logo

Chinese Weaver Ant hackers spied on telco network for 4 years

ID: dcb099c2-175b-5199-937e-495e3657a738

STIX ID: report--dcb099c2-175b-5199-937e-495e3657a738

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Weaver Ant, a China-linked APT, operated for more than four years inside a major Asian telecom provider by compromising Zyxel CPE routers and deploying web shells (China Chopper variants and a custom INMemory DLL-based loader) to create a covert internal proxy network (‘web-shell tunneling’), enabling stealthy credential harvesting, lateral movement, and passive data collection for sustained espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.