Threats Tagged 'china-nexus'
View all threats tagged with 'china-nexus'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'china-nexus'
Click on any threat for detailed analysis and mitigation recommendations
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino. The campaign primarily affected Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria through sophisticated spear-phishing operations using tailored political and diplomatic lures. The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers. The backdoor supports reconnaissance, command execution, file transfer, shellcode loading, and persistence establishment. Attribution to Chinese nexus is based on metadata containing Simplified Chinese artifacts, UTC+8 timestamps, use of China-focused Rust package mirrors, and targeting patterns consistent with Chinese intellige... Join the discussion | AlienVault OTX General | 09/30/2026, 15:17:20 UTC Added: 09/30/2026, 18:48:38 UTC |
A China-linked cyber espionage infrastructure provider operates a multi-component 'quartermaster' system that offers reconnaissance, proxy orchestration, and traffic routing services to Chinese state-sponsored actors. The infrastructure includes QScan for reconnaissance, Fast Labyrinth for encrypted relay networks using commercial proxy services, QTRouter for proxy access management, and QTProxy for operational node control. It targets research universities, defense networks, government agencies, and critical infrastructure worldwide, with notable focus on the U.S., U.K., and Asia-Pacific regions. The operation leverages commercial proxy services designed to bypass China's Great Firewall, enabling multiple threat actors to maintain anonymity and coordinate operations via shared infrastructure. This represents an advanced evolution in state-enabled cyber espionage capabilities. Join the discussion | AlienVault OTX General | 08/26/2026, 22:00:43 UTC Added: 08/27/2026, 22:07:26 UTC |
A China-nexus threat actor is targeting Myanmar government personnel and diplomats through Operation QUICSILVER, delivering malware via Virtual Hard Disk files disguised as JPEG images. The campaign uses Burmese-language lures impersonating Myanmar's Information Technology and Cyber Security Department, including graduation ceremony invitations. The multi-stage infection chain begins with a malicious LNK file that abuses ftp.exe to execute scripts, reconstructs payloads from split files, and deploys QUICAgent, a custom Go-based backdoor. The implant retrieves C2 infrastructure through Cloudflare Workers, communicates over HTTP/3 using QUIC protocol, and employs RC4 encryption. Deleted documents recovered from the VHD reveal interest in ASEAN affairs, BIMSTEC, and Myanmar diplomatic activities. Three related campaigns were identified between April and July 2026, sharing similar TTPs and infrastructure. Join the discussion | AlienVault OTX General | 08/17/2026, 15:03:53 UTC Added: 08/18/2026, 09:26:43 UTC |
Researchers uncovered a fractured criminal ecosystem built around Flying Eagle, an Android remote access tool whose source code was stolen in early 2026 along with nearly 200 customer databases. The investigation began with a malicious APK impersonating a Chinese Provincial Public Security Bureau app, leading to identification of 170 active servers running the framework. Two Telegram channels, SQLRCE0 and Yx Technology, distribute modified versions with operational support and cash-out services at 20-50% transaction fees. The platform combines APK generation and C2 device management with phishing overlays targeting financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, featuring enhanced credential capture capabilities for Chinese banking apps, cryptocurrency wallets, and social media platforms. The activity primarily targets Chinese citizens through social engineering lures, though international templates suggest broader targeting capability. Join the discussion | AlienVault OTX General | 07/28/2026, 21:18:53 UTC Added: 07/29/2026, 12:07:07 UTC |
Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an... Join the discussion | AlienVault OTX General | 07/09/2026, 22:16:04 UTC Added: 07/10/2026, 07:47:32 UTC |
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
A sophisticated China-aligned cyber espionage campaign targeting India's tax infrastructure was identified between May and June 2026. The operation impersonates the Income Tax Department, Ministry of Finance, exploiting the AY2026-27 ITR filing season to target corporate entities, tax professionals, chartered accountants, and taxpayers. The attack employs spear-phishing emails with malicious attachments mimicking legitimate government utilities. The multi-stage infection chain deploys DcRAT through steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence. The threat actor demonstrates operational maturity through active payload rotation achieving 0/66 detection rates, encrypted TLS-based C2 communications, and infrastructure hosted across multiple ASNs linked to China. The campaign shows overlaps with the China-nexus threat actor Silver Fox, featuring screen capture capabilities, data exfiltration, and systematic intelligence collection from high-value India... MediumMalware Join the discussion | AlienVault OTX General | 06/26/2026, 12:50:31 UTC Added: 06/26/2026, 17:57:21 UTC |
A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection requirements. Join the discussion | AlienVault OTX General | 06/15/2026, 19:33:11 UTC Added: 06/16/2026, 11:30:21 UTC |
In March 2026, a China-nexus threat actor launched a sophisticated campaign targeting countries in the Arabian Gulf region, exploiting renewed Middle East conflict themes within 24 hours of escalation. The attack utilized Arabic-language lures depicting missile strikes and employed a multi-stage infection chain beginning with weaponized ZIP archives containing malicious LNK and CHM files. The campaign deployed a heavily obfuscated PlugX backdoor variant through DLL sideloading, with components using control flow flattening and mixed boolean arithmetic techniques. The backdoor supports HTTPS command-and-control communications, DNS-over-HTTPS resolution, and multiple plugins for system manipulation. Based on tools, techniques, and procedures including specific RC4 decryption keys and rapid geopolitical weaponization, the activity is attributed with medium confidence to Mustang Panda. Join the discussion | AlienVault OTX General | 04/13/2026, 14:40:01 UTC Added: 04/13/2026, 14:46:50 UTC |
A China-nexus threat actor targeted countries in the Persian Gulf region using a multi-stage attack chain to deploy a PlugX backdoor variant. The campaign exploited the renewed Middle East conflict, using an Arabic-language document lure depicting missile attacks. The attack utilized a ZIP archive containing a malicious Windows shortcut file, which downloaded a CHM file leading to the deployment of PlugX. The malware employed various obfuscation techniques, including control flow flattening and mixed boolean arithmetic. The PlugX variant supported HTTPS for command-and-control communication and DNS-over-HTTPS for domain resolution. Based on the tools and tactics used, the activity is attributed to a China-nexus actor, possibly linked to Mustang Panda. Join the discussion | AlienVault OTX General | 03/16/2026, 10:26:21 UTC Added: 03/16/2026, 10:50:06 UTC |
Showing 1 to 10 of 16 results