ZeroHour

Search: “spotify”

198 stories

Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting

DoJ seized domains of Chinese espionage botnet platforms QScan and QTRouter, run by private firm QTFY for MSS and PLA targeting.

The US Department of Justice disrupted QScan, a distributed vulnerability scanning system with nearly a decade of internet scanning data, and QTRouter, a covert communications platform routing traffic through compromised IoT devices, operated by QTFY under Chinese company Nanjing Xinjiuwei Network Technology. FBI and NSA advisories say QTFY customers include China's Ministry of State Security and the People's Liberation Army, targeting federal agencies, the US Senate, hospitals, telecoms and financial institutions. This is the third Chinese state-backed botnet disrupted since December 2023, following the KV botnet (Volt Typhoon) and Raptor Train (Flax Typhoon), and a sister network, JDY, has more than doubled since the KV disruption. Separately, the Qilin ransomware group claimed a breach of the ATF's CALEA system, briefly publishing 6.3 GB of case folders and forensic data.

Risky Business News · 13d agoThreat actor1

China's AI-Enabled APT Operations Are Getting Interesting

Bitdefender links seven RAT families, five previously undocumented, to China-nexus espionage actor SilkParasite using AI-assisted malware development against Central Asian governments.

A Bitdefender report attributes seven remote access tool families to a single actor dubbed SilkParasite, with medium confidence a China-nexus group targeting governments in Uzbekistan, Turkmenistan and Kazakhstan. The RATs are written in .NET, C++, Go and JavaScript, use C2 via Google Drive and protocols like HTTP, DNS and TCP, and employ modular plugin architectures with regular rotation of infrastructure, encryption material and persistence artifacts. Evidence of AI-assisted development includes leftover test functions, placeholder encryption keys, and GoginRAT and NomadRAT sharing a high-level architecture despite different languages, suggesting a specification implemented twice with AI. The newsletter also covers the US Operation Economic Outcast sanctioning six MOIS-linked Iranian hackers, including hands-on-keyboard operators who targeted US critical infrastructure.

Risky Business News · 20d agoThreat actor1

Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

Google's Threat Intelligence Group reports data theft extortion is surging, with Silent Ransom extracting $10M and $18M from two law firms and BlackFile taking $10M.

Risky Business News, citing Google Threat Intelligence Group (GTIG), reports that cybercriminals are shifting from encrypting ransomware to data theft extortion. Law firms Goodwin Procter and WilmerHale paid Silent Ransom (Luna Moth) ransoms of $10 million and $18 million respectively; GTIG says the group often completes contact-to-extortion in a single day, now sometimes compromising systems in person posing as IT staff. BlackFile, now calling itself Redact, used high-volume vishing to steal credentials and pivot through OneDrive, SharePoint and other SaaS apps, collecting more than $10 million between February and mid-May with an average ransom of $750,000, including attempted attacks on Wall Street hedge funds and private equity firms. The piece argues governments should keep pressure on encrypting ransomware gangs while lower-impact extortion absorbs criminal energy.

Risky Business News · Aug 13, 2026Threat actor1