & Threats MITRE Hackers’ Backdoor Has Targeted Windows for Years Windows versions of the BrickStorm backdoor that the Chinese APT used in the MITRE hack last year have been active for years. Ionut ArghireApril 17, 2025
Malware & Threats Enhanced Version of ‘BPFDoor’ Linux Backdoor Seen in the Wild In recent attacks, the state-sponsored backdoor BPFDoor is using a controller to open a reverse shell and move laterally. Ionut ArghireApril 16, 2025
Nation-State China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games China accuses three alleged U.S. NSA operatives of cyberattacks targeting critical infrastructure and the Asian Games in Harbin. Associated PressApril 15, 2025
Nation-State China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report In a secret meeting between Chinese and US officials, the former confirmed conducting cyberattacks on US infrastructure. Eduard KovacsApril 11, 2025
Malware & Threats Hackers Could Unleash Chaos Through Backdoor in China-Made Robot Dogs An undocumented remote access backdoor in the Unitree Go1 Robot Dog allows remote control over the tunnel network and use of the vision cameras... Ryan NaraineApril 1, 2025
Government Despite Rip-and-Replace Efforts, FCC Suspects Banned Chinese Telecom Providers Still Active in US The FCC is investigating whether Chinese firms such as Huawei, ZTE and China Telecom are still operating in the US. Eduard KovacsMarch 24, 2025
Nation-State Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley The FishMonger APT group, a subdivision of Chinese cybersecurity firm I-Soon, compromised seven organizations in a 2022 campaign. Ionut ArghireMarch 21, 2025
Nation-State Mandiant Uncovers Custom Backdoors on End-of-Life Juniper Routers China-nexus cyberespionage group caught planting custom backdoors on end-of-life Juniper Networks Junos OS routers. Ryan NaraineMarch 12, 2025
ICS/OT China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days Dragos case study reveals that Volt Typhoon hacked the US electric grid and stole information on OT systems. Eduard KovacsMarch 12, 2025
Cyberwarfare US Indicts China’s iSoon ‘Hackers-for-Hire’ Operatives i-Soon employees charged with conducting extensive hacking campaigns on behalf of Beijing’s security services. Ryan NaraineMarch 5, 2025
Malware & Threats Chinese Botnet Powered by 130,000 Devices Targets Microsoft 365 Accounts A China-linked botnet powered by 130,000 hacked devices has targeted Microsoft 365 accounts with password spraying attacks. Eduard KovacsFebruary 25, 2025
Artificial Intelligence OpenAI Bans ChatGPT Accounts Used by Chinese Group for Spy Tools OpenAI has banned ChatGPT accounts used by Chinese threat actors, including ones leveraged for the development of spying tools. Eduard KovacsFebruary 24, 2025
Nation-State Cisco Details ‘Salt Typhoon’ Network Hopping, Credential Theft Tactics Cisco Talos observed Chinese hackers pivoting from a compromised device operated by one telecom to target a device in another telecom. Ryan NaraineFebruary 21, 2025
Nation-State How China Pinned University Cyberattacks on NSA Hackers A researcher dives into Chinese reports attributing cyberattacks on Northwestern Polytechnical University to the NSA’s TAO division. Ionut ArghireFebruary 21, 2025
Nation-State Salt Typhoon Targeting Old Cisco Vulnerabilities in Fresh Telecom Hacks China-linked APT Salt Typhoon has been exploiting known vulnerabilities in Cisco devices in attacks on telecom providers in the US and abroad. Ionut ArghireFebruary 14, 2025
Vulnerabilities New Windows Zero-Day Exploited by Chinese APT: Security Firm ClearSky Cyber Security says it has seen a new Windows zero-day being exploited by a Chinese APT named Mustang Panda. Eduard KovacsFebruary 14, 2025
Ransomware Chinese Cyberspy Possibly Launching Ransomware Attacks as Side Job A toolset associated with China-linked espionage intrusions was employed in a ransomware attack, likely by a single individual. Ionut ArghireFebruary 13, 2025
Artificial Intelligence Can AI Early Warning Systems Reboot the Threat Intel Industry? News analysis: The big AI platforms are emerging as frontline early warning systems, detecting nation-state hackers at the outset of their campaigns. Can this... Ryan NaraineFebruary 10, 2025