#china-linked


China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Sep 15, 2026 // 11:32

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver […]

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

Sep 11, 2026 // 10:19

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to […]

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Aug 31, 2026 // 12:10

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access […]

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

Aug 27, 2026 // 00:40

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to […]

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

Aug 14, 2026 // 11:13

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. […]

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Aug 10, 2026 // 19:55

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of […]

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

Jul 8, 2026 // 13:36

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing […]

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

Jun 16, 2026 // 14:21

Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. “The Windows variants discovered are […]

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Jun 12, 2026 // 21:27

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login […]

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Jun 10, 2026 // 19:16

Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. “The JDY botnet comprises over […]

1 2 Next