Chinese state hackers target telcos with new malware toolkit
2026-03-06T07:23:28Z•cbb3f266dee466b34d736dab127d679f609fefbccc0c33919c1330f574cc45e4
AI-search-abuseAPTBing-AICiscoFreeScoutGitHubLinuxMail2ShellSD-WANSecure-FMCWindowsWordPressactive-exploitationchina-linkedinformation-stealermalware-toolkitnetwork-edgeplugin-exploitprivilege-escalationremote-code-executionsupply-chaintelecom-targetingvulnerability-managementzero-clickzero-day
What happened
Multiple high-impact security incidents and active exploitations were reported across enterprise, cloud, and consumer ecosystems. A China-linked APT (UAT-9244) has targeted South American telecommunications providers with a cross-platform malware toolkit affecting Windows, Linux, and network-edge devices; Cisco disclosed actively exploited SD-WAN and Secure FMC vulnerabilities (maximum severity/root access); a Mail2Shell zero-click RCE affecting FreeScout and a critical WordPress User Registration & Membership plugin flaw are being actively exploited to gain remote code execution and create管理员
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- cbb3f266dee466b34d736dab127d679f609fefbccc0c33919c1330f574cc45e4
- Enrichment time
- 2026-03-06T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.