EU sanctions Chinese and Iranian actors over cyberattacks on critical infrastructure

2026-03-18T02:51:47Z2596a93afa537b63d59a7888d2d608c2c0aa24343356ffa3031aa5962229b9b6
APTCL-STA-1087CVE-2025-47813ClickFixDRILLAPPFBI inquiryLaundry BearRondoDoxSteam malwareStrykeraccessibility-apiandroid-17botnetcritical infrastructuredata-wipingespionageinfostealerknown-exploited-vulnerabilitiesmacOSsanctionssignal-account-takeoversocial engineeringvulnerability exploitationwing-ftp

What happened

Feed of March 16–17, 2026 cyber news: The EU imposed sanctions on Chinese and Iranian companies/individuals for cyberattacks on critical infrastructure. The RondoDox botnet dramatically increased activity, targeting 174 vulnerabilities with up to ~15,000 daily exploit attempts. China-linked CL-STA-1087 has conducted long-running espionage against Southeast Asian militaries using AppleChris and MemFun. ClickFix social-engineering campaigns are shifting to macOS and using ChatGPT-style lures to deploy infostealers (e.g., AMOS). A malware-free attack against Stryker’s Microsoft environment wiped/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2596a93afa537b63d59a7888d2d608c2c0aa24343356ffa3031aa5962229b9b6
Enrichment time
2026-03-18T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.