China-Nexus Actor Spy on US Researchers Undetected for a Year

2026-06-15T20:51:45Z66e56b0edf2072c40d2cd5aaa107502c47031779009824a83124ab908f809c34
CISACVE-2025-8088ai-enabled-attackscredential-theftdata-exfiltrationedr-evasionespionagenation-statephishingpolicyprompt-injectionransomwaresoftware-supply-chainsupply-chainvulnerabilitieszero-day

What happened

A surge of high-impact activity across nation‑state espionage, software supply‑chain compromise, and active zero‑day exploitation is featured. Google disrupted a China‑linked campaign that stole RedCAP credentials to spy on U.S. researchers, while multiple groups (China‑linked, North Korean, Russian) and cybercrime affiliates have been exploiting zero‑days and supply‑chain implants (Oracle, Ivanti, Check Point VPN, WinRAR/CVE-2025-8088, Miasma, IronWorm, Hades). Attack techniques are evolving with AI-assisted phishing, automated EDR‑evasion testing, prompt‑injection risks in large models, and警

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
66e56b0edf2072c40d2cd5aaa107502c47031779009824a83124ab908f809c34
Enrichment time
2026-06-15T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · China-Nexus Actor Spy on US Researchers Undetected for a Year · Baitaphish