Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Web Hosting Firms in Taiwan Attacked by Chinese APT for Access to High-Value Targets

Posted on August 18, 2025August 18, 2025 By CWS

Hosting entities in Taiwan have been within the crosshairs of a Chinese language APT trying to set up long-term entry to high-value targets, Cisco Talos reviews.

Tracked as UAT-7237 and believed to be energetic since 2022, the risk actor is probably going a division of the hacking group that Talos tracks as UAT-5918, which overlaps with Chinese language APTs reminiscent of Volt Hurricane and Flax Hurricane.

In response to Talos, nevertheless, UAT-7237’s use of Cobalt Strike, its deployment of internet shells on choose techniques solely, and its use of RDP entry and of a official VPN consumer recommend the APT represents a separate cluster of exercise below the UAT-5918 umbrella.

Throughout a latest intrusion at a internet hosting supplier in Taiwan, UAT-7237 was seen exploiting identified vulnerabilities in internet-facing servers for preliminary entry, conducting reconnaissance, and deploying the SoftEther VPN software program for distant entry.

For reconnaissance and lateral motion, the risk actor used a mixture of available instruments and Home windows Administration Instrumentation (WMI)-based utilities, reminiscent of SharpWMI and WMICmd.

Alongside numerous open supply instruments, UAT-7237 was noticed deploying a customized shellcode loader dubbed SoundBill, which is written in Chinese language and accommodates two executables originating from the Chinese language prompt messaging software program QQ.

SoundBill, Talos says, can load payloads starting from customized Mimikatz implementations to code resulting in arbitrary command execution, or Cobalt Strike payloads for long-term information-stealing entry.

UAT-7237 was additionally seen counting on the privilege escalation device JuicyPotato for command execution, altering the OS configuration of the compromised techniques, enabling storage of cleartext passwords, and utilizing numerous instruments for credential exfiltration.Commercial. Scroll to proceed studying.

The risk actor additionally used community scanning instruments reminiscent of Fscan and SMB scans to find different endpoints on the community, and deployed the SoftEther VPN consumer to take care of entry to the compromised techniques.

As a result of the distant server internet hosting SoftEther VPN was created in September 2022, Talos believes that the APT has been utilizing the distant entry software program for over two years.

Associated: Report Hyperlinks Chinese language Firms to Instruments Utilized by State-Sponsored Hackers

Associated: Chinese language Researchers Counsel Lasers and Sabotage to Counter Musk’s Starlink Satellites

Associated: Canada Provides Hikvision the Boot on Nationwide Safety Grounds

Associated: Chinese language APT Hacking Routers to Construct Espionage Infrastructure

Security Week News Tags:Access, APT, Attacked, Chinese, Firms, HighValue, Hosting, Taiwan, Targets, Web

Post navigation

Previous Post: HR Giant Workday Discloses Data Breach After Hackers Compromise Third-Party CRM
Next Post: Wazuh for Regulatory Compliance

Related Posts

Critical Vulnerability Exposes Many Mitel MiCollab Instances to Remote Hacking Security Week News
Prison Sentence for Man Involved in SEC X Account Hack Security Week News
Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack Security Week News
Trial Opens Against Meta CEO Mark Zuckerberg and Other Leaders Over Facebook Privacy Violations Security Week News
Virtual Event Preview: Cloud & Data Security Summit – Tackling Exposed Attack Surfaces in the Cloud Security Week News
Scattered Spider Activity Drops Following Arrests, but Others Adopting Group’s Tactics Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • RapperBot Botnet Disrupted, American Administrator Indicted
  • Seemplicity Raises $50 Million for Exposure Management Platform
  • Discover and Control Shadow AI Agents in Your Enterprise Before Hackers Do
  • Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data
  • RingReaper Malware Attacking Linux Servers Evading EDR Solutions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • RapperBot Botnet Disrupted, American Administrator Indicted
  • Seemplicity Raises $50 Million for Exposure Management Platform
  • Discover and Control Shadow AI Agents in Your Enterprise Before Hackers Do
  • Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data
  • RingReaper Malware Attacking Linux Servers Evading EDR Solutions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News