Google says Chinese state-linked hacker group, known as APT31, has been using malware on GitHub to upload and download files on networks in targeted attacks
This report extends Google's earlier election-season disclosures: back in June, its researchers said hackers backed by China had targeted Joe Biden's campaign while Iran targeted Trump's, with no signs of compromise. The new detail is technical — attribution of that activity to APT31 and evidence the group used malware hosted on GitHub to upload and download files inside victim networks.
The mechanism matters more than the single case: it shows state-linked operators turning a mainstream developer platform into covert infrastructure rather than building their own. Google's subsequent disclosures in this corpus — Iran-backed APT42 targeting the Trump and Biden campaigns in 2024, and a [[a:1170979|Chinese-linked group hitting US and Canadian academic, medical, and military research institutions through 2025]] — suggest this reporting stream became a recurring channel for exposing such operations.
First-order effects
APT31 gains an upload/download channel on compromised networks that blends into normal traffic to GitHub, complicating detection for the targeted organizations Google did not name publicly.
Second-order effects
Defenders and platform abuse teams now have to police legitimate code-hosting services as attack infrastructure, raising the monitoring burden on GitHub and pressuring other platforms over how their infrastructure gets weaponized.
Third-order effects
If the pattern holds — from campaign targeting to the later research-institution intrusions in this coverage — legitimate developer platforms become a standing battleground in state-linked espionage, and Google's threat intelligence unit consolidates its role as the de facto public discloser of foreign operations against US targets.
The trend: State-linked hacking groups are shifting their command-and-transfer infrastructure onto trusted mainstream code platforms, while Google's threat research team turns periodic public attributions into a running counterintelligence record spanning elections and critical research sectors.
As we head into the U.S. election, @google's Threat Analysis Group released its latest update on what we're seeing and how threat actors are changing their tactics. https://blog.google/...
Interesting mention: “While it's less common to see DDoS attacks rather than phishing or hacking campaigns coming from government-backed threat groups, we've seen bigger players increase their capabilities” https://blog.google/... Given @jc_stubbs scoop: https://www.reuters.com/.…
Today we announced that our infrastructure previously absorbed a 2.5 Tbps DDoS - remains the highest-bandwidth attack reported to date. Despite targeting thousands of IPs, in hopes of slipping past defenses, the attack had no impact. @googlecloud https://cloud.google.com/...
Looks like Google got tired of cloudflare/github/aws bragging about absorbing biggest DDoS ever. tl;dr: “Yeah we got more than that three years ago, and it had no impact on us even then”. https://cloud.google.com/...
Great to see the outstanding work by our IO team featured in Google's roundup. Thanks for the shoutout @ShaneHuntley! As usual, the update's full of goodies. 1/2 https://blog.google/...
In 2017 Google was targeted with a record 2.5 Tbps DDoS attack. The impact was none. Impressive. I wonder how a playbook for an attack 10x size looks like. https://cloud.google.com/...
There are some easter eggs for DDoS experts/historians in my blog post at https://cloud.google.com/... — How many can you find? https://twitter.com/...
Google's latest cyber threat update includes new information about the activities of Chinese and North Korean hackers. https://blog.google/... https://twitter.com/...
New updates from TAG in today's post https://blog.google/... Includes DDOS attacks from China, COVID-19 targeting from North Korea and a large spam network conducting coordinated influence operation. Thanks @t_gidwani @billyleonard & team.
New Google TAG threat report notes after Treasury Dept sanctioned Andriy Derkach — a Ukrainian politician who the USG says is a Russian agent — for attempting to influence 2020 US elections, Google “removed 14 Google accounts that were linked to him” https://blog.google/...
New Google TAG blog post detailing threats that Google has been seeing. No huge revelations in this one but now that I can't anymore, I really want to watch the possibly Chinese government-backed YouTube spam channel Old Doctor News. https://blog.google/... https://twitter.com/..…
@robert_spalding https://www.engadget.com/... Chinese hackers impersonated McAfee to attack election campaign staffers APT31, a group linked to China, impersonated McAfee (the antivirus software, not its indicted founder) in a bid to trick campaign workers into installing malware