Chinese Spy Group Lures Energy Workers With Fake Australian News Site — Then Steals Everything They Type

A state-linked hacking group spent two months tricking employees at offshore energy companies into visiting a bogus news website that silently recorded their keystrokes.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: an offshore oil and gas drilling platform at dusk, surrounded by calm dark ocean water
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Chinese hacking group TA423, also known as Red Ladon, ran a cyber-espionage campaign from April through mid-June 2022 targeting Australian organisations and offshore energy firms in the South China Sea.
  • Attackers sent fake emails posing as staff from a fictional outlet called "Australian Morning News" to lure victims to a malicious website.
  • The site secretly ran a surveillance tool called ScanBox, which recorded everything visitors typed without installing any software on their computers.
  • A July 2021 US Department of Justice indictment linked TA423 to China's Hainan Province Ministry of State Security, the country's civilian intelligence agency.
  • Proofpoint and PwC jointly published the findings and say the group shows no signs of slowing down.

A China-linked espionage group spent roughly two months building a fake Australian news website for one purpose: get energy-sector workers to visit it, then quietly harvest their information.

The campaign, detailed jointly by Proofpoint and PwC, targeted employees at offshore energy companies operating in the South China Sea, alongside organisations inside Australia.

How did the hackers get in?

It started with a phishing email, a fake message designed to look trustworthy. Targets received notes with subject lines like "Sick Leave," "User Research" or "Request Cooperation," apparently sent by a journalist at something called the "Australian Morning News," who asked recipients to visit the website. That website was not real.

Clicking through took victims to australianmorningnews[.]com. The page looked plausible enough; its articles were lifted from the BBC and Sky News. While visitors read, the site was already running ScanBox in the background.

ScanBox is a surveillance toolkit written in JavaScript, the same programming language that makes ordinary websites interactive in your browser. It leaves nothing on your computer. No file is downloaded, no antivirus alarm fires. The code runs inside your browser tab, records everything you type, and sends that data back to the attackers.

Beyond keylogging, ScanBox quietly profiled each visitor: their operating system, browser version, installed plugins, and, through a web technology called WebRTC, their real IP address, even behind a corporate network gateway designed to hide it. Think of it as a silent intake form that visitors never agreed to fill out.

TA423, also tracked as Red Ladon and believed to operate from Hainan Island, China, is the group behind this. A July 2021 Department of Justice indictment found the group provides long-running support to the Hainan Province Ministry of State Security. Past victims span twelve countries across aviation, defence, biopharmaceutical and maritime industries.

Proofpoint's Sherrod DeGrippo said the group "specifically wants to know who is active in the region," with a sustained focus on naval and energy matters near Malaysia, Singapore, Taiwan and Australia. Despite the indictment, researchers say TA423 has not meaningfully slowed its operations. Our earlier story on UNC6508's year-long intrusion into US and Canadian research networks shows the same pattern: China-linked groups treat indictments as an administrative inconvenience.

Should you worry if you work in energy or government?

Yes, particularly if your role touches the South China Sea region. Emails asking you to visit an unfamiliar news site, especially ones with vague subject lines, are a serious warning sign. Close any tab you landed on by accident. Multi-factor authentication (MFA), where a login requires a code from your phone as well as a password, would not have stopped ScanBox running in a browser, but it limits what attackers can do with any credentials they collect. The more uncomfortable point is that browser-based tools like ScanBox bypass most endpoint defences entirely, which means network-layer monitoring is the control that actually matters here.

© 2026 Threat Vectr