Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks

2026-05-21T14:51:44Z148acb5ca2c76b94a3427df3d6051b1977557132b6d84517d99a5b3e7b023679
APTAndroid carrier-billing fraudCISA exposureCVE-2026-42897CVSS 10.0China-linked actorsCisco SD‑WANFamousSparrowGitHub breachLinux backdoorMicrosoft ExchangeOT/ICSRubyGemsShowboatUnderminrbrand hijackingcommand injectiondata theftdomain-frontingmalicious packagesmobile malwarerobotics vulnerabilitysupply chain compromisetelco attackszero-day

What happened

A batch of DarkReading stories highlights an active, high-risk threat landscape: China-linked APTs (Showboat, FamousSparrow) are deploying Linux backdoors against telcos and energy firms; multiple high-severity vulnerabilities are being exploited in the wild (including a Microsoft Exchange zero-day); a CVSS 10.0 Cisco SD‑WAN bug and a critical OT robot OS command-injection flaw are causing urgent remediation calls; and large-scale data incidents (GitHub repo theft, CISA secrets exposure) and weaponized supply-chain channels (malicious RubyGems, poisoned packages) are increasing attacker reach.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
148acb5ca2c76b94a3427df3d6051b1977557132b6d84517d99a5b3e7b023679
Enrichment time
2026-05-21T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks · Baitaphish