CL-STA-0048: China-Nexus Espionage Cluster
CL-STA-0048 is a China-nexus espionage cluster that has been linked to the exploitation of SAP NetWeaver vulnerabilities, including CVE-2025-31324.
CL-STA-0048 is a China-nexus espionage cluster that has been linked to the exploitation of SAP NetWeaver vulnerabilities, including CVE-2025-31324.
UNC5221 is a China-nexus espionage cluster that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, to compromise targets. The group is known…
Moonshot AI is one of three Chinese firms accused by Anthropic of running industrial-scale campaigns to extract Claude's capabilities for their own…
MiniMax is another Chinese firm accused by Anthropic of illegally extracting Claude's capabilities to improve its own models.
Zhejiang Fengwo IoT Technology Co., Ltd. is a mainland China company founded in 2019, attributed by Bitsight to the Fuyao ad fraud…
CNCERT is China's national computer emergency response team. It jointly tracks the Dysphoria IoT botnet with XLab and published analysis on its…
Chinese security company whose Xingtu Lab contributed to the research on Android AI agent vulnerabilities.
A Chinese asset-search service whose key was found alongside the Hermes agent's web interface password on the staging server.
UAT-7810 is a Chinese advanced persistent threat (APT) actor responsible for maintaining and proliferating LapDogs, an Operational Relay Box (ORB) network. The…
UAT-5918 is a China-nexus threat actor that has leveraged ORB networks maintained by UAT-7810 to conduct cyber attacks targeting critical infrastructure entities…