/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google says Chinese state-linked hacker group, known as APT31, has been using malware on GitHub to upload and download files on networks in targeted attacks

Former vice president Joe Biden.  Chinese hackers have unsuccessfully targeted the campaign, according to Google.  (Flickr / Gage Skidmore)

CyberScoop Sean Lyngaas

Context & Ripple Effects

This report extends Google's earlier election-season disclosures: back in June, its researchers said hackers backed by China had targeted Joe Biden's campaign while Iran targeted Trump's, with no signs of compromise. The new detail is technical — attribution of that activity to APT31 and evidence the group used malware hosted on GitHub to upload and download files inside victim networks.

The mechanism matters more than the single case: it shows state-linked operators turning a mainstream developer platform into covert infrastructure rather than building their own. Google's subsequent disclosures in this corpus — Iran-backed APT42 targeting the Trump and Biden campaigns in 2024, and a [[a:1170979|Chinese-linked group hitting US and Canadian academic, medical, and military research institutions through 2025]] — suggest this reporting stream became a recurring channel for exposing such operations.

First-order effects

  • APT31 gains an upload/download channel on compromised networks that blends into normal traffic to GitHub, complicating detection for the targeted organizations Google did not name publicly.

Second-order effects

  • Defenders and platform abuse teams now have to police legitimate code-hosting services as attack infrastructure, raising the monitoring burden on GitHub and pressuring other platforms over how their infrastructure gets weaponized.

Third-order effects

  • If the pattern holds — from campaign targeting to the later research-institution intrusions in this coverage — legitimate developer platforms become a standing battleground in state-linked espionage, and Google's threat intelligence unit consolidates its role as the de facto public discloser of foreign operations against US targets.

The trend: State-linked hacking groups are shifting their command-and-transfer infrastructure onto trusted mainstream code platforms, while Google's threat research team turns periodic public attributions into a running counterintelligence record spanning elections and critical research sectors.

Discussion

  • @kent_walker Kent Walker on x
    As we head into the U.S. election, @google's Threat Analysis Group released its latest update on what we're seeing and how threat actors are changing their tactics. https://blog.google/...
  • @bing_chris Chris Bing on x
    Interesting mention: “While it's less common to see DDoS attacks rather than phishing or hacking campaigns coming from government-backed threat groups, we've seen bigger players increase their capabilities” https://blog.google/... Given @jc_stubbs scoop: https://www.reuters.com/.…
  • @samlugani Sam Lugani on x
    Today we announced that our infrastructure previously absorbed a 2.5 Tbps DDoS - remains the highest-bandwidth attack reported to date. Despite targeting thousands of IPs, in hopes of slipping past defenses, the attack had no impact. @googlecloud https://cloud.google.com/...
  • @thomashabets Thomas Habets on x
    Looks like Google got tired of cloudflare/github/aws bragging about absorbing biggest DDoS ever. tl;dr: “Yeah we got more than that three years ago, and it had no impact on us even then”. https://cloud.google.com/...
  • @johnhultquist John Hultquist on x
    Great to see the outstanding work by our IO team featured in Google's roundup. Thanks for the shoutout @ShaneHuntley! As usual, the update's full of goodies. 1/2 https://blog.google/...
  • @campuscodi Catalin Cimpanu on x
    Sean has a summary about the APT attacks from today's TAG report. I only covered the DDoS thing. More here: https://twitter.com/...
  • @lukolejnik Lukasz Olejnik on x
    In 2017 Google was targeted with a record 2.5 Tbps DDoS attack. The impact was none. Impressive. I wonder how a playbook for an attack 10x size looks like. https://cloud.google.com/...
  • @menscher Damian Menscher on x
    There are some easter eggs for DDoS experts/historians in my blog post at https://cloud.google.com/... — How many can you find? https://twitter.com/...
  • @ericgeller Eric Geller on x
    Google's latest cyber threat update includes new information about the activities of Chinese and North Korean hackers. https://blog.google/... https://twitter.com/...
  • @shanehuntley Shane Huntley on x
    New updates from TAG in today's post https://blog.google/... Includes DDOS attacks from China, COVID-19 targeting from North Korea and a large spam network conducting coordinated influence operation. Thanks @t_gidwani @billyleonard & team.
  • @shanvav Shannon Vavra on x
    New Google TAG threat report notes after Treasury Dept sanctioned Andriy Derkach — a Ukrainian politician who the USG says is a Russian agent — for attempting to influence 2020 US elections, Google “removed 14 Google accounts that were linked to him” https://blog.google/...
  • @methodtim Tim on x
    I have the privilege of working alongside some massively talented folks. https://twitter.com/...
  • @kevincollier Kevin Collier on x
    New Google TAG blog post detailing threats that Google has been seeing. No huge revelations in this one but now that I can't anymore, I really want to watch the possibly Chinese government-backed YouTube spam channel Old Doctor News. https://blog.google/... https://twitter.com/..…
  • @softwarnet Charles R. Smith on x
    @robert_spalding https://www.engadget.com/... Chinese hackers impersonated McAfee to attack election campaign staffers APT31, a group linked to China, impersonated McAfee (the antivirus software, not its indicted founder) in a bid to trick campaign workers into installing malware
  • @mattiasgeniar @mattiasgeniar on x
    DDoS attacks are getting more powerful at an alarming rate https://cloud.google.com/... https://twitter.com/...