The CrowdStrike 2026 Technology Threat Landscape Report highlights that the technology sector remains the primary target for both state-sponsored and eCrime adversaries. China-nexus actors focus on intellectual property theft and AI capabilities, while DPRK-nexus actors leverage fraudulent employment and open-source supply chain compromises (such as the Axios npm package). Additionally, eCrime groups are accelerating extortion operations and exploiting AI trends to distribute malware like macOS infostealers.
China-nexus
7 posts
CrowdStrike 2026 Technology Threat Landscape Report: China’s Ambitions Fuel Attacks Intelligence Center Cisco Talos identified UAT-8302, a China-nexus APT, targeting global government entities using a diverse toolkit of custom and shared malware. The threat actor leverages DLL side-loading to deploy implants like NetDraft, CloudSorcerer v3, and VSHELL, while utilizing open-source tools for extensive network reconnaissance, credential harvesting, and lateral movement.
International cyber agencies share fresh advice to defend against China-linked covert networks An international coalition of cyber agencies has issued a joint advisory warning that China-linked threat actors are leveraging covert networks of compromised edge devices to disguise their attacks. The advisory highlights the growing problem of 'IOC extinction' and urges organizations to shift towards dynamic threat filtering and behavioral baselining of edge device traffic to maintain effective defense.
Executive Summary: Defending against China-nexus covert networks of compromised devices China-nexus threat actors are increasingly leveraging compromised SOHO and edge devices to form dynamic covert networks. These botnets facilitate various stages of cyber attacks while rendering traditional static indicators of compromise obsolete, necessitating adaptive defense strategies like traffic baselining and zero trust architecture.
Defending against China-nexus covert networks of compromised devices China-nexus cyber actors have strategically shifted to utilizing large-scale covert networks of compromised SOHO and IoT devices to obfuscate their operations. These dynamic botnets, such as Raptor Train and KV Botnet, facilitate deniable access and complicate traditional static IOC-based defense, requiring organizations to adopt behavioral baselining and dynamic threat intelligence.
Defending Against China-Nexus Covert Networks of Compromised Devices China-nexus threat actors are increasingly utilizing large-scale covert networks of compromised SOHO routers and IoT devices to obfuscate their operations and route malicious traffic. This strategic shift renders traditional static IOC blocklists ineffective, requiring defenders to adopt behavioral profiling, zero trust principles, and active network hunting to detect multi-hop proxy traffic.
China-nexus Group Targets Persian Gulf Region | ThreatLabz A China-nexus threat actor, assessed with medium confidence as Mustang Panda, targeted the Persian Gulf region using a multi-stage attack chain themed around the Middle East conflict. The campaign leverages LNK and CHM files to execute a heavily obfuscated shellcode loader via DLL sideloading, ultimately deploying a PlugX backdoor capable of HTTPS and DNS-over-HTTPS (DoH) C2 communications.