Microsoft said it disrupted infrastructure used by the China-based threat group NICKEL after obtaining a federal court order in Virginia to seize malicious domains and redirect them to Microsoft-controlled servers. The company said the domains supported intrusions against organizations in the United States and 28 other countries, with victims including government agencies, ministries of foreign affairs, diplomatic entities, think tanks, and human rights organizations across Latin America and Europe.
According to Microsoft, NICKEL used stealthy malware, stolen spear-phishing credentials, compromised third-party VPN suppliers, and exploits targeting unpatched on-premises Exchange Server and SharePoint systems to conduct intelligence-gathering operations. Court records show Microsoft filed a civil action against unidentified operators controlling the domains and secured emergency relief, including a temporary restraining order, preliminary injunctions, discovery authority, and ultimately a default judgment with a permanent injunction to disable the infrastructure and preserve evidence.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced that its Digital Crimes Unit had disrupted infrastructure used by Nickel and described the group's targeting of government agencies, think tanks, human rights organizations, diplomatic entities, and ministries of foreign affairs in the United States and 28 other countries. Microsoft also said Nickel used stealthy malware, compromised third-party VPN suppliers, stolen spear-phishing credentials, and exploits against unpatched on-premises Exchange and SharePoint systems.
A legal notice for Microsoft's civil case against John Does 1-2 was first published, describing allegations that the defendants controlled domains used in a cybercriminal operation targeting Microsoft and its customers. The notice also outlined requested relief including disabling and preserving the domains.
Microsoft filed pleadings with the U.S. District Court for the Eastern District of Virginia seeking authority to take control of websites allegedly used by Nickel in attacks. The action was part of a civil lawsuit against John Does tied to the malicious domains.
Microsoft said it had analyzed the specific Nickel activity described in the reports since 2019. The campaign targeted organizations for intelligence gathering across multiple regions.
Microsoft said its Threat Intelligence Center had tracked the China-linked threat group Nickel since 2016. The group is also referred to by other researchers as KE3CHANG, APT15, Vixen Panda, Royal APT, and Playful Dragon.
After obtaining court authority, Microsoft redirected traffic from the malicious websites to Microsoft-controlled secure servers. Microsoft said this both protected victims and gave it additional visibility into Nickel's operations.
A federal court in Virginia granted Microsoft's request to seize malicious websites used by Nickel, later unsealing the order after service on hosting providers was completed. Microsoft said the action cut off Nickel's access to victims and prevented the sites from being used in further attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourceblogs.microsoft.com
Open sourcenoticeofpleadings.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.