45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation
ID: f393563a-cef1-5d9c-94d9-b319b89d1638
STIX ID: report--f393563a-cef1-5d9c-94d9-b319b89d1638
Feed Name: HackRead
SOCRadar researchers uncovered a large, automated cybercrime operation linked to actors in China that uses a centralized backend (Paperclip) and an agent workflow (OpenClaw) to mass-scan internet-facing assets, exploit RCE vulnerabilities (e.g., Log4Shell and cited CVEs), deploy backdoors (d2, pl) and webshells, and steal sensitive data such as AI API keys, Stripe tokens, and database credentials; attacker logs report ~45,000 attack attempts and thousands of compromised hosts, indicating a high-scale, organized criminal campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
