China's Cyber Spies Caught Red-Handed: Hacking Russia, Infiltrating Taiwan, and Pwning the Cloud! episode artwork

EPISODE · Oct 15, 2025 · 4 MIN

China's Cyber Spies Caught Red-Handed: Hacking Russia, Infiltrating Taiwan, and Pwning the Cloud!

from Cyber Sentinel: Beijing Watch · host Inception Point AI

This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here with your Cyber Sentinel: Beijing Watch update, and buckle up because Chinese threat actors have been absolutely relentless this past week. Let's start with Jewelbug, a Chinese hacking collective that just pulled off something remarkable. Broadcom-owned Symantec just revealed that Jewelbug spent five months embedded inside a Russian IT service provider from January through May this year. Yeah, you heard that right, China hacking Russia. Despite all the diplomatic backslapping between Moscow and Beijing, espionage apparently knows no borders. These attackers had their hands in code repositories and software build systems, positioning themselves perfectly for supply chain attacks against Russian customers. What makes this particularly sneaky is they were exfiltrating data through Yandex Cloud, essentially hiding in plain sight using legitimate Russian infrastructure. But Jewelbug wasn't done. They also hit a large South American government organization in July, deploying a brand new backdoor that uses Microsoft Graph API and OneDrive for command and control. This is textbook tradecraft, blending malicious traffic with normal business operations to avoid detection. The malware collects system information, enumerates files, and uploads everything to OneDrive. Good luck spotting that in your network logs. The technical sophistication here is impressive. Jewelbug leveraged a renamed Microsoft Console Debugger to bypass application allowlisting, dumped credentials using tools like LSASS and Mimikatz, and deployed the KillAV tool to disable security software. They also used publicly available privilege escalation tools with names like PrintNotifyPotato and Sweet Potato. When they hit a Taiwanese company last year, they deployed ShadowPad, a backdoor exclusively used by Chinese state-linked groups. Meanwhile, Taiwan's National Security Bureau is sounding alarm bells about escalating Chinese cyber attacks targeting government departments. They're also calling out Beijing's online troll army for spreading fabricated content across social networks, trying to undermine trust in Taiwan's government and create friction with the United States. Chinese threat actors aren't just targeting governments either. According to recent reports, they're leveraging geo-mapping technology and custom remote access trojans to infiltrate critical infrastructure across Asia and North America. The targeting scope is expanding rapidly. So what's the strategic takeaway? Chinese cyber operations are diversifying targets geographically and technically. They're using legitimate cloud services and native operating system tools to maintain stealth. The shift toward supply chain positioning shows they're thinking long-term about access and impact. For defenders, this means assume breach mentality is critical. Monitor your cloud service usage patterns, especially Microsoft Graph API and OneDrive traffic. This content was created in partnership and with the help of Artificial Intelligence AI.

Episode metadata supplied by the publisher feed · Published Oct 15, 2025

Embed this episode

NOW PLAYING

China's Cyber Spies Caught Red-Handed: Hacking Russia, Infiltrating Taiwan, and Pwning the Cloud!

0:00 4:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Sentinel: Beijing Watch?

This episode is 4 minutes long.

When was this Cyber Sentinel: Beijing Watch episode published?

This episode was published on October 15, 2025.

Can I download this Cyber Sentinel: Beijing Watch episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!