Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
2026-05-21T14:51:44Z•148acb5ca2c76b94a3427df3d6051b1977557132b6d84517d99a5b3e7b023679
APTAndroid carrier-billing fraudCISA exposureCVE-2026-42897CVSS 10.0China-linked actorsCisco SD‑WANFamousSparrowGitHub breachLinux backdoorMicrosoft ExchangeOT/ICSRubyGemsShowboatUnderminrbrand hijackingcommand injectiondata theftdomain-frontingmalicious packagesmobile malwarerobotics vulnerabilitysupply chain compromisetelco attackszero-day
What happened
A batch of DarkReading stories highlights an active, high-risk threat landscape: China-linked APTs (Showboat, FamousSparrow) are deploying Linux backdoors against telcos and energy firms; multiple high-severity vulnerabilities are being exploited in the wild (including a Microsoft Exchange zero-day); a CVSS 10.0 Cisco SD‑WAN bug and a critical OT robot OS command-injection flaw are causing urgent remediation calls; and large-scale data incidents (GitHub repo theft, CISA secrets exposure) and weaponized supply-chain channels (malicious RubyGems, poisoned packages) are increasing attacker reach.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 148acb5ca2c76b94a3427df3d6051b1977557132b6d84517d99a5b3e7b023679
- Enrichment time
- 2026-05-21T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.