#APT27
Off the top of my head.

APT27 false flagging Iranian APTs: cloud.google.com/blog/topics/...

Turla stealing victims and using tools from a Pakistani APT and Tomiris. www.microsoft.com/en-us/securi...

Scarcruft and Dark Hotel media.kasperskycontenthub.com/wp-content/u...
August 24, 2026 at 11:11 PM
AI-powered hacking tools have rapidly evolved since WormGPT in 2023, spreading via SaaS, open source, and local models. They now enable automation, credential theft, and self-modifying malware. #WormGPT #APT27 #APT45
The proliferation and evolution of AI-powered hacking tools – how generative AI has changed the cyber attack ecosystem and response strategies
WormGPT’s emergence in June 2023 marked a turning point as AI-powered hacking tools rapidly spread across paid SaaS, open-source releases, and locally run models, lowering the barrier to cybercrime and enabling new forms of attack automation. The article also shows AI moving beyond support roles into orchestration, credential theft, and self-modifying...
www.hendryadrian.com
May 28, 2026 at 4:15 AM
Through state-sponsored hacking groups (such as APT27), it steals secrets and commercial technologies from foreign governments, militaries, and private companies on a massive scale.
May 20, 2026 at 3:45 AM
📰 Google Ungkap Eksploitasi Zero-Day Pertama di Dunia yang Dihasilkan oleh AI

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/12/google-ungkap-eksploitasi-zero-day-pertama-dari-ai/

#2fa
By#2faBypassp#aiExploit7#apt275#apt45t#beritaTeknologir#cybersecurityn#geminiApil#googleGtigp#promp
May 12, 2026 at 2:20 AM
📢 GTIG : Les acteurs malveillants exploitent l'IA pour la découverte de vulnérabilités et les opérations offensives
📝 ## 🌐 Con…
https://cyberveille.ch/posts/2026-05-11-gtig-les-acteurs-malveillants-exploitent-l-ia-pour-la-decouverte-de-vulnerabilites-et-les-operations-offensives/ #APT27 #Cyberveille
May 11, 2026 at 9:00 PM
Google Threat Intelligence Group reveals AI was likely used to create a zero-day exploit bypassing 2FA in an open-source web admin tool. Linked APT groups include APT27, APT45, and others. #AIExploits #OpenSource #APT27
Google: Hackers used AI to develop zero-day exploit for web admin tool
Google Threat Intelligence Group says a zero-day exploit against an unnamed open-source web administration tool was likely created with AI to bypass two-factor authentication, and the attack was stopped before mass exploitation. The report also links AI use to other threat activity involving APT27, APT45, UNC2814, UNC5673, UNC6201, CANFAIL, LONGSTREAM, Overload, and PromptSpy. #APT27 #APT45 #UNC2814 #UNC5673 #UNC6201 #CANFAIL #LONGSTREAM #Overload #PromptSpy
www.hendryadrian.com
May 11, 2026 at 4:15 PM
APT27 Turns Trusted Apps Into Silent Weapons as Healthcare Ransomware Crisis Escalates

Introduction: A New Wave of Stealth Cyberattacks Hidden in Everyday Software Cybersecurity researchers have uncovered a disturbing evolution in modern cyberattacks where trusted applications are no longer safe…
APT27 Turns Trusted Apps Into Silent Weapons as Healthcare Ransomware Crisis Escalates
Introduction: A New Wave of Stealth Cyberattacks Hidden in Everyday Software Cybersecurity researchers have uncovered a disturbing evolution in modern cyberattacks where trusted applications are no longer safe by default. Threat actors are increasingly abusing legitimate software ecosystems to remain undetected for long periods. In the latest findings, advanced persistent threat groups and ransomware operators are refining techniques that blend malicious activity into normal system behavior.
undercodenews.com
May 9, 2026 at 12:30 AM
LevelBlue’s GSOC reveals how APT27 abuses trusted Electron apps like GitHub Desktop and Microsoft Teams for persistence and evasion by backdooring key files. Loki C2 detection guidance also provided. #ElectronApps #APT27 #China
Threat Analysis: Backdoored Electron Apps Evading Defenses
LevelBlue’s GSOC shows how trusted Electron apps can be abused for persistence and to bypass application safelisting by backdooring or hollowing out applications like GitHub Desktop and Microsoft Teams. The report also demonstrates detection guidance for Loki C2 activity and highlights APT27-linked abuse of Electron applications such as Mimi Chat. #Electron #GitHubDesktop #MicrosoftTeams #LokiC2 #APT27 #MimiChat
www.hendryadrian.com
May 9, 2026 at 12:15 AM
Hunting the Dragon: A Technical Deep Dive into the Chinese APT Playbook + Video

Introduction: In the ever-escalating landscape of state-sponsored cyber espionage, Chinese Advanced Persistent Threats (APTs) such as APT41, APT27 (Emissary Panda), and APT10 (MenuPass) remain some of the most prolific…
Hunting the Dragon: A Technical Deep Dive into the Chinese APT Playbook + Video
Introduction: In the ever-escalating landscape of state-sponsored cyber espionage, Chinese Advanced Persistent Threats (APTs) such as APT41, APT27 (Emissary Panda), and APT10 (MenuPass) remain some of the most prolific and technically sophisticated adversaries. A recently surfaced "playbook" provides a granular field manual detailing their common Tactics, Techniques, and Procedures (TTPs). This article dissects those methodologies, translating threat intelligence into actionable detection and hardening strategies for Red and Blue teams alike, focusing on the specific malware development and evasion behaviors observed in these campaigns.
undercodetesting.com
February 27, 2026 at 1:02 AM
米国、中国のハッカー雇用グループ「i-Soon」のメンバーを起訴

米国は、政府職員およびi-Soonのスタッフとともに、活動が非常に活発な中国のハッキンググループAPT27のメンバーを、長年にわたる間接的なハッキング・キャンペーンに関して起訴した。 司法省(DoJ)は昨日、2016年から2023年にかけて実施され、メールアカウント、携帯電話、サーバー、ウェブサイトへの広範なハッキングを伴ったキャンペーンに関連して、i-Soonの従業員8人と公安部(MPS)の警察官2人を指名手配していると述べた。 その中には、i-SoonのCEOである呉海波(Wu Haibo)、COOの陳成(Chen…
米国、中国のハッカー雇用グループ「i-Soon」のメンバーを起訴
米国は、政府職員およびi-Soonのスタッフとともに、活動が非常に活発な中国のハッキンググループAPT27のメンバーを、長年にわたる間接的なハッキング・キャンペーンに関して起訴した。 司法省(DoJ)は昨日、2016年から2023年にかけて実施され、メールアカウント、携帯電話、サーバー、ウェブサイトへの広範なハッキングを伴ったキャンペーンに関連して、i-Soonの従業員8人と公安部(MPS)の警察官2人を指名手配していると述べた。 その中には、i-SoonのCEOである呉海波(Wu Haibo)、COOの陳成(Chen Cheng)らが含まれる。DoJによれば、彼らは雇われハッカーとして数千万ドルを稼ぎ、MPSまたは国家安全部(MSS)の要請に応じてコンピューター侵入を行う一方で、自らの判断で侵入を実施し、侵害したデータを北京に販売していたという。 サイバーセキュリティ企業i-Soonは、侵害したメール受信箱1件あたり1万~7万5000ドルをMSSおよびMPSに請求していたとみられ、さらにMPS職員の訓練でも収益を得ていた。 標的には、名称不明の「大規模な宗教団体」や、北京に批判的な「複数の報道機関」が含まれていた。 i-Soonに関する詳細はこちら:i-SoonのGitHub流出:サイバー専門家が中国のサイバー諜報について学んだこと DoJによれば、この計画はi-Soonの範囲を超えて広がっていた。 FBIサイバー部門のブライアン・ボーンドラン(Bryan Vorndran)副局長は、「本日の発表は、中国の公安部が、中国共産党(CCP)を批判する米国人にデジタル上の被害を与えるため、雇われハッカーに報酬を支払ってきたことを明らかにするものだ」と述べた。 「侵入の証拠を携えて勇気をもって名乗り出た被害者の皆さんには、毅然と立ち上がり、私たちの民主主義を守ってくださったことに感謝します。そして、CCPの違法なサイバー活動を助けることを選ぶ者に対しては、これらの起訴が、私たちが利用可能なあらゆる手段を用いてあなた方を特定し、起訴し、悪意ある活動を世界中に暴露することを示すはずです。」 別件として、DoJは2013年にさかのぼる長期の営利目的キャンペーンに関して、APT27の関係者2人を起訴した。彼らは複数の買い手(中国政府を含む)にデータを販売するためにハッキングを行ったとされる。被害者には、米国のテクノロジー企業、シンクタンク、法律事務所、防衛関連請負業者、地方自治体、医療システム、大学が含まれていた。 さらに米国務省は、指名手配中のi-Soon従業員の「身元または所在」の特定につながる情報に対して最大1000万ドル、またAPT27関係者の尹克成(Yin Kecheng)および周帥(Zhou Shuai)の「逮捕および有罪判決につながる情報」に対してそれぞれ200万ドルの報奨金を提示した。 財務省の外国資産管理局(OFAC)も、2024年9月から12月にかけて同局へのハッキングに関与したとされる尹に対する制裁を発表した。 翻訳元:
blackhatnews.tokyo
February 7, 2026 at 4:25 AM
英国のシステムがハッキング被害:スパイ活動への懸念が再燃 – Cyber Warriors Middle East

長年の警告が具体的な形を取る…
英国のシステムがハッキング被害:スパイ活動への懸念が再燃 – Cyber Warriors Middle East
長年の警告が具体的な形を取る 10年以上にわたり、サイバーセキュリティの状況は、中国に関連するとされるサイバー脅威について西側諸国政府が発し続けてきた警告によって再編されてきた。こうした警告は、世界の外交言説の陰でしばしば囁かれてきたが、英国政府システムへの侵害が確認されたことで、近ごろ厳しい光の下にさらされることになった。単なるスパイ活動に関する懸念として始まったものは、いまや、不可欠なデジタル・インフラを標的とする、より広範で破壊的なサイバー活動という憂慮すべき物語へと発展しつつある。 長年の警告が具体的な形を取る侵害を認めつつも慎重にインフラリスクとしてのスパイ活動否認と常態化の狭間で Volt Typhoon、Salt Typhoon、APT27、Mustang Pandaといった名称は、中国国家によって指揮されている、あるいは支援されているとみられる高度な脅威グループの代名詞となっている。これらのグループは単にスパイ活動を行っているだけではない。重要インフラ、通信ネットワーク、政府機関、さらにはジャーナリズムの領域にまで及び、競合国の中枢そのものを探り、脆弱性を見つけ出そうとしている。分析者は、国家と足並みをそろえた協調的なキャンペーンがデジタルの均衡を覆しかねない状況を描いている。 米国では、こうした恐れがとりわけ顕著だった。トランプ政権が5G展開からHuaweiを排除する決定を下したことは、国家支援のサイバー諜報に悪用され得る潜在的な監視能力に対する深い懸念を浮き彫りにしている。これに対し北京は断固として否認し、これらの非難は現実に根差したものではなく、米国の政治的駆け引きの戦術だと描いてきた。 侵害を認めつつも慎重に 英国政府が最近、重大なサイバー侵入を確認したことで、不安の空気はいっそう強まった。機密サーバー、特に内務省のために外務省が運用していたものが侵害され、ビザ申請の詳細を含む機微なデータが露出したのではないかとの懸念が生じた。この侵害は、ボリス・ジョンソンの著名な元顧問であるドミニク・カミングスによって最初に指摘され、しばらく見過ごされていた可能性のある脆弱性を示唆している。 通商担当大臣のクリス・ブライアントはBBC Breakfastのインタビューでこの事案について語り、侵害が迅速に対処されたことを認めつつ、その深刻さを抑えようとした。しかし、加害者の特定については慎重で、捜査がなお進行中であることを強調した。捜査当局は「現時点では単に分かっていない」との彼の主張は、こうした侵入の背後にある動機を不安視する人々にとってほとんど安心材料にならない。 インフラリスクとしてのスパイ活動 この侵害の含意は、機微な資料の即時的な露出を超えて広がる。すなわち、スパイ活動がインフラリスクの文脈でますます捉えられるようになっているという、拡大するパラダイムを象徴している。今日の政府は深く相互接続されており、移民システムから公衆衛生サービスに至るまで、重要な行政機能を、完全に安全を確保することが本質的に難しいデジタルネットワーク上で運用している。 ブライアントは個人が被害を受けるリスクは「かなり低い」として国民を安心させようとした一方で、厳しい現実も強調した。政府施設はその性質上、サイバー攻撃者にとって格好の標的であり、現代の統治には絶え間ない警戒が求められることを示している。 サイバーセキュリティの専門家もこの見方に同調し、これらの諜報キャンペーンは即時の混乱を狙うというより、持続的なアクセスを維持することに重きがあると認識している。攻撃者はしばしば、静かにシステムへ侵入し、情報を収集し、ネットワークを把握し、将来的に影響力を行使できるよう布石を打つことに注力する。 否認と常態化の狭間で 中国が、これらの疑われているサイバー活動への関与を一貫して否認していることは、非難と弁明という物語の間に奇妙な緊張を生み出している。中国当局は、こうした主張を、地政学的利益のために自国の技術的進歩を歪めて描こうとする試みだと断じてきた。しかし、この言葉の応酬は、西側諸国がサイバー脅威をより広い視野で捉え始めていることを示唆している。すなわち、それを現代の統治に不可避の要素として見るということだ。 ブライアントの発言は、こうしたサイバー敵対行為への対応における明確な変化を反映している。侵入を単に「現代生活の一部」と位置づけることで、脅威環境を常態化させる方向への動きがはっきりと見て取れる。この見方は、政府が脅威の発生にその都度反応するのではなく、継続するサイバー上の課題を運用の中核要素として受け入れ、適応していく必要があることを示唆している。 サイバー脅威が持続的な現実へと進化するにつれ、帰属の特定、対応措置、インフラの強靭性をめぐる議論はますます緊急性を帯びている。デジタル統治の領域は、これらの脅威から防御するという二重の課題と、世界的なサイバー対話にしばしば伴う政治的な複雑さを乗り越えるという課題の双方に取り組まなければならない。 翻訳元:
blackhatnews.tokyo
December 22, 2025 at 4:53 AM
📢 Chevauchement APT27, HAFNIUM et Silk Typhoon: attribution 2025 et TTPs clés
📝 Source: Natto Thoughts (Substack).
https://cyberveille.ch/posts/2025-10-23-chevauchement-apt27-hafnium-et-silk-typhoon-attribution-2025-et-ttps-cles/ #APT27 #Cyberveille
October 24, 2025 at 8:30 PM
The Natto Team explores how APT27, HAFNIUM, and Silk Typhoon highlight the complexities of tracking threat actors and their real-world identities and why understanding the humans behind the keyboard matters.

nattothoughts.substack.com/p/beyond-the...
Beyond the Aliases: Decoding Chinese Threat Group Attribution and the Human Factor
Examining the overlap between APT27, HAFNIUM, and Silk Typhoon through recent U.S. government disclosures, and why understanding the humans behind the keyboard is important for cyber defenders
nattothoughts.substack.com
October 22, 2025 at 4:34 PM
Phantom Taurus - Le groupe d'espionnage chinois qui hante les gouvernements depuis 3 ans korben.info/phantom-taur...
Phantom Taurus - Le groupe d'espionnage chinois qui hante les gouvernements depuis 3 ans | Le site de Korben
Cet article fait partie de ma série spéciale hackers . Bonne lecture ! Vous connaissez APT27, Winnti, Mustang Panda… Ces groupes de cyberespionnage ...
korben.info
October 2, 2025 at 8:21 PM
A Chinese threat actor, dubbed "Phantom Taurus" by Palo Alto's Unit 42 threat intel division, has been identified as targeting the Middle East. This group shares some infrastructure with Chinese nation-state groups APT27 and Winnti, but also employs unique components, suggesting operational ...
Emerging Chinese Threat Actor Targets Middle East
China's 'Phantom Taurus' Hacks Middle East A Chinese cyberespionage threat actor wit
www.govinfosecurity.com
October 2, 2025 at 12:44 AM
Threat Actor Profile: APT27
Threat Actor Profile: APT27
www.dexpose.io
September 20, 2025 at 10:09 AM
KIM used an Ivanti Connect Secure VPN exploit that Intel 471 links to UNC5221.

According to the US DOJ, UNC5221 is aka APT27, aka Shanghai Heiying Information Technology Company, Limited - contractors to MSS, and possible also, DPRK.

www.state.gov/zhou-shuai
Zhou Shuai - United States Department of State
WANTED: ZHOU SHUAI REWARD OF UP TO $2 MILLION Reward Poster in English  [196 KB] Reward Poster in Mandarin   [230 KB] NAME: Zhou Shuai ALIASES: “Coldface’ DOB: July 9, 1979 POB: People’s Republic of C...
www.state.gov
September 15, 2025 at 12:17 PM