#China
40 stories taggedChina.

Chinese-speaking crew UAT-10147 hits web servers with AI-built tools and a Linux rootkit
The group targets Windows and Linux servers across education, media, tech and gaming, with victims concentrated in Brazil, Bolivia, China, Canada and Vietnam.

FBI Probe Into Chinese Espionage Front Ensnares a Small Brisbane Consultancy
A legitimate Australian firm called Horizzen found itself flooded with job applications meant for a fake version of its business. That fake site was one of 13 seized by the US Department of Justice as part of an alleged Chinese espionage operation.

Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit
Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar, Mongolia and Pakistan.

New Zealand's spy agency says China is spying 'at scale'. Beijing says that's a lie.
New Zealand's national intelligence service named China as the only country conducting large-scale espionage on its soil. China's embassy fired back, calling the report fabricated and blaming 'anti-China forces' for orchestrating the claims.

Taiwan Says AI-Assisted Hackers Targeted Government Agencies in July
Taiwan's Ministry of Digital Affairs confirmed it detected an unusual wave of overseas cyber-attacks on government systems last month, describing the use of artificial intelligence by the attackers as a new kind of threat.

New Zealand's Spy Agency Says It Blocked a Chinese Observatory From Installing Satellite-Tracking Equipment on NZ Soil
The Purple Mountain Observatory, a Chinese government-linked research body, tried to set up ground-based space hardware in New Zealand through a local company that apparently had no idea the gear could gather intelligence useful to Beijing's military.

Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time
A single criminal outfit is running a massive cryptocurrency scam network with one hand and breaking into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor
Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

Trump Weighs AI Controls After OpenAI's Tools Broke Into Other Companies' Systems
OpenAI has admitted its AI tools acted outside their intended limits at least twice in a week. Now the White House is asking how much control the government should take over artificial intelligence, and what that means for the race against China.

Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families
Researchers link a spying campaign against Afghanistan, Kyrgyzstan and neighbours to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

Chinese Operator Turns DeepSeek Into a Self-Driving Hacker via Telegram
Unit 42 says an attacker gave one Telegram command and let an AI agent pick the targets, choose the exploits, and run the intrusion on its own.

Cheap TV streaming sticks are secretly clicking ads and pretending to be phones
Researchers say around 38,000 H96 Android TV boxes are pulling double duty as ad-fraud bots and residential proxies, funnelling roughly $50,000 a day to a mainland China outfit called the Fengwo Group.

Silver Fox Hackers Chain Three Vulnerable Drivers to Plant ValleyRAT on Japanese Factory
The Chinese crew abused legitimate but flawed Windows drivers to switch off security tools before dropping a remote-access trojan.