logo

US charges Chinese nationals in cyberattacks on Treasury, dissidents and more

ID: 4d8bf9fc-06b1-5a62-9303-e1b52573ac7c

STIX ID: report--4d8bf9fc-06b1-5a62-9303-e1b52573ac7c

Feed Name: The Record from Recorded Future News

Threat Score
89/100

Date Published: 2025-03-05

Date Updated: 2026-05-01

...
...

U.S. authorities unsealed indictments charging multiple Chinese nationals, including officers of PRC security services and employees of the commercial firm i-Soon, with a decade-long cyberespionage and hacking-for-hire operation tied to APT activity (linked to APT27 / Silk Typhoon). The report alleges these actors used tools like PlugX, leased VPS infrastructure, exploited vulnerabilities (including an Ivanti flaw), exfiltrated and brokered stolen data (including a 2024 U.S. Treasury intrusion), and sold access to Chinese state agencies; U.S. agencies seized domains, issued sanctions and placed bounties.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.