Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
#SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
https://www.theregister.com/2025/06/09/china_malware_flip_switch_sentinelone/
Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs

: SentinelOne discovered the campaign when they tried to hit the security vendor's own servers

The Register

⚠️ Chinese hackers hit governments, media, and cybersecurity firms in a global cyber espionage spree. Over 70 orgs targeted using tools like ShadowPad and PurpleHaze.

Read: https://hackread.com/chinese-linked-hackers-targeted-global-organizations/

#CyberSecurity #China #CyberAttack #PurpleHaze #ShadowPad #APT15

Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
BADBAZAAR and MOONSHINE: Spyware targeting Uyghur, Taiwanese and Tibetan groups and civil society actors
#BadBazaar #MOONSHINE #APT15
https://www.ncsc.gov.uk/files/NCSC-Advisory-BADBAZAAR-and-MOONSHINE-guidance.pdf
Bundesregierung: China für Angriff auf Bundesbehörde im Jahr 2021 verantwortlich

Ein digitaler Spionagefall beim Bundesamt für Kartographie und Geodäsie aus dem Jahr 2021 führt nun zur Einberufung des chinesischen Botschafters.

heise online
Cyberspionage: Chinesische Gruppe hat deutsche Kartographiebehörde gehackt

Einer chinesischen Gruppierung ist vor zwei Jahren ein Einbruch bei einer deutschen Bundesbehörde gelungen. Wie sie vorgeht, erklärt der Verfassungsschutz.

heise online

NEW: "Sham Signal App Tied to China Raises Alarms"

You're using your smartphone, scrolling through your favorite apps, sending messages, and staying connected. But what if some of those innocent-looking apps are not what they seem?

https://www.hackingbutlegal.com/p/sham-signal-app-tied-to-china-raises

#infosec
#malware
#china #prc #apt15

Sham Signal App Tied to China Raises Alarms

You're using your smartphone, scrolling through your favorite apps, sending messages, and staying connected. But what if some of those innocent-looking apps are not what they seem?

Hacking, but Legal

Full write up and #IOCs for #APT15 aka #PlayfulTaurus and their campaign against Iranian targets

"#Turian #malware...we recently identified new variants of this backdoor as well as new command and control infrastructure. Analysis of both the samples and connections to the malicious infrastructure suggests that several Iranian government networks have likely been compromised by Playful Taurus."

https://unit42.paloaltonetworks.com/playful-taurus/

#threatintelligence #hacking #ChineseGovernement

Chinese Playful Taurus Activity in Iran

Chinese APT Playful Taurus is using a new backdoor named Turian. Analysis suggests several Iranian government networks have likely been compromised.

Unit 42
Android Spyware Tools Emerge in Widespread Surveillance Campaign - Four Android spyware tools have been used in a widespread APT campaign to spy on the Uyghur ethnic... more: https://threatpost.com/four-android-spyware-tools-surveillance-campaign/157063/ #dataexfiltration #surveillanceware #websecurity #carbonsteal #doubleagent #goldeneagle #silkbean #malware #android #spyware #uyghur #hacks #apt15 #mapt #apt
Android Spyware Tools Emerge in Widespread Surveillance Campaign

Four newly discovered Android spyware tools have come to light in a widespread APT campaign to spy on the Uyghur ethnic minority group.

Threatpost - English - Global - threatpost.com