China

Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
BetaBeacon
September 8, 2026
Arm's DLSS for Android is set to be released soon, starting with the Xiaomi 18 Fold in China. The new Arm Mali G2-Ultra NX graphics processor inside the custom Xring O3 chip promises to enhance mobile gaming by providing PC-like technologies to improve game performance without using more power. This technology includes AI gaming graphics accelerators that can eliminate jagged edges in games and offer features similar to Nvidia's DLSS, such as AI upscaling, frame generation, and ray reconstruction. The new graphics tech is expected to be available in various devices beyond Chinese phones, including tablets and Chromebooks. The technology is aimed at improving gaming experiences while maintaining battery life and will be integrated into games like Where Winds Meet, Infinity Nikki, and Arena Breakout: Infinite.
AppWizard
September 5, 2026
Go grandmaster Shin Jin-seo became the first human to win against the AI platform KataGo on July 21, achieving victory in an official three-game series with a final score of 2-1. Shin, who is 26 years old, played with a two-stone handicap and initially lost the first match before winning the next two. His victory is significant as it contrasts with the previous defeat of grandmaster Lee Sedol by Google's AlphaGo a decade ago. Shin expressed the desire to challenge AI under more difficult conditions in the future and emphasized the importance of personal strategy over imitating AI moves.
Tech Optimizer
September 5, 2026
The cyber threat group Silver Fox is distributing the ValleyRAT backdoor disguised as a legitimate signed Chinese adware application, specifically bundled with the QN Wallpaper tool. This malware allows attackers to gain comprehensive control over infected machines, enabling them to collect sensitive information, capture screenshots, and deploy additional malicious modules. The attack utilizes DLL sideloading, where a modified version of QN Wallpaper loads a malicious DLL from the same directory, circumventing signature-based security measures. The installer disables Windows Defender, adds itself to autorun entries, and uses the "runas" command to elevate privileges if the user lacks administrator rights. ValleyRAT also marks its process as critical, potentially causing a blue screen of death if terminated. Kaspersky has identified Silver Fox as the likely perpetrator of this campaign, known for similar techniques.
AppWizard
September 4, 2026
Google's Scam Detection feature, initially available only on Pixel devices, is expanding to more Android smartphones, currently accessible on the Galaxy S26 series and potentially coming to vivo phones. Recent findings from the Google Phone app's public beta indicate that Xiaomi may also support this feature, with the Xiaomi 18 Fold being a possible candidate for the initial rollout, although it is currently confirmed only for release in China. Google's Scam Detection uses on-device AI to analyze incoming calls for potential scams, aiming to enhance user security. The feature is still in beta and may have flaws, but improvements are expected as Google refines the technology.
Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
Winsage
September 1, 2026
Windows is the most widely used desktop operating system, but Linux is gaining popularity among government entities globally, driven by a desire for independence from Western software due to geopolitical tensions. France plans to transition government workstations from Windows to Linux as part of a broader European movement for digital sovereignty, with the national police force having migrated 97% of its computers to a customized version of Ubuntu called GendBuntu. Germany is also adopting Linux, with Munich creating a customized distribution called LiMuX and other states like Mecklenburg-Vorpommern shifting to open-source platforms like Nextcloud. In Russia, the government is deploying Astra Linux to reduce reliance on Microsoft products following the Ukraine conflict. China is promoting Kylin OS, a Linux-based system, to achieve software self-sufficiency after the end of support for Windows 10. Governments are increasingly turning to Linux to diminish dependence on American technology and foster digital autonomy.
Tech Optimizer
August 31, 2026
Silver Fox is linked to the distribution of a backdoor malware called ValleyRAT, disguised as the legitimate QN Wallpaper adware application. Once installed, ValleyRAT provides complete control over the compromised machine. The malware uses DLL sideloading to operate under the guise of a legitimate process, bypassing security measures. It disables Windows Defender and adds itself to autorun entries, and can mark its process as critical, causing system crashes if terminated. Kaspersky has identified specific indicators of compromise (IoCs) including hashes, command-and-control servers, and associated domains. In 2026, Kaspersky recorded over 100,000 detections of ValleyRAT affecting more than 1,500 unique users, mainly in China and India.
AppWizard
August 29, 2026
Google has introduced several network security enhancements in Android 17 to improve user privacy. One key feature is Encrypted Client Hello (ECH), which encrypts domain names to prevent external observers from monitoring user activities. ECH is integrated with private DNS and is enabled by default for apps using compatible networking libraries. Google claims to be the first major mobile operating system to implement widespread ECH support. Testing conducted by Jigsaw showed stable connection success rates and minimal interference across various networks. Additional security features in Android 17 include: - Local Network Protection, requiring apps to request permission before accessing devices on a user's home network. - Certificate Transparency, mandating public logging of certificates to detect forged ones. - A 2G Network Shutdown option for mobile operators to disable 2G services, reducing exposure to phishing messages.
Search