A long-term Chinese cyber espionage operation that has been active since at least 2017 and has a count of at least 53 victims has been substantially disrupted, according to the Google Threat Intelligence Group (GTIG) and Mandiant.
Anthropic's calls the incident the "first reported AI-orchestrated cyber espionage campaign" and has attributed it with high confidence to a Chinese state-sponsored group it calls GTG-1002. The campaign took place in mid-September and the integration of AI agents for performance of autonomous tasks is described as unprecedented.
Chinese malware deployed by a state-sponsored advanced persistent threat group is targeting critical industries and their downstream customers in a prolonged cyber espionage campaign.
Chinese APT group Weaver Ant breached and maintained a foothold on a large Asian telco network for four years using compromised Zyxel CPE routers for cyber espionage.
State-sponsored hackers from Russia, China, Iran, and North Korea are exploiting Windows shortcut files to execute malicious commands for cyber espionage.
North Korean hackers are using ClickFix social engineering tactics to compromise devices and perform data exfiltration in a highly focused cyber espionage campaign.
A recent confirmed T-Mobile hack has been attributed to Salt Typhoon, the Chinese cyber espionage team that also breached Verizon and AT&T earlier in the year. That means the hackers were able to penetrate all three of the country's major mobile carriers in 2024.
Microsoft and the U.S. Department of Justice have seized over 100 domains used by Kremlin-backed Russian hackers Star Blizzard for cyber espionage against the West.
A known state-sponsored hacking group from China has been sanctioned by the US Treasury Department for a campaign of cyber attacks over the past decade, and has been named by the UK's National Cyber Security Centre (NCSC) as the culprit in a 2021 cyber espionage campaign against parliamentarians.
The assessment of the damage from the recent cyber espionage campaign by Chinese hackers has now been revised and greatly expanded, with more senior officials and ambassadors confirmed to have been targeted and potentially "hundreds of thousands" of email accounts breached.










