← BACK TO FEED
TAG

cyber espionage3 articles

DoJ Quietly Walks Back Claim That Major US Agencies Were Hacked by Chinese Group

The U.S. Department of Justice corrected a press statement to clarify that several federal agencies, including NASA, the Federal Reserve, and the DoJ itself, were *targeted* by Chinese state-linked hacking group QTFY rather than confirmed *victims*, a distinction suggesting not all targeted organisations were successfully compromised. QTFY, operating through a private Chinese company with ties to the Ministry of State Security, has been active since 2018 and provides cyber espionage tools — including a vulnerability scanning platform and an obfuscation network — used to attack critical infrastructure in the U.S. and abroad. The FBI has since seized domains linked to the group's key tools, while investigators revealed QTFY also operates a botnet of compromised IoT devices to mask the origins of its malicious traffic.

2 Sept 2026

QUICAgent Backdoor Targets Myanmar Government in Multi-Stage Espionage Campaign

is a China-linked cyber espionage campaign targeting Myanmar's government and IT sectors, using deceptive lures such as graduation ceremony invitations and holiday calendars to trick victims into executing malware. The multi-stage infection chain abuses legitimate Windows tools like `ftp.exe` to reconstruct and deploy a custom Go-based backdoor called **QUICAgent**, which communicates with its command-and-control server via the QUIC protocol and supports file transfer, command execution, and directory browsing. Separately, the China-linked Mustang Panda group has been observed deploying an updated version of the **COOLCLIENT** backdoor featuring a new kernel-mode driver that enhances stealth by hiding malicious processes and protecting related files from detection.

25 Aug 2026

Daxin Is Back, and It Brought a Friend: Meet Stupig, the Pre-Login Backdoor Nobody Saw Coming

A China-linked advanced malware called Daxin has resurfaced at a Taiwan manufacturing firm in 2026, over four years after it was first publicly documented, alongside a newly discovered backdoor called Stupig that hides within the Windows logon process to execute commands with SYSTEM privileges before any user signs in. Both tools carry 2013 compilation timestamps, raising the possibility the intrusion went undetected for up to 13 years. Separately, a suspected China-linked actor has also been observed using AI tools, including Anthropic's Claude Code and DeepSeek, to automate cyberattacks against government and financial targets across multiple countries.

27 Jul 2026