Threats Affecting China
View all threats affecting or targeting China. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting China
Click on any threat for detailed analysis and mitigation recommendations
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o... Join the discussion | AlienVault OTX General | 09/16/2026, 09:45:38 UTC Added: 09/16/2026, 12:31:39 UTC |
An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives. Join the discussion | AlienVault OTX General | 09/03/2026, 07:26:56 UTC Added: 09/03/2026, 07:52:49 UTC |
A malware campaign uses counterfeit software-download websites impersonating trusted vendors to distribute malicious installers. The activity primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Malicious installers deploy payloads that establish persistence, disable security protections, and communicate with attacker-controlled infrastructure. The campaign employs dynamically generated installers with rotating hashes, spoofed vendor pages on .com.cn and .hl.cn domains, and randomized payload staging paths. Follow-on activity includes disabling Windows Defender, deleting shadow copies, neutralizing Windows Update, creating scheduled tasks for persistence, and establishing command-and-control over non-standard ports. Microsoft assesses this activity aligns with publicly reported Silver Fox operations but has not attributed it to a nation-state actor. Join the discussion | AlienVault OTX General | 09/02/2026, 02:57:18 UTC Added: 09/02/2026, 11:37:30 UTC |
ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated. Join the discussion | AlienVault OTX General | 08/31/2026, 11:11:49 UTC Added: 08/31/2026, 15:38:07 UTC |
0 A misconfigured open directory on IP 86.53.111.212:8080 exposed the Moobot botnet source code, DDoS tools, and fraudulent services linked to an active cybercrime operation. The exposed data included StresD Pro+, a multi-user DDoS panel with multiple registered accounts and recorded attacks. Analysis of the Moobot source code revealed a dormant download-and-execute feature likely used by APT28 to deploy malware. Despite a 2024 court-authorized disruption, Moobot remains active as of August 2026, with ongoing DDoS attacks consistent with DDoS-as-a-service activity. Join the discussion | AlienVault OTX General | 08/28/2026, 02:25:31 UTC Added: 08/28/2026, 08:52:30 UTC |
Three implants named SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS have been found embedded in ZBT router firmware distributed globally, including in the US, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor on port 9992 providing root shell access with trivial MAC address bypass. SPEAKINGSTONE is a phone-home implant capable of DNS hijacking, ISP credential theft, and remote command execution. These implants use plaintext protocols without authentication, making them vulnerable to hijacking by network adversaries. The compromised hardware is found in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commercial devices. A sinkholed backup domain revealed 392 devices, mostly in China, and internet scans found 203 DARKLANTERN instances in 22 countries. Join the discussion | AlienVault OTX General | 08/27/2026, 22:16:24 UTC Added: 08/28/2026, 09:07:13 UTC |
0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303. Join the discussion | Zero Day Initiative | 08/21/2026, 00:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309. Join the discussion | Zero Day Initiative | 08/21/2026, 00:00:00 UTC Added: 07/30/2026, 15:59:02 UTC |
0 Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27987. Join the discussion | Zero Day Initiative | 08/20/2026, 16:24:53 UTC Added: 07/31/2026, 01:36:50 UTC |
Cisco Talos identified a Chinese-speaking cybercrime group, UAT-10147, conducting large-scale attacks against Windows and Linux web servers globally. The group exploits publicly disclosed vulnerabilities to gain initial access and integrates AI-driven tools to automate exploitation, reconnaissance, payload generation, validation, and persistence. Targets include organizations in government, education, media, technology, and gaming sectors across Brazil, Bolivia, China, Canada, and Vietnam. The actor deploys malware for SEO fraud and data theft, using multiple open-source offensive frameworks and privilege escalation tools. The infection chains involve multi-stage scripts that evade detection and establish persistence via backdoors and rogue accounts. Talos assesses this as a financially motivated campaign leveraging semi-autonomous AI orchestration to scale complex intrusions efficiently. Join the discussion | Cisco Talos | 08/20/2026, 10:00:32 UTC Added: 08/20/2026, 10:15:42 UTC |
Showing 1 to 10 of 5328 results