Chinese state hackers target telcos with new malware toolkit

2026-03-06T07:23:28Zcbb3f266dee466b34d736dab127d679f609fefbccc0c33919c1330f574cc45e4
AI-search-abuseAPTBing-AICiscoFreeScoutGitHubLinuxMail2ShellSD-WANSecure-FMCWindowsWordPressactive-exploitationchina-linkedinformation-stealermalware-toolkitnetwork-edgeplugin-exploitprivilege-escalationremote-code-executionsupply-chaintelecom-targetingvulnerability-managementzero-clickzero-day

What happened

Multiple high-impact security incidents and active exploitations were reported across enterprise, cloud, and consumer ecosystems. A China-linked APT (UAT-9244) has targeted South American telecommunications providers with a cross-platform malware toolkit affecting Windows, Linux, and network-edge devices; Cisco disclosed actively exploited SD-WAN and Secure FMC vulnerabilities (maximum severity/root access); a Mail2Shell zero-click RCE affecting FreeScout and a critical WordPress User Registration & Membership plugin flaw are being actively exploited to gain remote code execution and create管理员

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
cbb3f266dee466b34d736dab127d679f609fefbccc0c33919c1330f574cc45e4
Enrichment time
2026-03-06T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Chinese state hackers target telcos with new malware toolkit · Baitaphish