/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail how five China-linked hacking groups targeting high-value Linux servers have managed to stay relatively undetected for almost a decade

Five APT groups have been using remote access trojans to take advantage of a network component that doesn't get much attention from security teams.

TechRepublic Veronica Combs

Context & Ripple Effects

This report slots into a decade-long arc of researchers unpicking what looked like scattered intrusions into one campaign family: back in 2018, opsec errors let analysts merge many previously 'independent' hacker groups into the Winnti Umbrella under China's government. The new detail — five groups quietly holding high-value Linux servers through an overlooked network component — extends that pattern from Windows-centric tooling to the least-watched layer of enterprise infrastructure.

It also rhymes with how these actors pick targets: APT10's years-long invasion ran through eight IT service providers including HPE and IBM, reaching clients indirectly, while CISA later flagged MSS-linked groups exploiting F5, Citrix, Pulse Secure, and Exchange edge devices. Neglected intermediary infrastructure is the recurring entry point, and Linux servers running it are where detection budgets rarely go.

First-order effects

  • Security teams operating high-value Linux servers face an immediate audit burden on the specific network component these RATs abused — logging and patching there, not just on endpoints, becomes the urgent task.
  • The named organizations hosting those servers must now assume up to ten years of potential dwell time, forcing retroactive threat hunting rather than simple remediation.

Second-order effects

  • Vendors of the overlooked network component come under pressure to ship telemetry and hardened defaults, since their product became the stealth channel for five separate groups.
  • Attribution work of the Winnti Umbrella kind pushes defenders and threat-intel vendors to merge group-by-group tracking into shared infrastructure signatures, changing how intrusion data is sold and shared.

Third-order effects

  • If low-visibility server infrastructure remains the preferred perch, espionage economics favor long-dwell access over headline ransomware-style disruption — pushing regulators and CISA-style agencies toward mandating visibility on exactly these components.
  • A pattern of parallel, non-collaborating groups hitting adjacent targets — as seen in the Southeast Asian telco intrusions attributed to three separate Chinese espionage groups — points to a state ecosystem where multiple units independently converge on the same blind spots.

The trend: Chinese state-linked espionage is consolidating around long-dwell, low-visibility footholds — neglected network components, service providers, and supply chains — with public attribution catching up only after years of access.

Discussion

  • @780thc @780thc on x
    BlackBerry released a report that examines how five APT groups operating in the interest of the Chinese government have systematically targeted Linux servers, Windows systems and Android mobile devices for nearly a decade. https://blogs.blackberry.com/ ... via @BlackBerry
  • @blackberry @blackberry on x
    BlackBerry Report Examines Decade-Long attacks on Linux Servers by APTs targeting Intellectual Property. Report details a shift to cloud service providers for C2 & data exfiltration which appear to be trusted network traffic. #malware #infosec #security https://blogs.blackberry.c…