logo

China's APT40 gang is ready to attack vulns within hours or days of public release

ID: fb77fb04-ce1b-50fa-a5a7-7f0610dbfb66

STIX ID: report--fb77fb04-ce1b-50fa-a5a7-7f0610dbfb66

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-07-09

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

An eight-nation advisory profiles China-aligned APT40 (aka Kryptonite Panda) as a state-sponsored actor that rapidly weaponizes exploit proof-of-concepts—often within hours—to target known and historical vulnerabilities (e.g., Log4J, Confluence, Exchange), leverages compromised SOHO devices as operational infrastructure and last-hop redirectors, employs web shells and credential theft to gain persistence, and deploys malware to exfiltrate data; the advisory includes mitigation guidance, links to malware samples, and case studies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.