logo

45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation

ID: f393563a-cef1-5d9c-94d9-b319b89d1638

STIX ID: report--f393563a-cef1-5d9c-94d9-b319b89d1638

Feed Name: HackRead

Threat Score
80/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Deeba Ahmed

...
...

SOCRadar researchers uncovered a large, automated cybercrime operation linked to actors in China that uses a centralized backend (Paperclip) and an agent workflow (OpenClaw) to mass-scan internet-facing assets, exploit RCE vulnerabilities (e.g., Log4Shell and cited CVEs), deploy backdoors (d2, pl) and webshells, and steal sensitive data such as AI API keys, Stripe tokens, and database credentials; attacker logs report ~45,000 attack attempts and thousands of compromised hosts, indicating a high-scale, organized criminal campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.