Advertisement
Roundcube Flaw Exploited by China-Linked Group Against Academics
A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.

UAT-7810 Expands LapDogs ORB Network via LONGLEASH Malware
China-linked actor UAT-7810 is leveraging new LONGLEASH malware to expand the LapDogs ORB network, targeting internet-facing networking devices for proxying.
China-Linked Espionage Targets REDCap Servers, Stealing Medical Data
China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.
JDY Botnet: China-Linked Campaign Targets US Military Networks
Analysis of the China-linked JDY botnet's expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.

TA4922 Expands Phishing Campaigns to Europe and South Africa
China-linked TA4922 threat actor expands targeting to the UK, Germany, Italy, and South Africa using ValleyRAT and Atlas RAT malware in high-tempo attacks.

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing
China-linked threat actor Silver Fox targets Russian and Indian organizations using tax-themed lures to deliver the novel ABCDoor malware via phishing waves.

Storm-1175: China-Linked Zero-Day Exploits Deploy Medusa Ransomware
China-linked actor Storm-1175 is weaponizing zero-day and N-day vulnerabilities in perimeter assets to execute high-velocity Medusa ransomware attacks.

TA416 Targets European Govts with PlugX & OAuth Phishing
China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.