china11 articles
DoJ Quietly Walks Back Claim That Major US Agencies Were Hacked by Chinese Group
The U.S. Department of Justice corrected a press statement to clarify that several federal agencies, including NASA, the Federal Reserve, and the DoJ itself, were *targeted* by Chinese state-linked hacking group QTFY rather than confirmed *victims*, a distinction suggesting not all targeted organisations were successfully compromised. QTFY, operating through a private Chinese company with ties to the Ministry of State Security, has been active since 2018 and provides cyber espionage tools — including a vulnerability scanning platform and an obfuscation network — used to attack critical infrastructure in the U.S. and abroad. The FBI has since seized domains linked to the group's key tools, while investigators revealed QTFY also operates a botnet of compromised IoT devices to mask the origins of its malicious traffic.
FBI Takes Down Chinese State Hacking Tools Used Against NASA, Senate, and DOE
The FBI has disrupted a botnet and seized two hacking platforms — QScan and QTRouter — used by a Chinese government-backed group called QTFY to infiltrate major US institutions, including NASA, the Department of Energy, the US Senate, and several other agencies, dating back to at least 2018. QTFY, operated through a private Chinese company called Nanjing Xinjiuwei, used the tools to build networks of compromised IoT devices that obscured the origin of their cyberattacks, exploiting critical vulnerabilities in products from Ivanti and Citrix. The seizure of three QTFY-linked domains has rendered both hacking services inoperable, marking the latest in a series of FBI actions targeting Chinese state-sponsored hacking operations.
Nine Charged in Taiwan Over Smuggled AI Servers Destined for China, Nvidia and Super Micro Staff Among Accused
Taiwanese prosecutors have charged nine individuals, including employees from Nvidia and Super Micro, with illegally exporting banned high-end AI servers — specifically Nvidia B300 GPUs — to mainland China in violation of U.S. export controls. A total of 74 servers were successfully smuggled through routes involving Indonesia, Japan, and Hong Kong, while a further 56 servers were intercepted and remain in Taiwan. Prosecutors are seeking maximum five-year sentences for four of the defendants, including an Nvidia manager identified as a key figure in authorising the illegal releases.
New Zealand Intelligence: China Used Astronomy Cover to Plant Spy Kit on Kiwi Soil
New Zealand's Security Intelligence Service (NZSIS) has alleged that Chinese organisations, including the Purple Mountain Observatory, attempted to install ground-based space infrastructure in New Zealand to collect military intelligence, with the agency successfully disrupting the activity. China is rated as the only country targeting New Zealand at scale, with additional concerns raised over Chinese military intelligence using fake job advertisements on professional networking sites to recruit and gather sensitive information. The report also highlights growing domestic threats from violent extremism, noting that the internet has vastly complicated the task of identifying genuine threats amid vast volumes of toxic online content.
AI Agents Ran a Near-Autonomous Cyberattack on Taiwan's Nuclear Safety Agency
Suspected Chinese cyber operatives used AI agents built on open-source tools to launch a "near-autonomous" attack on Taiwanese government systems in early July, compromising 85 user accounts and extracting over 2,500 personnel records across 12 attack waves in just four days. The AI framework autonomously mapped government infrastructure, bypassed authentication, solved CAPTCHAs, and then pivoted to target supply-chain vendors, a nuclear safety agency, and at least seven energy companies. The attack highlights the growing real-world threat of fully automated, AI-driven cyberattacks, with the agents capable of self-correcting errors and independently researching new vulnerabilities to exploit.
Zbtlink Routers Shipped With Built-In Backdoor Handing Out Root Shells to Anyone Listening
Cybersecurity researchers at VulnCheck have discovered a factory-installed backdoor, dubbed ENDLESSDOORS, embedded in firmware across at least 20 Zbtlink router models, which automatically beacons to Chinese command-and-control servers and can grant attackers an unauthenticated interactive root shell. The implant, based on an obscure open-source tool called rctl, requires no authentication and can be hijacked by anyone able to intercept or control the C2 domain resolution. Zbtlink has taken down the affected firmware and claims the feature was intended solely for after-sales technical support, but has suspended sales of the impacted models while working on patched firmware.
China Opens Security Probe Into Palo Alto Networks — And Tells Us Absolutely Nothing About Why
China's Cyberspace Administration (CAC) has launched a security review of Palo Alto Networks' products, citing the need to protect critical infrastructure and national security, though no further details have been provided. The probe mirrors a similar 2023 investigation into Micron, which ultimately resulted in the memory-maker being effectively banned from selling to Chinese critical infrastructure operators, costing it billions in revenue. Analysts suggest the review could be used to favour domestic competitors such as Huawei and H3C, while Palo Alto has stated there is currently no impact on its operations or customers in the region.
Flying Eagle Android RAT Source Code Leaks, Fingerprints Spotted on 170 Servers
Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with researchers at Hunt.io and NetAskari identifying matching infrastructure on 170 internet servers, though this figure reflects server fingerprints rather than confirmed victims or active command-and-control systems. The toolkit, disguised as a fake Chinese public security app, supports keystroke and payment-password capture, screen recording, camera access, and phishing overlays, and its builder generates obfuscated APKs with encrypted C2 URLs. Researchers also identified a separate Android RAT called Night Dragon being promoted by one of the same Telegram channels, though it appears to be an independent, financially motivated tool unrelated to the 2011 espionage campaign of the same name.
China Claims US Firms Distil Its Models Too, As AI Trade War Rhetoric Escalates
China's Ministry of Commerce has threatened "all necessary measures" in response to US allegations that Chinese AI companies distilled American frontier models, denying the claims and counter-alleging that US companies have themselves distilled Chinese models. Beijing also argues its AI firms are already leading in some areas, making distillation of US models unnecessary, while noting the timing of releases leaves little room for the alleged copying to have occurred. Amid the dispute, China is calling for cooperative AI governance through its newly formed World Artificial Intelligence Cooperation Organization, and interestingly finds itself aligned with a large portion of the US tech industry in advocating for open-source AI models.
SpaceX's Quiet Chinese Investors: Military-Linked Backers, Qatari Royals, and a Middleman Who Promised CFO Access
A ProPublica investigation has revealed that a Chinese businessman with ties to military contractors, along with other overseas investors from China, Hong Kong, and Russia, secretly acquired small stakes in SpaceX through a US middleman firm called Tomales Bay Capital between 2018 and 2021. This raises national security concerns given SpaceX's extensive work on sensitive US government contracts, such as building spy satellites for the Pentagon. The revelations are particularly notable as SpaceX recently barred Chinese and Hong Kong investors from its record-breaking IPO, citing "regulatory and compliance risks."
China Is Bolting AI Onto Its Creaking Camera Grid. The Upgrade Is Significant.
China is upgrading its extensive legacy camera network with AI-powered systems from manufacturers like Hikvision and Huawei, enabling automated behavioral analysis, crowd detection, and text-based video search without manual review. The modernization follows a 2024 government directive issued after a series of violent attacks, shifting the system's focus from reactive individual identification to large-scale, proactive behavioral monitoring. Human rights experts and Anthropic have raised alarm, warning that the upgrades represent a far more sweeping surveillance capability that China could scale significantly by 2028.