#teamt5
New blog from TeamT5 warns a China-nexus APT is exploiting a vulnerability in #Ivanti Connect Secure VPN appliances to target victims in EMEA and the US. Today Shadowserver's CVE-2025-22457 tracker shows 4,098 unpatched instances remain, mostly in Asia and the US.

pse.is/7esf4n
China-nexus APT exploits Ivanti Connect Secure VPN vulnerability to infiltrate multiple entities - TeamT5
In late March, TeamT5 detected that the China-nexus APT group exploited the critical vulnerability in Ivanti Connect Secure VPN appliances to infiltrate multiple entities around the globe. The victims...
pse.is
April 14, 2025 at 12:35 PM
November 18, 2025 at 9:21 AM
A new ransomware operation named CrazyHunter is targeting organizations in Taiwanese critical sectors. The group has ransomed three hospitals, a university, and a power grid operator since the start of the month.

teamt5.org/en/posts/how...
March 13, 2025 at 1:10 PM
"Know Thy Network, Because They Already Do: A Case Study of SLIME27's Campaign against Telecoms"

Silvia Yeh, Cyber Threat Intelligence Analyst at TeamT5
Rax Chuang, Cyber Threat Researcher at TeamT5
12/15
March 10, 2026 at 5:23 PM
Really excited to present at #LABScon25 on ChamelGang‘s most recent campaign targeting the Taliban, a collaborative research project with @milenkowski.bsky.social (SentinelLABS) and @azaka.fun (TeamT5)! www.labscon.io/speakers/jul...
September 16, 2025 at 1:50 PM
🚀LABScon kicks off tomorrow!

I am excited to be presenting on the APT group CamoFei, a joint research project with @julianferdinand.bsky.social (Recorded Future) and @azaka.fun (TeamT5). [1/3]
September 16, 2025 at 11:37 AM
6/ Sincerely grateful to the all-star team of experts who shared their insights and feedback: Scott Henderson (Google Mandiant), Adam Kozy (SinaCyber), @meidanowski.bsky.social (@nattothoughts.bsky.social), @thegrugq.bsky.social, @Chris St.Myers (SentinelOne), & Charles Li and Zha0 (TeamT5)
July 21, 2025 at 8:12 AM
U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar, and Zimbra flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
February 18, 2026 at 11:50 AM
#ICYMI

🇨🇳 🇷🇺 Chinese state-sponsored groups including Mustang Panda and Tonto Team have been targeting Russian aerospace and defense firms looking for intelligence on Moscow's military capabilities, researchers at the Taiwanese cybersecurity firm TeamT5 told POLITICO

www.politico.eu/article/chin...
China’s cyber spies are targeting Russia’s aerospace and defense firms
State-backed hackers seek intel on nuclear weapons and military capabilities, researchers say.
www.politico.eu
January 23, 2025 at 3:47 PM
Bloomberg: Chinese ‘State-affiliated cyber groups more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, according to TeamT5, a Taiwanese research firm.’
China’s Hackers Use DeepSeek for Attacks, Researchers Say
Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools...
www.bloomberg.com
August 25, 2026 at 7:50 AM
Chinese state-linked hacking groups have more than doubled their attack output after wiring low-cost artificial intelligence models into their operations, according to Taiwanese threat intelligence firm TeamT5.
August 26, 2026 at 6:27 AM
TeamT5 reported that the China-nexus APT exploited Ivanti Connect Secure VPN vulnerabilities to infiltrate nearly 20 industries across 12 countries, maintaining control over victim networks during analysis. #CyberSecurity #APT teamt5.org/en/posts/chi...
China-nexus APT exploits Ivanti Connect Secure VPN vulnerability to infiltrate multiple entities - TeamT5
In late March, TeamT5 detected that the China-nexus APT group exploited the critical vulnerability in Ivanti Connect Secure VPN appliances to infiltrate multiple entities around the globe. The victims...
teamt5.org
April 14, 2025 at 4:52 PM
中国政府支持的黑客组织自俄乌战争爆发以来,持续渗透俄罗斯政府与军工系统,目标是窃取军事机密与实战经验,尤其关注核潜艇、作战战术与西方武器表现。尽管中俄高层不断宣示“友谊无上限”,这些入侵行动显示出中国将俄罗斯视为可利用的情报目标。2023年,台湾网络安全公司TeamT5揭露“中国黑客冒充俄罗斯工程公司邮箱”,试图获取潜艇技术。俄国安局(FSB)内部机密文件,称中方为“敌方”,意图获取俄军乌克兰战场经验。此事揭示中俄“战略协作”背后的高度不信任,以及中国对战争情报的现实渴求,凸显北京在对外政策上“表友实敌”的务实姿态。
China Unleashes Hackers Against Its Friend Russia, Seeking War Secrets
www.nytimes.com
June 21, 2025 at 9:15 AM
Event: RSA Conference 2026
Expo date: March 24-26, 2026
Booth: S-1561
Location: Moscone Center at San Francisco, USA

teamt5.org/en/posts/tea...
We’re Exhibiting at RSA Conference 2026 - TeamT5
We are pleased to announce that we will be exhibiting at **RSA Conference 2026**, one of the world’s leading cybersecurity events, taking place in San Francisco. This year, we will join the **Taiwan P...
teamt5.org
March 2, 2026 at 9:08 AM
Critical Flaw in TeamT5 ThreatSonar Anti-Ransomware Confirmed Exploited by Chinese APTs, Added to CISA KEV

AllSafeUs Research Labs has been closely monitoring a critical development in the cybersecurity landscape: a significant vulnerability within the TeamT5 ThreatSonar Anti-Ransomware solution.…
Critical Flaw in TeamT5 ThreatSonar Anti-Ransomware Confirmed Exploited by Chinese APTs, Added to CISA KEV
AllSafeUs Research Labs has been closely monitoring a critical development in the cybersecurity landscape: a significant vulnerability within the TeamT5 ThreatSonar Anti-Ransomware solution. This flaw, recently highlighted by a Taiwanese security firm, has been confirmed as actively exploited by sophisticated Chinese Advanced Persistent Threat (APT) groups. The urgency of this situation is further underscored by its immediate inclusion in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, mandating rapid remediation by U.S.
allsafeus.com
February 24, 2026 at 12:08 PM
CISA Alert: Immediate Action Required for Actively Exploited TeamT5 ThreatSonar Anti-Ransomware Vulnerability

AllSafeUs Research Labs is issuing an urgent security advisory following a recent alert from the Cybersecurity and Infrastructure Security Agency (CISA). CISA has added a critical…
CISA Alert: Immediate Action Required for Actively Exploited TeamT5 ThreatSonar Anti-Ransomware Vulnerability
AllSafeUs Research Labs is issuing an urgent security advisory following a recent alert from the Cybersecurity and Infrastructure Security Agency (CISA). CISA has added a critical vulnerability affecting TeamT5's ThreatSonar Anti-Ransomware product to its Known Exploited Vulnerabilities (KEV) catalog. This designation signifies that the vulnerability is not merely theoretical but is actively being exploited by threat actors in real-world attacks. Organizations leveraging ThreatSonar Anti-Ransomware are strongly advised to take immediate mitigation steps.
allsafeus.com
February 18, 2026 at 11:08 AM
Lots of scaled up cyberattacks against Taiwan using AI (h/t the Metacurity Newsletter)
Chinese Hackers Escalate Cyberattacks Using Open-Source AI
Chinese Hackers Escalate Cyberattacks Using Open-Source AI Chinese hackers use DeepSeek AI to escalate cyberattacks, TeamT5 finds
www.chosun.com
August 25, 2026 at 3:44 PM
TeamT5: hackers vinculats a la Xina han duplicat el volum d'atacs des que incorporen DeepSeek. Motiu? "És potent i té molt poques barreres de ciberseguretat", segons Charles Li. Grups com Grimfengxi, Huapi i Teleboyi l'u ...
[^BgTA^] :verified: :opensuse: (@raul@mastodon.in4matics.cat)
TeamT5: hackers vinculats a la Xina han duplicat el volum d'atacs des que incorporen DeepSeek. Motiu? "És potent i té molt poques barreres de ciberseguretat", segons Charles Li. Grups com Grimfengxi, Huapi i Teleboyi l'usen per generar exploits, atacar email systems i mapejar xarxes senceres. La IA barata canvia l'escala de l'atac, no la sofisticació. https://share.google/aimode/Ckz1EXsSsWycPUPVw #DeepSeek #Ciberseguretat #Ciberatacs
mastodon.in4matics.cat
August 26, 2026 at 6:30 AM
China’s cyber spies are targeting Russia’s aerospace and defence firms – POLITICO Europe: ‘researchers at the Taiwanese cybersecurity firm TeamT5 told POLITICO.’
China’s cyber spies are targeting Russia’s aerospace and defense firms
State-backed hackers seek intel on nuclear weapons and military capabilities, researchers say.
www.politico.eu
January 24, 2025 at 3:01 AM
第一個發現中國安洵文件外洩,是台灣資安公司TeamT5 ​!安洵曾竊取台灣人口資料 ⋯
​全文詳
www.instagram.com/reel/DPjVpgK...
viewpoint.pts on Instagram: "第一個發現中國安洵文件外洩,是台灣資安公司TeamT5 ​!安洵曾竊取台灣人口資料 ⋯​「第一次有機會,看到中國的資安公司披露這麼多,他們內部的資料,能幫助我們理解,中國政府跟中國民間公司背後的生態系。」— 張哲誠 杜浦數位安全分析師​2024年初,中國資安公司…"
第一個發現中國安洵文件外洩,是台灣資安公司TeamT5 ​!安洵曾竊取台灣人口資料 ⋯​「第一次有機會,看到中國的資安公司披露這麼多,他們內部的資料,能幫助我們理解,中國政府跟中國民間公司背後的生態系。」— 張哲誠 杜浦數位安全分析師​2024年初,中國資安公司「安洵」(i-Soon)的內部文件外洩,內容涉及網路攻擊,以及自各國政府竊取的資料,而第一個發現這些文件的,正是台灣資安公司「#杜浦數位安全」TeamT5 @lifeatteamt5 。​​TeamT5在X上發現一個神祕的網址,揭開了安洵外洩的577個檔案中,有許多網路攻擊的技術資訊,包含可入侵信箱帳號的工具,遠端操控智慧型手機,取得定位和音訊的說明,還有員工的聊天紀錄,從對話內容可知,與中國政府、公安密切相關。​​中國政府是否外包駭客從事海外行動?杜浦數位認為,安洵外洩的內部資訊,#有助於證實中國政府涉入網路攻擊。而當中,有文件顯示,安洵曾竊取台灣的個資,包括人口資料及定位資料等等...​​NHK記者團隊,走訪全球七個地區的專家,尋找577份外洩檔案的真相,揭露了中國對各國進行的駭客網路攻擊,和輿論操控的「認知戰」! 一場沒有煙硝的戰爭已開打...​​╔════════════╗📺【#解碼中國外洩文件】𝘿𝙚𝙘𝙤𝙙𝙞𝙣𝙜 𝙩𝙝𝙚 𝘾𝙝𝙞𝙣𝙚𝙨𝙚 𝘿𝙤𝙘𝙪𝙢𝙚𝙣𝙩 𝙇𝙚𝙖𝙠𝙨📺 𝟭𝟬/ 𝟵 (四) 𝟮𝟮:𝟬𝟬|公視紀錄觀點🈶 公視YT網路直播🈶 公視+免費線上看(2025/10/10~2026/10/9)╚════════════╝​​.ᐟ.ᐟ NHK重磅調查報導紀錄片 .ᐟ.ᐟ.ᐟ.ᐟ 中國「安洵資訊」檔案外洩事件 .ᐟ.ᐟ.ᐟ.ᐟ 7國專家聯手調查 577份洩密文件.ᐟ.ᐟ.ᐟ.ᐟ 揭露中國對各國進行駭客攻擊&認知戰.ᐟ.ᐟ.ᐟ.ᐟ 一場沒有煙硝的戰爭早已開打.ᐟ.ᐟ ..#紀錄觀 #紀錄片 #公視 #中國 #認知戰 #安洵文件 #網路攻擊
www.instagram.com
October 12, 2025 at 7:49 AM
Great report from SentinelOne, Recorded Future and TeamT5 about China's use of ransomware to provide cover for espionage campaigns

Confirms some of what I reported about the attack on the government of Palau earlier this year

therecord.media/chamelgang-c...
Suspected Chinese gov’t hackers used ransomware as cover in attacks on Brazil presidency, Indian health org
Hackers believed to be working for the Chinese government are increasingly deploying ransomware in an effort to cause disruption and provide cover for espionage operations — most notably in attacks on...
therecord.media
June 27, 2024 at 10:04 PM
Wie chinesische Hacker mit einer Word-Datei Russland ausspionieren wollten – Der Spiegel: „Den Anhang haben Cyberexperten der taiwanischen Sicherheitsfirma TeamT5 entdeckt und mit dem SPIEGEL geteilt.“
(S+) Wie chinesische Hacker mit einer Word-Datei Russland ausspionieren wollten
Peking ist Putins wichtigster Partner, doch Misstrauen bleibt: China will Moskaus Kriegswissen abschöpfen. Vor allem auf die russische Luftfahrt- und Drohnenexpertise haben es Spione abgesehen.
www.spiegel.de
August 31, 2025 at 10:16 AM
www.chosun.com/english/indu...

I knew this day would go back on 2008.

I have a U.S. Patent on any advanced threat management system to stop cyber attacks including AI based.

Unfortunately due to funding requirements we were not able to fund it.
Chinese Hackers Escalate Cyberattacks Using Open-Source AI
Chinese Hackers Escalate Cyberattacks Using Open-Source AI Chinese hackers use DeepSeek AI to escalate cyberattacks, TeamT5 finds
www.chosun.com
August 25, 2026 at 3:51 PM