logo

Chinese hackers hide on military and govt networks for 6 years

ID: 9eb26b09-ea80-5440-8e87-722230828d2e

STIX ID: report--9eb26b09-ea80-5440-8e87-722230828d2e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-05-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Bitdefender investigation profiles "Unfading Sea Haze," a China-aligned APT active since 2018 against South China Sea military and government targets. Attacks begin with spear-phishing ZIPs containing LNK files that run obfuscated PowerShell, abuse msbuild.exe to load fileless C# backdoors (SerialPktdoor) from remote SMB shares, and deploy Gh0stRAT variants, keyloggers, and custom exfiltration tools; the group also uses RMM tool abuse, local administrator account manipulation, DLL side-loading, and evolving exfiltration methods. Recommended defenses include patching, MFA, network segmentation, traffic monitoring, and modern detection/response tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.