Chinese state-linked intrusion groups have continued broad cyberespionage operations against governments, critical infrastructure, telecommunications, finance, technology, and research organizations across Europe, Southeast Asia, Russia, the United States, and other regions. Public reporting from ENISA/CERT-EU, CISA, and private threat intelligence firms links multiple campaigns to clusters including APT27, APT30, APT31, GALLIUM, Mustang Panda, APT41/RedGolf, TA459, and RedHotel, with activity focused on information theft, persistent access, and in some cases economic espionage. Authorities and researchers said these actors repeatedly exploited exposed enterprise systems such as Microsoft Exchange, SharePoint, Zimbra, Pulse Connect Secure, Citrix ADC, F5 BIG-IP, VMware vCenter, Atlassian Confluence, and ManageEngine, while also using spear-phishing, EU-themed lures, and spoofed domains to gain entry.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
25 events from the most recent confirmed update back to the earliest known activity.
On 6 December 2023, Splunk Threat Research published an analysis of a PlugX variant that uses DLL side-loading via msbtc.exe and a malicious version.dll to decrypt and load a headless payload. Splunk also released a Python extraction tool, plugx_extractor.py, and related detections to help defenders identify the malware.
On 7 September 2023, Sekoia published a report summarizing recent China-nexus cyber operations, including increased targeting of Europe, finance, governments, critical infrastructure, and dissident communities. The report highlighted the maturing threat landscape and broader operational scope since 2020.
Recorded Future said RedHotel infrastructure served a stolen TLS certificate belonging to Vietnam’s Ministry of Education and Training, and that the actor was still using it as of June 2023. This showed continued operational use of compromised Vietnamese assets and certificates.
On 15 February 2023, ENISA and CERT-EU published a joint warning that APT27, APT30, APT31, Ke3chang, GALLIUM, and Mustang Panda had recently conducted malicious cyber activity against businesses and governments in the European Union. The publication said the actors posed important and ongoing threats focused mainly on information theft through persistent access.
On 6 October 2022, NSA, CISA, and the FBI issued a joint advisory identifying the top CVEs exploited since 2020 by PRC state-sponsored cyber actors. The agencies warned that these actors continued targeting U.S. and allied government, civilian, critical infrastructure, and technology networks.
CERT-EU and ENISA said Intrinsec reported in October 2022 that APT27 exploited the ProxyLogon vulnerability chain on an unnamed customer’s Microsoft Exchange server. The compromise reportedly affected five domains over nine months and led to exfiltration of many gigabytes of data using HyperBro malware.
On 18 July 2022, Belgium urged Chinese authorities to act against malicious cyber activities linked to APT27, APT30, APT31, and GALLIUM. The statement followed an espionage campaign against Belgium’s Interior and Defence Ministries.
Recorded Future reported that RedHotel likely compromised a U.S. state legislature in July 2022. Infrastructure linked to the victim communicated with RedHotel-attributed ShadowPad and Cobalt Strike command-and-control servers.
CERT-EU and ENISA said Palo Alto Networks Unit 42 identified GALLIUM activity in June 2022 and reported that the group had expanded beyond telecommunications into government and finance, including at least one European country. This marked a broadening of the actor’s victimology.
Recorded Future reported that in late 2022, RedHotel used Brute Ratel C4 signed with a stolen code-signing certificate belonging to Wanin International Co., Ltd. The payload communicated with compromised Vietnamese government infrastructure at isos[.]gov[.]vn.
CERT-EU said it detected exploitation attempts in 2021 and 2022 against some EU institutions, bodies, or agencies that were likely linked to Ke3chang. The activity involved attempts against public-facing systems.
CERT-EU and ENISA said Germany’s Bundesamt für Verfassungsschutz published information in January 2022 about an ongoing data-gathering campaign affecting German companies that it attributed to APT27. The disclosure highlighted continued Chinese espionage targeting in Europe.
CERT-EU and ENISA said Microsoft reported in December 2021 that Ke3chang targeted several organizations in Europe, Latin America, and other regions, including at least 11 European entities. The activity showed continued targeting of Europe by the actor.
On 19 July 2021, the European Union urged Chinese authorities to act against malicious cyber activities linked to APT31. The statement said the activity had targeted EU and Member State government institutions, political organizations, and key European industries.
CERT-EU and ENISA said ANSSI warned in July 2021 of an ongoing APT31 campaign against a large number of French organizations. The warning highlighted continued China-linked espionage activity in Europe.
CERT-EU and ENISA said Finnish authorities disclosed in March 2021 that their investigation into the December 2020 breach of the Parliament of Finland pointed to APT31. The disclosure tied the intrusion to a China-linked espionage actor.
CERT-EU observed an uptick in Mustang Panda campaigns targeting EU entities from late 2021 to early 2022. The activity affected government and nongovernmental organizations.
Sekoia noted that China introduced vulnerability management regulations in 2021 that support the acquisition and exploitation of zero-days. The report framed the rules as part of the broader Chinese cyber ecosystem.
Sekoia reported that Volt Typhoon, also called Vanguard Panda, had targeted U.S. critical infrastructure including Guam since mid-2021. The activity reflected a China-linked focus on strategically important infrastructure.
Sekoia said China-aligned threat actors have targeted critical national infrastructure and the finance sector since December 2020. This marked a sustained expansion of targeting beyond traditional espionage victims.
CERT-EU and ENISA said APT27 operators had engaged in ransomware-based cybercriminal activity since 2020 in addition to information theft operations. The group continued targeting organizations across Europe and other regions.
Sekoia reported that since 2020, China-nexus cyber espionage campaigns have shown increased risk tolerance and operational tempo. The activity expanded across governments, critical infrastructure, manufacturing, finance, and other sectors worldwide.
NSA, CISA, and the FBI said PRC state-sponsored cyber actors had been exploiting a set of top internet-facing vulnerabilities since 2020 to access government, critical infrastructure, and private-sector networks. The activity included exploitation of flaws in products such as Pulse Secure, Exchange, Confluence, F5 BIG-IP, Citrix ADC, and VMware vCenter.
Recorded Future reported that the Chinese state-sponsored group RedHotel had been active since at least 2019. The group was later observed targeting governments and other sectors across multiple countries.
Proofpoint found evidence that the actor it tracks as TA459 had related activity dating back to 2013, with overlaps to the Saker, Netbot, and DarkStRat malware families. This establishes earlier historical activity preceding the 2015 Russia-focused campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
splunk.com
Open sourceblog.sekoia.io
Open sourcecisa.gov
Open sourceproofpoint.com
Open sourcego.recordedfuture.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcecert.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.