BTC$85,190+0.77% LTC$69.87+3.93% XMR$543.25+0.03%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Oct 1, 2026 · 3 min read · Original story

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments

Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments

Chinese government-backed hacking groups allegedly targeted artificial intelligence companies and several Asian governments in recent campaigns, according to two new reports this week.

On Thursday, researchers at Proofpoint spotlighted an incident from July where a Chinese threat actor conducted multiple phishing attacks by impersonating prominent economists and even a former member of the White House Office of Science and Technology Policy leadership team.

The emails targeted AI experts who worked for universities, think tanks and law firms. The first emails were sent on July 8 and initially impersonated former White House official Lynne Edwards Parker before switching to prominent foreign police expert Heidi Crebo-Rediker.

The lure in the email was the opportunity to join a fake "AI Policy Advisory Committee" or participate in a fictitious Senate report on AI export controls.

“The group first sent benign conversation starter emails, which included calls to action themed around AI policy such as joining an ‘AI Policy Advisory Committee,’ to build rapport and solicit a response from the target,” Proofpoint researchers said.

Once they got a response, the hackers followed up with a URL redirection chain that tried to steal credentials and more. The malicious links led to a OneDrive credential phishing page designed to get victims to provide their login information.

Proofpoint noted that the same group was previously seen targeting people who work for U.S. and Japanese think tanks, defense contractors and universities.

It typically registered domains impersonating legitimate organizations like The Heritage Foundation, the Japan-Taiwan Exchange Association and the office of Japan’s Defense Minister.

Antino backdoor used in Taiwan, India, Philippines

The Proofpoint report came one day after Cisco Talos published an advisory about a new backdoor used by Chinese state-backed groups to target government organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.

Cisco incident responders identified 16 organizations that were either affected or targeted across eight different Asian countries between September 2025 and July 2026.

The hackers used a backdoor called Antino that allowed them to conduct reconnaissance, transfer files and maintain their access to victims. The goal of the campaign was intelligence gathering, according to the researchers.

Most victims were initially targeted with phishing emails and decoy documents to lure victims into responding, clicking on links or downloading malicious files.

“Talos first identified [the group’s] campaign while investigating a spear-phishing campaign directed at Taiwan's academic, think tank, and civil society policy community in March 2026,” Cisco said.

“Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.”

The campaign started in the Philippines and continued until the latest wave in June that targeted organizations in India. In total, Cisco found about 350 compromised endpoints across the eight countries.

The hackers used a variety of lures, including news reports about the Trump administration, invitations spoofing real events, legislative documents and more.

Cisco Talos found overlaps with another campaign identified by researchers at Symantec that saw Chinese state hackers using the Antino backdoor.

References in this story

  1. Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | Proofpoint US www.proofpoint.com Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial
  2. China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor blog.talosintelligence.com Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously…
  3. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side www.security.com China-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run an industrial-scale cryptocurrency fraud business.
  4. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  5. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  6. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  7. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news