/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Journalists and IT experts shed light on years-long cyberespionage campaign against German corporations by Winnti, a hacking group believed to be based in China

Bayerischer Rundfunk : Tweets: @martijn_grooten , @securedemocracy , @hatr , @hatr , @mattiasalmeflo , and @campuscodi Tweets: Martijn Grooten / @martijn_grooten : This BR/NDR piece on Winnti and its attacking of German companies by @hatr et al is really good. We really need more journalistic pieces on attack groups to help us really understand the threat. Security copanies rarely provide us with the big picture https://web.br.de/... @securedemocracy : Good reporting by @br_data and @NDRpresse, highlighting the intersection between cyberattacks and strategic economic coercion https://web.br.de/... @hatr : Re: our joint investigation on Winnti (http://br24.de/...) here are some technical details in a short thread. We looked at more than 250 samples, wrote Yara rules, conducted nmap scans. (1/6) @hatr : Exclusive: We've been tracking a hacker group called #Winnti. We're on the very technical side of investigation with this one. Here is the link to the English version of the article. with @maxzierer @jlstro @sveckert @r_ciesielski @stekhn https://br24.de/... Mattias Almeflo / @mattiasalmeflo : “In former times, it was solely the job of intelligence agencies to uncover espionage operations. Nowadays, corporations and IT security companies prefer to employ staff earning six-figure salaries for that purpose.” https://twitter.com/... Catalin Cimpanu / @campuscodi : 2) German journalists revealed a wide-scale Chinese hacking campaign that appears to have targeted all of Germany's major companies. This is also the best infosec story of the day. https://web.br.de/... https://twitter.com/...

Bayerischer Rundfunk

Context & Ripple Effects

Bayerischer Rundfunk and NDR are doing what the security industry rarely does, per researcher Martijn Grooten's reaction to the piece: giving the big picture on an attack group rather than another isolated indicator feed. Their subject, Winnti, is a China-based group accused of a years-long espionage operation against German corporations — placing Germany alongside Vietnam as a country where dissidents and companies alike face long-running intrusion campaigns, as BR24's later OceanLotus investigation showed.

The report lands mid-arc in a well-documented escalation of Beijing-linked operations: from source code and chip design theft at Taiwanese semiconductor firms, through APT40's use of front companies and translators, to Microsoft's warning about intrusions into US critical infrastructure. What makes the BR/NDR piece notable is its framing of cyberattacks as strategic economic coercion rather than mere theft.

First-order effects

  • German corporations targeted by Winnti now have named attribution and a public record of a years-long campaign, shifting the burden onto their boards and national security agencies to respond.
  • Security researchers gain a rare comprehensive account of one attack group's methods — the kind of synthesis Grooten argues commercial threat-intel reports almost never provide.

Second-order effects

  • Rival Chinese-linked groups operating against European targets — OceanLotus among dissidents in Germany, APT40 running front-company recruitment — come under renewed scrutiny as part of a coordinated ecosystem rather than unrelated incidents.
  • German and EU policymakers face mounting evidence linking espionage directly to economic coercion, strengthening the case for export-control and investment-screening responses aimed at China.

Third-order effects

  • If investigative outlets continue outpacing vendor threat reports, public understanding of state-sponsored hacking will be shaped by journalists stitching years of campaigns into strategic narratives — pressuring governments to declassify more of what they know.
  • The trajectory across these reports points toward state hacking becoming a standing instrument of great-power economic competition, with private-sector hackers increasingly folded into national campaigns and targets moving from corporate IP toward critical infrastructure.

The trend: Chinese state-sponsored espionage is widening from corporate IP theft toward strategic economic coercion and critical infrastructure, with investigative journalism increasingly setting the public narrative that vendor reporting cannot.