A China-linked advanced persistent threat (APT) group infiltrated a U.S. non-profit organization focused on influencing U.S. government policy on international issues, maintaining access for several weeks in April 2025. The attackers initiated their campaign with mass scanning on April 5, targeting a server using multiple public exploits, including those for Log4j, Atlassian OGNL, Apache Struts, and GoAhead Web Server. After a brief pause, activity resumed on April 16 with connectivity tests and network reconnaissance, followed by the establishment of persistence through a scheduled task that executed msbuild.exe as SYSTEM every hour. This task likely injected code into csc.exe, which then communicated with a command-and-control server at 38.180.83[.]166. The attackers also used DLL sideloading via the legitimate VipreAV component vetysafe.exe to load a malicious DLL (sbamres.dll), a technique previously associated with other Chinese APT groups.
The intrusion demonstrated a focus on stealth and long-term access, with the use of legitimate binaries and scheduled tasks to evade detection. The attackers' tactics, including the use of Imjpuexc (a Microsoft file for East Asian input) to mask activity and the deployment of a custom loader to execute an encrypted payload (likely a remote access trojan) in memory, align with methods seen in other campaigns attributed to Chinese state-sponsored actors. The operation is part of a broader pattern of Chinese cyber-espionage targeting U.S. organizations involved in policy matters, leveraging both legacy and recent vulnerabilities to gain initial access and maintain persistence within high-value networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2025-11-07, reporting also highlighted multiple China-aligned campaigns observed across regions in 2025, including exploitation of misconfigured IIS servers with exposed ASP.NET machine keys. Attackers used this access to deploy the TOLLBOOTH (HijackServer) backdoor, enabling SEO cloaking and web shell functionality.
By 2025-11-07, separate research reported Salt Typhoon exploiting the WinRAR vulnerability CVE-2025-8088 to sideload a DLL that runs shellcode and beacons to mimosa.gleeze[.]com. This was presented as a related development in ongoing China-linked intrusion activity.
By 2025-11-07, Broadcom's Symantec and Carbon Black teams publicly attributed the espionage campaign against the U.S. non-profit to a China-linked threat actor. Researchers said tooling overlapped with several China-nexus clusters, including Salt Typhoon, Earth Estries, Earth Longzhi, Space Pirates, and Kelp, making precise attribution difficult.
During the April 2025 intrusion, the threat actor used the legitimate Vipre antivirus component vetysafe.exe to sideload a malicious DLL named sbamres.dll. This added another stealth mechanism for maintaining access and executing malicious code on the compromised environment.
On 2025-04-16, the attackers progressed to host reconnaissance, established scheduled-task persistence, and likely executed an in-memory remote access trojan. They also used living-off-the-land techniques, including msbuild.exe and code injection into csc.exe, to communicate with command-and-control infrastructure.
On 2025-04-05, attackers began broad scanning activity against a U.S. non-profit involved in influencing U.S. government policy on international issues. The intrusion leveraged multiple known vulnerabilities, including Log4j and Atlassian Confluence flaws, as initial access vectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.