/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google says Chinese state-linked hacker group, known as APT31, has been using malware on GitHub to upload and download files on networks in targeted attacks

Former vice president Joe Biden.  Chinese hackers have unsuccessfully targeted the campaign, according to Google.  (Flickr / Gage Skidmore)

CyberScoop Sean Lyngaas

Context & Ripple Effects

This report adds tooling detail to a disclosure Google had already made: back in June, its researchers said hackers backed by China targeted the Biden campaign while Iran went after Trump's, with no signs of compromise on either side. The new element is the infrastructure — APT31 abusing GitHub itself as an upload-and-download channel inside victim networks.

First-order effects

  • The Biden campaign and other targeted organizations face an attacker whose command-and-control traffic is disguised as ordinary traffic to a mainstream developer platform, making conventional blocking by domain reputation largely ineffective.
  • GitHub inherits a detection problem: state-linked operators are using its hosting legitimately enough to stay resident, forcing the platform to police abuse without breaking service for normal developers.

Second-order effects

  • Defenders at campaign organizations, research institutions, and enterprises have to monitor egress to code-hosting services as potential exfiltration, shifting security spending toward behavioral detection over blocklists.
  • Google's repeated role as the discloser — from the 2020 campaign reporting through its later alerts on Iran-backed APT42's targeting of the Trump and Biden campaigns — pressures rivals' platforms and security vendors to match its attribution cadence or cede the threat-intelligence narrative.

Third-order effects

  • If state-linked groups keep nesting operations inside trusted consumer and developer platforms, the industry moves toward treating platform-abuse reporting as a standing regulatory and liability question for companies like GitHub, not just a threat-intel briefing item.
  • Google's disclosure pattern — campaign targets in 2020, APT42 in 2024, and a Chinese-linked group hitting US and Canadian academic, medical, and military research bodies per later Reuters reporting — points to attribution briefings becoming a fixed feature of each election and geopolitical cycle, shaping policy debates before incidents are even confirmed.

The trend: State-linked hacking groups are increasingly hiding operations inside legitimate developer platforms, with Google's threat-attribution disclosures setting the public rhythm of the cat-and-mouse.

Discussion

  • @kent_walker Kent Walker on x
    As we head into the U.S. election, @google's Threat Analysis Group released its latest update on what we're seeing and how threat actors are changing their tactics. https://blog.google/...
  • @bing_chris Chris Bing on x
    Interesting mention: “While it's less common to see DDoS attacks rather than phishing or hacking campaigns coming from government-backed threat groups, we've seen bigger players increase their capabilities” https://blog.google/... Given @jc_stubbs scoop: https://www.reuters.com/.…
  • @samlugani Sam Lugani on x
    Today we announced that our infrastructure previously absorbed a 2.5 Tbps DDoS - remains the highest-bandwidth attack reported to date. Despite targeting thousands of IPs, in hopes of slipping past defenses, the attack had no impact. @googlecloud https://cloud.google.com/...
  • @thomashabets Thomas Habets on x
    Looks like Google got tired of cloudflare/github/aws bragging about absorbing biggest DDoS ever. tl;dr: “Yeah we got more than that three years ago, and it had no impact on us even then”. https://cloud.google.com/...
  • @johnhultquist John Hultquist on x
    Great to see the outstanding work by our IO team featured in Google's roundup. Thanks for the shoutout @ShaneHuntley! As usual, the update's full of goodies. 1/2 https://blog.google/...
  • @campuscodi Catalin Cimpanu on x
    Sean has a summary about the APT attacks from today's TAG report. I only covered the DDoS thing. More here: https://twitter.com/...
  • @lukolejnik Lukasz Olejnik on x
    In 2017 Google was targeted with a record 2.5 Tbps DDoS attack. The impact was none. Impressive. I wonder how a playbook for an attack 10x size looks like. https://cloud.google.com/...
  • @menscher Damian Menscher on x
    There are some easter eggs for DDoS experts/historians in my blog post at https://cloud.google.com/... — How many can you find? https://twitter.com/...
  • @ericgeller Eric Geller on x
    Google's latest cyber threat update includes new information about the activities of Chinese and North Korean hackers. https://blog.google/... https://twitter.com/...
  • @shanehuntley Shane Huntley on x
    New updates from TAG in today's post https://blog.google/... Includes DDOS attacks from China, COVID-19 targeting from North Korea and a large spam network conducting coordinated influence operation. Thanks @t_gidwani @billyleonard & team.
  • @shanvav Shannon Vavra on x
    New Google TAG threat report notes after Treasury Dept sanctioned Andriy Derkach — a Ukrainian politician who the USG says is a Russian agent — for attempting to influence 2020 US elections, Google “removed 14 Google accounts that were linked to him” https://blog.google/...
  • @methodtim Tim on x
    I have the privilege of working alongside some massively talented folks. https://twitter.com/...
  • @kevincollier Kevin Collier on x
    New Google TAG blog post detailing threats that Google has been seeing. No huge revelations in this one but now that I can't anymore, I really want to watch the possibly Chinese government-backed YouTube spam channel Old Doctor News. https://blog.google/... https://twitter.com/..…