China-linked hackers breach dozens of telecoms, government agencies

This audio is auto-generated. Please let us know if you have feedback.

Hackers working for the Chinese government broke into more than 50 telecommunications companies and government agencies in 42 countries, in a campaign that exploited cloud platforms’ legitimate features to hide the attackers’ tracks.

“The attacker was using API calls to communicate with [software-as-a-service] apps as command-and-control (C2) infrastructure to disguise their malicious traffic as benign,” researchers at Google’s Threat Intelligence Group and Mandiant said in a report on Wednesday.

Google said the “prolific, elusive” China-linked hacker team, which it tracks as UNC2814, “has a long history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas.”

The group breached 53 organizations worldwide as part of the latest campaign, a massive scope that Google said likely reflected “a decade of concentrated effort.”

“Prolific intrusions of this scale are generally the result of years of focused effort and will not be easily re-established,” Google researchers wrote. “We expect that UNC2814 will work hard to re-establish their global footprint.”

UNC2814, which is distinct from the threat actor responsible for Beijing’s Salt Typhoon campaign, “has a history of gaining entry by exploiting and compromising web servers and edge systems,” Google said. Researchers have tracked its activities since 2017.

Commandeering a collaboration platform

In the latest operation — which Google and its partners disrupted last week by seizing the attackers’ infrastructure — the UNC2814 hackers deployed backdoor malware dubbed “GRIDTIDE” that they controlled through an elaborate abuse of the Google Sheets API.

GRIDTIDE looked for commands in cell A1 and then overwrote the cell’s data with a status report on its activities, according to Google’s report. The hackers used nearby cells to transfer additional tools to victim machines and exfiltrate files from them.

“Once the Sheet is prepared, the backdoor conducts host-based reconnaissance,” Google said, including collecting information about the target machine, its user, and its network environment. “This information is then exfiltrated and stored in cell V1 of the attacker-controlled spreadsheet.”

The campaign’s clever techniques and widespread impact highlight “the serious threat facing telecommunications and government sectors, and the capacity for these intrusions to evade detection by defenders,” Google warned.

Although the campaign is distinct from Salt Typhoon, Google said it seemed to have a similar goal, describing it as “consistent with cyber espionage activity in telecommunications, which is primarily leveraged to identify, track, and monitor persons of interest.”

Knocking the attackers offline

In response to the hacking campaign, Google disabled the attackers’ cloud platform access, and the company and its partners sinkholed the threat actor’s web domains.

“We terminated all Cloud Projects controlled by the attacker, effectively severing their persistent access to environments compromised by the GRIDTIDE backdoor,” the researchers wrote.

Google also released indicators of compromise associated with infrastructure the group has been using since 2023, updated its signature-based malware detections to spot GRIDTIDE and provided search queries that its cloud security customers could use to scan for potential compromises in their environments.

The company said it had notified victims of the campaign.

Source link

Visited 1 times, 1 visit(s) today

Related Article

China–Laos Railway logs 42 % jump in cross-border passengers during holiday rush

China–Laos Railway logs 42 % jump in cross-border passengers during holiday rush

Cross-border rail proved to be one of the winners of China’s first fully re-opened Lunar New Year season. Operators of the 1,035-kilometre China–Laos Railway reported handling 12,900 international passenger trips between Kunming and Vientiane from 15 to 23 February—up 41.8 percent on last year’s holiday, with inbound traffic from Laos to China increasing an eye-catching

Pres. Trump addresses tariff ruling in front of Supreme Court justices

Trump makes little mention of China in the longest State of the Union speech

U.S. President Donald Trump shakes hands with members of Congress as he departs following his State of the Union address in the House Chamber of the US Capitol in Washington, DC, on Feb. 24, 2026. Andrew Caballero-Reynolds | AFP | Getty Images BEIJING — U.S. President Donald Trump avoided directly naming China in his State

ET logo

German Chancellor Merz meets Xi Jinping in China to strengthen trade, strategic ties

Beijing: German Chancellor Friedrich Merz met with Chinese leader Xi Jinping in Beijing on Wednesday, hoping to bolster ties with his country’s largest trade partner and high-tech rival as Europe’s biggest economy struggles. Berlin and Beijing want to build on their decades-old economic ties at a time when US President Donald Trump has sparked global

How Xi's military purges could hamper China's ability to fight

How Xi’s military purges could hamper China’s ability to fight

HONG KONG — Chinese President Xi Jinping’s purges of senior military officials run far deeper than previously thought, researchers say, threatening the effectiveness of his People’s Liberation Army. The crackdown, documented in two new studies released Tuesday, includes the recent ouster of Xi’s top two generals. Purges have been a regular occurrence under Xi, but

Toggle View of Key Takeaways

US Signals Steady Tariffs Ahead of China Meeting

Greer said Feb. 25 that the U.S. is seeking to maintain levies on Chinese goods within a range of 35% to 50%, depending on the product. (Aaron Schwartz/CNP/Bloomberg) February 25, 2026 9:30 AM, EST Key Takeaways: U.S. Trade Representative Jamieson Greer said the administration plans to keep tariffs on Chinese goods at 35% to 50%

Panda lovers wave goodbye to a truck believed to be carrying the twin pandas upon a departure from Ueno Zoo in Tokyo on January 27, 2026, heading towards their return to China. (Photo by Kazuhiro NOGI / AFP)

Japan to install missiles near Taiwan: Are China tensions set to spike? | Military News

Japan’s plans to deploy missiles on its westernmost island, close to Taiwan, within five years will further add to the growing tensions with China, analysts say. Japanese defence minister Shinjiro Koizumi said the surface-to-air systems – designed to intercept aircraft and ballistic missiles – will be deployed to Yonaguni island, located about 110km (68 miles)

German Chancellor Friedrich Merz and Chinese Premier Li Qiang attend a signing ceremony at the Great Hall of the People in Beijing, China on February 25, 2026.

German leader arrives in China to press for fair trade, help ending Ukraine war

German Chancellor Friedrich Merz and Chinese Premier Li Qiang attend a signing ceremony at the Great Hall of the People in Beijing, China on February 25, 2026. | Photo Credit: Reuters German Chancellor Friedrich Merz is meeting China’s top leaders on Wednesday (February 25, 2026) at the start of a whirlwind two-day visit to press

China’s AI race: Doubao outpaces Alibaba, Tencent in holiday push

China’s AI race: Doubao outpaces Alibaba, Tencent in holiday push

ByteDance’s Doubao AI chatbot (Source: Shutterstock) ByteDance’s AI chatbot Doubao drew more than 100 million daily active users (DAU) during China’s Lunar New Year holiday, emerging as the clear winner in a fierce user-acquisition battle among the country’s biggest tech firms, according to private survey data. Doubao surpassed 100 million DAUs on February 16, roughly

China restricts exports to 40 Japanese entities with ties to military | News

FILE – Paramilitary soldiers and a police officer with a sniffer dog march past the main entrance gate of China’s Ministry of Commerce, in Beijing, on April 3, 2025. (Andy Wong | AP) BANGKOK — China on Tuesday restricted exports to 40 Japanese entities it says are contributing to Japan’s “remilitarization,” in the latest escalation

China sees record-high tourist numbers, spending during Spring Festival holiday

China sees record-high tourist numbers, spending during Spring Festival holiday

China’s tourism sector showed strong momentum during the Spring Festival holiday, with both visitor numbers and tourism spending hitting record highs. The Ministry of Culture and Tourism on Tuesday reported that during the nine-day holiday, which began on Feb 15 and came to an end on Monday, China recorded 596 million domestic trips, an increase

Nvidia did not immediately respond to a request for comment [File]

Nvidia AI chip not yet sold in China, says US official

Nvidia did not immediately respond to a request for comment [File] | Photo Credit: REUTERS A high-end Nvidia chip that can train and run artificial intelligence systems has not yet been sold to Chinese companies despite softened export restrictions, a US commerce official said Tuesday. The H200 chip had until recently been barred from sale

Apple, Nvidia, Qualcomm and AMD have long ignored a 'China warning' from US government that threatens to 'cripple' American economy if comes true, claims report

Apple, Nvidia, Qualcomm and AMD have long ignored a ‘China warning’ from US government that threatens to ‘cripple’ American economy if comes true, claims report

A report by the New York Times has said that US government officials have for years warned major American tech companies – that included Apple, Nvidia, Qualcomm and AMD about the risk of relying heavily on Taiwan for advanced computer chips. In private briefings held in Washington and Silicon Valley, national security officials have cautioned

A man looks at his phone near a giant image of the Chinese flag on the side of a building in Beijing on Oct. 23, 2017.

China’s Next Cyber Crackdown

Welcome to Foreign Policy’s China Brief. The highlights this week: China considers a sweeping cybercrime law, a date is set for a summit between Trump and Xi, and a plagiarism scandal rocks the Chinese literary scene.   Sign up to receive China Brief in your inbox every Tuesday. China Mulls Cybercrime Reform After changes to existing

China's 2026 Tariff Schedule Targets High-Tech, Healthcare Sectors

New MIIT Rules for 2026

China technology contract registration is undergoing significant changes as the country updates its regulatory framework for technology-related agreements. The new measures from the Ministry of Industry and Information Technology, effective March 1, 2026, redefine how contracts for technology development, transfer, licensing, consulting, and services are reviewed and certified. Companies aiming to access China’s technology-focused tax

China's online transactions rise during Spring Festival holiday

China’s online transactions rise during Spring Festival holiday

China’s online transactions saw a remarkable increase in both volume and value during the just-concluded Spring Festival holiday, data from the People’s Bank of China (PBOC) showed on Tuesday. From Feb 15 to 23, Chinese online payment-clearing house NetsUnion Clearing Corporation and card payment giant China UnionPay processed approximately 39.3 billion online transactions totaling 13.12

A montage of US President Donald Trump in the foreground, with the USS Abraham Lincoln and members of Iran’s police special forces monitoring an area in front of an Iranian flag during a pro-government rally in downtown Tehran, Iran, on January 12 2026, in the background.

Shein’s mysterious founder emerges to hail Chinese roots

Good morning and welcome back to FirstFT Asia. In today’s newsletter: Shein’s mysterious founder emerges China hits Japanese companies with export curbs Trump’s Iran ‘crisis of his own making’ We start in Guangzhou, where the mysterious founder of fast-fashion giant Shein used his first major public appearance yesterday to stress the company’s Chinese roots. What

Why Iran Is Erupting Again—Inside the Largest Protests Since 2022

Iran Nears Deal With China for CM-302 Anti-Ship Missiles Amid Rising US Tensions — UNITED24 Media

Iran is nearing a deal with China to acquire CM-302 anti-ship cruise missiles, aiming to enhance its military capabilities. The missiles, which have a range of 290 kilometers and are designed to evade ship defenses, could pose a serious threat to US naval forces in the region, Reuters reported on February 24. The potential sale comes amid heightened tensions between the US and Iran, with China asserting its role in the

Chinese CM-302 supersonic anti-ship missile displayed at Zhuhai Airshow 2016.

Iran nearing deal with China for supersonic missiles amid US tensions: report

NEWYou can now listen to Fox News articles! Iran is nearing a deal with China to acquire supersonic anti-ship cruise missiles, a move that could significantly raise the stakes in the Middle East as U.S. carrier strike groups assemble within striking distance of the Islamic Republic. Reuters reported Tuesday that Tehran is close to finalizing

0
Would love your thoughts, please comment.x
()
x