Chinese state hackers target telcos with new malware toolkit

2026-03-06T01:23:32Z8d4b574241652d1f5ff62ea67a100c7b29b2071ce08197a7ad5cd3e4166e3cfa
Bing AIBitwardenChina state‑linkedCiscoFreeScoutGitHubJavaScript wormMail2ShellOpenClawSD‑WANSecure FMCUAT-9244User Registration & Membership pluginWikimediaWordPressactive exploitationinfo stealermalware toolkitpasskeysphishingprivilege escalationproxy malwaretelecomszero‑click RCEzero‑day

What happened

Multiple high-impact security incidents and active exploitations across enterprise and consumer software were reported: a China-linked APT (UAT-9244) is targeting South American telcos with a new cross‑platform malware toolkit; GitHub-hosted fake OpenClaw installers promoted via Bing AI distributed info‑stealers and proxy malware; a self‑propagating JavaScript worm vandalized Wikimedia pages; a critical WordPress User Registration & Membership plugin flaw is being abused to create admin accounts; a zero-click RCE (Mail2Shell) affects FreeScout mail servers; Cisco disclosed maximum‑severity and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8d4b574241652d1f5ff62ea67a100c7b29b2071ce08197a7ad5cd3e4166e3cfa
Enrichment time
2026-03-06T01:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.