Report: APT20, a Chinese government-linked hacking group, has bypassed key fob-enabled 2FA in recent attacks on government orgs and managed service providers
Chinese state-sponsored group APT20 has been busy hacking government entities and managed service providers.
Context & Ripple Effects
APT20's key fob bypass lands on a well-worn path: six months earlier, APT10 broke into eight IT service providers including HPE and IBM to reach client networks, establishing managed service providers as the preferred side door into government targets. The 2FA angle raises the stakes — the control most orgs treat as their last line of defense is now demonstrably beatable by a state-linked actor.
The report also fits a documented escalation arc: FireEye had already flagged APT30's decade-plus of state-sponsored espionage in Southeast Asia back in 2015, and later reporting on APT41 exploiting Citrix and Zoho bugs across 20+ countries shows these groups moving from stealth collection toward aggressive vulnerability exploitation at scale.
First-order effects
- Government organizations and MSPs that relied on key fob-based 2FA lose their assumption of safety on that control and must audit whether APT20-style replay or interception affected their environments.
- MSPs are hit twice — as direct victims and as the propagation path to downstream government clients, repeating the access-broker role APT10 demonstrated against HPE and IBM.
Second-order effects
- Authentication vendors face pressure to move customers off simple fob tokens toward phishing-resistant methods, since a widely reported bypass undermines the product category's core value proposition.
- Security teams at edge-device and remote-access vendors (the Citrix/Pulse/F5 class later flagged by CISA) should expect Chinese state groups to keep pairing credential attacks with unpatched-vulnerability exploitation, forcing faster patch cadences across government suppliers.
Third-order effects
- If the pattern holds — APT10 via service providers, APT41 via software flaws, APT20 via 2FA bypass — Chinese state espionage structurally favors supply-chain and trust-relationship compromise over direct network assault, pushing governments to regulate MSP security standards as critical infrastructure.
- The eventual monetization turn is already visible in the corpus: APT41's later pivot to stealing $20M+ in US COVID relief funds suggests state-affiliated groups blurring espionage and financial crime, complicating attribution and deterrence frameworks.
The trend: Chinese state-linked hacking groups are systematically attacking the trust layer — service providers, shared software, and authentication itself — rather than individual targets, making supply-chain compromise the defining espionage model of the era.