threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
threat-intel UK weakens proposed telecoms defenses against Chinese hackers after industry pushback The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter… The Record · Jun 9, 2026 High UKCHespionagetelecomscybersecurity
threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
threat-intel Tropical Blend: Cyber & Politics Ramp Up Across Latin America This report details a surge in cyber espionage activities targeting Latin American nations, primarily driven by China-linked Advanced Persistent Threat (APT) groups. These groups, including FamousSparrow and NegativeGlim… Dark Reading · Jun 3, 2026 High CHVEPAaptcyber espionagelatin america
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel As Global Powers Explore Humanoid Robots, Cyber-Risk Looms This article discusses the emerging cybersecurity risks associated with the rapid development and deployment of embodied AI, particularly humanoid robots. The core concern is that these systems, currently being developed… Dark Reading · May 28, 2026 High CHRUCAembodied aicyberespionagerobotics
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
apt UAT-8302 and its box full of malware Cisco Talos has identified UAT-8302, a China-nexus advanced persistent threat (APT) group, targeting government entities in South America and southeastern Europe. The group utilizes a range of custom malware families, in… Cisco Talos · May 5, 2026 High CVE-2025-0994BRCOCUchinaaptgovernment
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago