4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm RoshanRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Threat actor57
UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting DiplomatsThe Hacker News·Aug 26, 10:32 UTC · Aug 26, 2025Malware42
FBI Deletes PlugX Malware from Thousands of ComputersSchneier on Security·Jan 15, 00:00 UTC · Jan 15, 2025Malware30
Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection ChainRecorded Future·May 27, 00:00 UTC · May 27, 2024Threat actor57
PlugX Trojan Disguised as Legitimate Windows Debugger Tool in Latest AttacksThe Hacker News·Feb 28, 04:48 UTC · Feb 28, 2023Malware42
RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage CampaignsThe Hacker News·Jan 10, 09:51 UTC · Jan 10, 2025Malware55
Chinese-Linked Hackers Exploit Windows Flaw to Spy on EU DiplomatsInfosecurity Magazine·Oct 31, 12:10 UTC · Oct 31, 2025Vulnerability55
Global Campaign Targets PlugX Malware with Innovative PortalInfosecurity Magazine·Jan 2, 17:15 UTC · Jan 2, 2025Malware30
China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 DevicesThe Hacker News·Jun 18, 09:27 UTC · Jun 18, 2024Vulnerability in the wild60
New Mustang Panda campaign targets Asia with a backdoor dubbed DOPLUGSSecurity Affairs·Feb 22, 07:06 UTC · Feb 22, 2024Malware42
PlugX Trojan disguised as a legitimate Win tool in recent attacksSecurity Affairs·Feb 27, 13:52 UTC · Feb 27, 2023Malware42
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Chinese state-sponsored hackers targets Russia and Belarus with ZeroT and PlugXSecurity Affairs·Feb 3, 18:38 UTC · Feb 3, 2017Threat actorCVE-2012-015860
Hackers Weaponize Balochistan Police Portal in MultiThe Hacker News·Jul 11, 17:49 UTC · Jul 11, 2026Malware42
Chinese Hackers Target Government Officials in Europe, South America, and Middle EastThe Hacker News·Sep 8, 17:21 UTC · Sep 8, 2022Malware42
Chinene Moshen Dragon abuses security software to sideload malwareSecurity Affairs·May 3, 10:56 UTC · May 3, 2022Malware42
Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese TargetsPalo Alto Unit 42·Nov 1, 09:41 UTC · Nov 1, 2018Malware42
Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software UpdatesThe Hacker News·Mar 19, 18:54 UTC · Mar 19, 2026Malware42
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage CampaignsThe Hacker News·Feb 4, 16:46 UTC · Feb 4, 2026Threat actorCVE-2025-808860
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European DiplomatsThe Hacker News·Nov 8, 05:26 UTC · Nov 8, 2025VulnerabilityCVE-2025-949135
Diplomatic entities in Belgium and Hungary hacked in ChinaThe Record·Oct 30, 18:17 UTC · Oct 30, 2025Exploit / PoC60
Suspected Chinese cyber spies targeted Serbian aviation agencyThe Record·Oct 6, 14:17 UTC · Oct 6, 2025Malware30
China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and RansomwareThe Hacker News·Feb 22, 06:56 UTC · Feb 22, 2025RansomwareCVE-2024-2491960
EastWind campaign distributes CloudSorcerer and two APT toolsKaspersky Securelist·Aug 14, 12:00 UTC · Aug 14, 2024Threat actor57
Daggerfly APT Targets African Telecoms Firm With New MgBot MalwareInfosecurity Magazine·Apr 20, 17:00 UTC · Apr 20, 2023Malware42
Nation-state hackers using malicious USB drives in fast-spreading attacks in Africa, Asia and OceaniaThe Record·Mar 9, 22:43 UTC · Mar 9, 2023Threat actor57
Experts uncovered a new wave of attacks conducted by Mustang PandaSecurity Affairs·May 9, 07:25 UTC · May 9, 2022Threat actor57
Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom SectorThe Hacker News·May 4, 07:40 UTC · May 4, 2022Malware42
APT trends report Q2 2020Kaspersky Securelist·Jul 29, 10:00 UTC · Jul 29, 2020VulnerabilityCVE-2019-1014947
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
China-linked UNC6384 exploits Windows zeroSecurity Affairs·Nov 1, 14:11 UTC · Nov 1, 2025Exploit / PoC60
China-linked hackers target European healthcare orgs in suspected espionage campaignThe Record·Feb 21, 01:12 UTC · Feb 21, 2025Threat actorCVE-2024-2491960
Financially motivated hackers are helping their espionage counterparts and vice versaArs Technica · Security·Feb 15, 00:00 UTC · Feb 15, 2025Threat actor57
RA World Ransomware Attack in South Asia Links to Chinese Espionage ToolsetThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025RansomwareCVE-2024-0012CVE-2023-20198CVE-2023-2027360
China-linked APTs' tool employed in RA World Ransomware attackSecurity Affairs·Feb 13, 15:49 UTC · Feb 13, 2025RansomwareCVE-2024-001260
We can try to bridge the cybersecurity skills gap, but that doesn’t necessarily mean more jobs for defendersCisco Talos·Sep 12, 18:00 UTC · Sep 12, 2024Malware55
DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and EuropeThe Hacker News·Sep 11, 15:39 UTC · Sep 11, 2024Threat actor57