Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Web Hosting Firms in Taiwan Attacked by Chinese APT for Access to High-Value Targets

Web Hosting Firms in Taiwan Attacked by Chinese APT for Access to High-Value Targets

Posted on August 18, 2025August 18, 2025 By CWS

Hosting entities in Taiwan have been within the crosshairs of a Chinese language APT trying to set up long-term entry to high-value targets, Cisco Talos reviews.

Tracked as UAT-7237 and believed to be energetic since 2022, the risk actor is probably going a division of the hacking group that Talos tracks as UAT-5918, which overlaps with Chinese language APTs reminiscent of Volt Hurricane and Flax Hurricane.

In response to Talos, nevertheless, UAT-7237’s use of Cobalt Strike, its deployment of internet shells on choose techniques solely, and its use of RDP entry and of a official VPN consumer recommend the APT represents a separate cluster of exercise below the UAT-5918 umbrella.

Throughout a latest intrusion at a internet hosting supplier in Taiwan, UAT-7237 was seen exploiting identified vulnerabilities in internet-facing servers for preliminary entry, conducting reconnaissance, and deploying the SoftEther VPN software program for distant entry.

For reconnaissance and lateral motion, the risk actor used a mixture of available instruments and Home windows Administration Instrumentation (WMI)-based utilities, reminiscent of SharpWMI and WMICmd.

Alongside numerous open supply instruments, UAT-7237 was noticed deploying a customized shellcode loader dubbed SoundBill, which is written in Chinese language and accommodates two executables originating from the Chinese language prompt messaging software program QQ.

SoundBill, Talos says, can load payloads starting from customized Mimikatz implementations to code resulting in arbitrary command execution, or Cobalt Strike payloads for long-term information-stealing entry.

UAT-7237 was additionally seen counting on the privilege escalation device JuicyPotato for command execution, altering the OS configuration of the compromised techniques, enabling storage of cleartext passwords, and utilizing numerous instruments for credential exfiltration.Commercial. Scroll to proceed studying.

The risk actor additionally used community scanning instruments reminiscent of Fscan and SMB scans to find different endpoints on the community, and deployed the SoftEther VPN consumer to take care of entry to the compromised techniques.

As a result of the distant server internet hosting SoftEther VPN was created in September 2022, Talos believes that the APT has been utilizing the distant entry software program for over two years.

Associated: Report Hyperlinks Chinese language Firms to Instruments Utilized by State-Sponsored Hackers

Associated: Chinese language Researchers Counsel Lasers and Sabotage to Counter Musk’s Starlink Satellites

Associated: Canada Provides Hikvision the Boot on Nationwide Safety Grounds

Associated: Chinese language APT Hacking Routers to Construct Espionage Infrastructure

Security Week News Tags:Access, APT, Attacked, Chinese, Firms, HighValue, Hosting, Taiwan, Targets, Web

Post navigation

Previous Post: HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM
Next Post: Wazuh for Regulatory Compliance

Related Posts

French Data Breach Exposes 1.2 Million Bank Accounts French Data Breach Exposes 1.2 Million Bank Accounts Security Week News
Aeternum Botnet Uses Polygon Blockchain for C&C Resilience Aeternum Botnet Uses Polygon Blockchain for C&C Resilience Security Week News
SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations Security Week News
High-Severity Vulnerabilities Patched in VMware Aria Operations, NSX, vCenter  High-Severity Vulnerabilities Patched in VMware Aria Operations, NSX, vCenter  Security Week News
American Airlines Subsidiary Envoy Air Hit by Oracle Hack American Airlines Subsidiary Envoy Air Hit by Oracle Hack Security Week News
Recent GeoServer Vulnerability Exploited in Attacks Recent GeoServer Vulnerability Exploited in Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark