Nanjing Xinjiuwei Network Technology Company
A Chinese company linked to QTFY, described by the FBI as an enabling company for cyber operations against U.S. critical infrastructure.
A Chinese company linked to QTFY, described by the FBI as an enabling company for cyber operations against U.S. critical infrastructure.
The U.S. Department of Justice (DoJ) announced the disruption of two hacking platforms, QScan and QTRouter, operated by the Chinese state-sponsored group…
QTFY is a Chinese state-sponsored hacking group linked to Nanjing Xinjiuwei Network Technology Company. Active since 2018, it has targeted U.S. critical…
Baidu is a Chinese technology company offering CDN services. It confirmed CDN Tsunami vulnerabilities and deployed fixes, also awarding bug bounties.
SneakyChef is a Chinese-speaking threat actor attributed to the use of SpiceRAT, a remote access tool used in espionage operations. The group…
BLOODALCHEMY is a C-based backdoor that is an updated version of Deed RAT, itself a successor to ShadowPad. It was first documented…
Deed RAT is a remote access tool that serves as the predecessor to BLOODALCHEMY. It is part of the malware lineage that…
A suspected China-nexus advanced persistent threat actor exploited CVE-2026-59310 to deploy backdoors and reverse_ssh binaries, leading to Babuk ransomware in some cases.
CL-STA-0048 is a China-nexus espionage cluster that has been linked to the exploitation of SAP NetWeaver vulnerabilities, including CVE-2025-31324.
UNC5221 is a China-nexus espionage cluster that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, to compromise targets. The group is known…