Google says Chinese state-linked hacker group, known as APT31, has been using malware on GitHub to upload and download files on networks in targeted attacks
This report adds tooling detail to a disclosure Google had already made: back in June, its researchers said hackers backed by China targeted the Biden campaign while Iran went after Trump's, with no signs of compromise on either side. The new element is the infrastructure — APT31 abusing GitHub itself as an upload-and-download channel inside victim networks.
First-order effects
The Biden campaign and other targeted organizations face an attacker whose command-and-control traffic is disguised as ordinary traffic to a mainstream developer platform, making conventional blocking by domain reputation largely ineffective.
GitHub inherits a detection problem: state-linked operators are using its hosting legitimately enough to stay resident, forcing the platform to police abuse without breaking service for normal developers.
Second-order effects
Defenders at campaign organizations, research institutions, and enterprises have to monitor egress to code-hosting services as potential exfiltration, shifting security spending toward behavioral detection over blocklists.
Google's repeated role as the discloser — from the 2020 campaign reporting through its later alerts on Iran-backed APT42's targeting of the Trump and Biden campaigns — pressures rivals' platforms and security vendors to match its attribution cadence or cede the threat-intelligence narrative.
Third-order effects
If state-linked groups keep nesting operations inside trusted consumer and developer platforms, the industry moves toward treating platform-abuse reporting as a standing regulatory and liability question for companies like GitHub, not just a threat-intel briefing item.
Google's disclosure pattern — campaign targets in 2020, APT42 in 2024, and a Chinese-linked group hitting US and Canadian academic, medical, and military research bodies per later Reuters reporting — points to attribution briefings becoming a fixed feature of each election and geopolitical cycle, shaping policy debates before incidents are even confirmed.
The trend: State-linked hacking groups are increasingly hiding operations inside legitimate developer platforms, with Google's threat-attribution disclosures setting the public rhythm of the cat-and-mouse.
As we head into the U.S. election, @google's Threat Analysis Group released its latest update on what we're seeing and how threat actors are changing their tactics. https://blog.google/...
Interesting mention: “While it's less common to see DDoS attacks rather than phishing or hacking campaigns coming from government-backed threat groups, we've seen bigger players increase their capabilities” https://blog.google/... Given @jc_stubbs scoop: https://www.reuters.com/.…
Today we announced that our infrastructure previously absorbed a 2.5 Tbps DDoS - remains the highest-bandwidth attack reported to date. Despite targeting thousands of IPs, in hopes of slipping past defenses, the attack had no impact. @googlecloud https://cloud.google.com/...
Looks like Google got tired of cloudflare/github/aws bragging about absorbing biggest DDoS ever. tl;dr: “Yeah we got more than that three years ago, and it had no impact on us even then”. https://cloud.google.com/...
Great to see the outstanding work by our IO team featured in Google's roundup. Thanks for the shoutout @ShaneHuntley! As usual, the update's full of goodies. 1/2 https://blog.google/...
In 2017 Google was targeted with a record 2.5 Tbps DDoS attack. The impact was none. Impressive. I wonder how a playbook for an attack 10x size looks like. https://cloud.google.com/...
There are some easter eggs for DDoS experts/historians in my blog post at https://cloud.google.com/... — How many can you find? https://twitter.com/...
Google's latest cyber threat update includes new information about the activities of Chinese and North Korean hackers. https://blog.google/... https://twitter.com/...
New updates from TAG in today's post https://blog.google/... Includes DDOS attacks from China, COVID-19 targeting from North Korea and a large spam network conducting coordinated influence operation. Thanks @t_gidwani @billyleonard & team.
New Google TAG threat report notes after Treasury Dept sanctioned Andriy Derkach — a Ukrainian politician who the USG says is a Russian agent — for attempting to influence 2020 US elections, Google “removed 14 Google accounts that were linked to him” https://blog.google/...
New Google TAG blog post detailing threats that Google has been seeing. No huge revelations in this one but now that I can't anymore, I really want to watch the possibly Chinese government-backed YouTube spam channel Old Doctor News. https://blog.google/... https://twitter.com/..…