Researchers link 6 software supply chain attacks, including backdoors in CCleaner and Asus' software update tool, to a group of likely Chinese-speaking hackers
Andy Greenberg / Wired :
Context & Ripple Effects
This story closes a two-year attribution loop. Cisco Talos flagged the CCleaner backdoor in 2017 as a watering-hole aimed at tech firms including Akamai, Cisco, Google, Intel, and Microsoft, but stopped short of naming a campaign; Wired's reporting now ties that implant, the Asus update-tool compromise, and four other incidents into a single likely Chinese-speaking group.
The grouping matters because it converts isolated vendor embarrassments into a pattern: the same actors later show up in the theft of source code, SDKs, and chip designs from Taiwanese chipmakers, suggesting a sustained program rather than opportunistic hits.
First-order effects
- Asus and the CCleaner franchise face renewed scrutiny of their update and signing infrastructure, since both were compromised at exactly the point users trust most — the automatic updater.
- The dozens of tech firms Talos found in the CCleaner target list can now treat their intrusions as part of one campaign, pooling indicators instead of investigating six separate breaches.
Second-order effects
- Software vendors beyond the six victims are pushed to treat their own build-and-update pipelines as attack surface, because the demonstrated technique — poisoning a trusted installer — scales to any vendor with a large installed base.
- Security teams buying endpoint tools must weigh the supplier itself as a risk, a dynamic later echoed when a researcher showed a single open-source ecosystem flaw could breach 35+ companies including Microsoft and Apple.
Third-order effects
- If one group can run six supply chain compromises across years, defense shifts from per-incident response to verifying code provenance end-to-end — a structural burden on every software distributor.
- The trajectory points toward automation: by 2026, suspected Chinese hackers were using open-source AI agents to build autonomous hacking tools against Taiwanese government sites, suggesting the manual tradecraft behind these six attacks is being industrialized.
The trend: Software supply chain attacks are evolving from bespoke implants hidden in trusted update channels toward industrialized, increasingly automated campaigns attributed to state-linked groups.