logo

Chinese Cybercrime Infrastructure Detected: Automated Exploitation & Harvesting Infrastructure

ID: c743d406-686f-5a66-99fc-fd6a6f189d4a

STIX ID: report--c743d406-686f-5a66-99fc-fd6a6f189d4a

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-05-03

Author: Ameer Owda

...
...

This SOCRadar report details a large-scale, organized Chinese cybercrime operation that automates discovery and exploitation of vulnerable web services, performs credential and secret harvesting (AI API keys, Stripe keys, DB credentials), uses a workflow-driven orchestration backend ('paperclip' / OpenClaw), deploys persistent backdoors and fileless C2, and monetizes stolen data via crypto-tracking and Stripe validation; the report includes evidence of active exploitation, operational scale (tens of thousands of attempts, thousands of backdoors), and multiple IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.