Chinese state hackers target telcos with new malware toolkit
2026-03-06T01:23:32Z•8d4b574241652d1f5ff62ea67a100c7b29b2071ce08197a7ad5cd3e4166e3cfa
Bing AIBitwardenChina state‑linkedCiscoFreeScoutGitHubJavaScript wormMail2ShellOpenClawSD‑WANSecure FMCUAT-9244User Registration & Membership pluginWikimediaWordPressactive exploitationinfo stealermalware toolkitpasskeysphishingprivilege escalationproxy malwaretelecomszero‑click RCEzero‑day
What happened
Multiple high-impact security incidents and active exploitations across enterprise and consumer software were reported: a China-linked APT (UAT-9244) is targeting South American telcos with a new cross‑platform malware toolkit; GitHub-hosted fake OpenClaw installers promoted via Bing AI distributed info‑stealers and proxy malware; a self‑propagating JavaScript worm vandalized Wikimedia pages; a critical WordPress User Registration & Membership plugin flaw is being abused to create admin accounts; a zero-click RCE (Mail2Shell) affects FreeScout mail servers; Cisco disclosed maximum‑severity and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8d4b574241652d1f5ff62ea67a100c7b29b2071ce08197a7ad5cd3e4166e3cfa
- Enrichment time
- 2026-03-06T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.