logo

Chinese APT Hackers Using Proxy and VPN Service to Anonymize Infrastructure

ID: a96adc90-b4e0-5531-a35c-99aa449b0c41

STIX ID: report--a96adc90-b4e0-5531-a35c-99aa449b0c41

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-08-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** Researchers report a sustained Chinese APT campaign that weaponized a zero-day Office RCE (CVE-2025-1234) to deploy a Go-based Trojan proxy which tunnels C2 and exfiltration through WgetCloud VPN exit nodes, leveraging wildcard TLS certificates (*.appletls.com) on ports 4000–4099 to evade detection and steal intellectual property from targets in South Korea and Taiwan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.