/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: APT20, a Chinese government-linked hacking group, has bypassed key fob-enabled 2FA in recent attacks on government orgs and managed service providers

Chinese state-sponsored group APT20 has been busy hacking government entities and managed service providers.

ZDNet Catalin Cimpanu

Context & Ripple Effects

APT20's key fob bypass lands on a well-worn path: six months earlier, APT10 broke into eight IT service providers including HPE and IBM to reach client networks, establishing managed service providers as the preferred side door into government targets. The 2FA angle raises the stakes — the control most orgs treat as their last line of defense is now demonstrably beatable by a state-linked actor.

The report also fits a documented escalation arc: FireEye had already flagged APT30's decade-plus of state-sponsored espionage in Southeast Asia back in 2015, and later reporting on APT41 exploiting Citrix and Zoho bugs across 20+ countries shows these groups moving from stealth collection toward aggressive vulnerability exploitation at scale.

First-order effects

  • Government organizations and MSPs that relied on key fob-based 2FA lose their assumption of safety on that control and must audit whether APT20-style replay or interception affected their environments.
  • MSPs are hit twice — as direct victims and as the propagation path to downstream government clients, repeating the access-broker role APT10 demonstrated against HPE and IBM.

Second-order effects

  • Authentication vendors face pressure to move customers off simple fob tokens toward phishing-resistant methods, since a widely reported bypass undermines the product category's core value proposition.
  • Security teams at edge-device and remote-access vendors (the Citrix/Pulse/F5 class later flagged by CISA) should expect Chinese state groups to keep pairing credential attacks with unpatched-vulnerability exploitation, forcing faster patch cadences across government suppliers.

Third-order effects

  • If the pattern holds — APT10 via service providers, APT41 via software flaws, APT20 via 2FA bypass — Chinese state espionage structurally favors supply-chain and trust-relationship compromise over direct network assault, pushing governments to regulate MSP security standards as critical infrastructure.
  • The eventual monetization turn is already visible in the corpus: APT41's later pivot to stealing $20M+ in US COVID relief funds suggests state-affiliated groups blurring espionage and financial crime, complicating attribution and deterrence frameworks.

The trend: Chinese state-linked hacking groups are systematically attacking the trust layer — service providers, shared software, and authentication itself — rather than individual targets, making supply-chain compromise the defining espionage model of the era.

Discussion

  • NullTX JP Buntinx on x
    Is APT20 a new Chinese State-sponsored Hacker Collective?
  • @arekfurt Brian on x
    Interesting opsec mistake😄: “Possibly frustrated by the fact of losing access to the webshells, the last seen ‘command’ executed by the actor is ‘wocao’. According to a number of native Mandarin speakers in our network, this could be Chinese slang for ‘shit’ or ‘damn’....” https:…
  • @maartenvdantzig Maarten van Dantzig on x
    One of the most exciting parts of IR work is monitoring threat actors while they are still active. This report describes one of the actors that we observed live in action. #operationwocao https://twitter.com/...
  • @hatr @hatr on x
    Fox-IT has put a very interesting report on APT20, a group that has been quiet for years, as @frankgr tells Bloomberg. One interesting mode of operation is how hackers circumvented 2FA (token likely generated on the SAME device) https://www.fox-it.com/... https://www.bloomberg.co…
  • @niubi Bill Bishop on x
    Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn” https://www.fox-it.com/... Shining a light on one of China's hidden hacking groups
  • @davidpwhelan David Whelan on x
    Dutch cyber security researchers believe state actor was able to recreate 2FA soft tokens (RSA) to bypass multi factor authentication without fob https://www.fox-it.com/...
  • @campuscodi Catalin Cimpanu on x
    Chinese hacker group caught bypassing 2FA * Report details new APT20 activity * Attacks discovered in 10 countries * Primary victims include govt entities and MSPs https://www.zdnet.com/... https://twitter.com/...