EPISODE · Oct 15, 2025 · 4 MIN
China's Cyber Spies Caught Red-Handed: Hacking Russia, Infiltrating Taiwan, and Pwning the Cloud!
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here with your Cyber Sentinel: Beijing Watch update, and buckle up because Chinese threat actors have been absolutely relentless this past week. Let's start with Jewelbug, a Chinese hacking collective that just pulled off something remarkable. Broadcom-owned Symantec just revealed that Jewelbug spent five months embedded inside a Russian IT service provider from January through May this year. Yeah, you heard that right, China hacking Russia. Despite all the diplomatic backslapping between Moscow and Beijing, espionage apparently knows no borders. These attackers had their hands in code repositories and software build systems, positioning themselves perfectly for supply chain attacks against Russian customers. What makes this particularly sneaky is they were exfiltrating data through Yandex Cloud, essentially hiding in plain sight using legitimate Russian infrastructure. But Jewelbug wasn't done. They also hit a large South American government organization in July, deploying a brand new backdoor that uses Microsoft Graph API and OneDrive for command and control. This is textbook tradecraft, blending malicious traffic with normal business operations to avoid detection. The malware collects system information, enumerates files, and uploads everything to OneDrive. Good luck spotting that in your network logs. The technical sophistication here is impressive. Jewelbug leveraged a renamed Microsoft Console Debugger to bypass application allowlisting, dumped credentials using tools like LSASS and Mimikatz, and deployed the KillAV tool to disable security software. They also used publicly available privilege escalation tools with names like PrintNotifyPotato and Sweet Potato. When they hit a Taiwanese company last year, they deployed ShadowPad, a backdoor exclusively used by Chinese state-linked groups. Meanwhile, Taiwan's National Security Bureau is sounding alarm bells about escalating Chinese cyber attacks targeting government departments. They're also calling out Beijing's online troll army for spreading fabricated content across social networks, trying to undermine trust in Taiwan's government and create friction with the United States. Chinese threat actors aren't just targeting governments either. According to recent reports, they're leveraging geo-mapping technology and custom remote access trojans to infiltrate critical infrastructure across Asia and North America. The targeting scope is expanding rapidly. So what's the strategic takeaway? Chinese cyber operations are diversifying targets geographically and technically. They're using legitimate cloud services and native operating system tools to maintain stealth. The shift toward supply chain positioning shows they're thinking long-term about access and impact. For defenders, this means assume breach mentality is critical. Monitor your cloud service usage patterns, especially Microsoft Graph API and OneDrive traffic. This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
China's Cyber Spies Caught Red-Handed: Hacking Russia, Infiltrating Taiwan, and Pwning the Cloud!
No transcript for this episode yet
Similar Episodes
No similar episodes found.