Google exposes China espionage group that’s been lurking in networks undetected since 2023

2026-06-15T20:51:43Z9e1e3252b41fb1d61bb4e66481d1b840740f5bebec321797010fe4eee07564eb
AI export restrictionsAnthropicChina espionageContiFBI takedownFable 5Mythos 5OpenAIOracle PeopleSoftOutsiderRussian espionageShinyHuntersUNC6508Void Blizzardbackdoordeepfakeexport controlsextortioninfluence operationnational securitynon-consensual imageryphishingransomwareunpatched vulnerabilityzero-day

What happened

Multiple CyberScoop reports detail a wave of high-impact cyber activity: Google disclosed a China-linked espionage group (UNC6508) that has been deploying backdoors and remaining undetected since 2023; ShinyHunters is actively exploiting an unpatched Oracle PeopleSoft zero‑day to extort universities; the U.S. shut down or disrupted several major operations — including the FBI takedown of the Outsider phishing infrastructure (causing ~$1.9B in losses), an international shutdown of a massive deepfake porn site, and prosecution of a Conti affiliate and a Russian national tied to the Void Blizzard

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
9e1e3252b41fb1d61bb4e66481d1b840740f5bebec321797010fe4eee07564eb
Enrichment time
2026-06-15T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.