/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft seizes 42 domains allegedly used by a Chinese cyber espionage group that targeted organizations in 29 countries including the US

Microsoft said today that its legal team has successfully obtained a court warrant that allowed it to seize 42 domains used by a Chinese cyber-espionage group … Source: Microsoft On the Issues .

The Record Catalin Cimpanu

Context & Ripple Effects

Microsoft had already used court orders to take control of infrastructure attributed to other state-linked groups, including 99 websites tied to an Iranian hacking operation and 50 domains attributed to North Korean group Thallium. The 42-domain action extends that legal-disruption playbook to a Chinese espionage operation.

Related coverage later records the same approach against Russia-linked Strontium, underscoring that Microsoft treats domain seizures as a repeatable part of disrupting state-linked attack infrastructure, not a one-off response.

First-order effects

  • The Chinese cyber-espionage group loses control of 42 domains identified in Microsoft's court action, interrupting infrastructure it allegedly used against organizations across 29 countries.
  • Organizations targeted by the group gain an immediate disruption of those identified domains, while Microsoft assumes control of the infrastructure named in the order.

Second-order effects

  • The group must replace or reconfigure the seized infrastructure to continue using the affected channels, increasing the operational burden of its campaign.
  • Microsoft's repeated resort to court orders makes domain registrars and hosting intermediaries a more consequential enforcement layer in responses to alleged espionage activity.

Third-order effects

  • If this pattern persists, large technology platforms will increasingly combine threat research with civil legal action to remove attacker infrastructure across national boundaries.
  • The model shifts part of cyber defense from detecting attacks inside customer networks toward contesting the internet services attackers depend on.

The trend: Microsoft is institutionalizing court-ordered infrastructure seizures as an ecosystem-defense tool against alleged state-linked and criminal cyber operations.

Discussion

  • @campuscodi Catalin Cimpanu on x
    NEW: Microsoft seized last week 42 domains used by Chinese cyber-espionage group Nickel (APT15) in its fifth legal action against an APT group and 24th overall https://therecord.media/... https://twitter.com/...
  • @msftissues @msftissues on x
    Microsoft's Digital Crimes Unit obtained a court order to seize malicious websites that were being used by nation-state actor, Nickel, to attack organizations in 29 countries. Read more from @TomBurt45: https://blogs.microsoft.com/ ...
  • @campuscodi Catalin Cimpanu on x
    A copy of the complaint is here: https://www.documentcloud.org/ ... A copy of the seized domains is here: https://www.documentcloud.org/ ... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    The domains were being used in a campaign that targeted government agencies, think tanks, and human rights organizations in the US and 28 other countries. Also of note... this is the first cropped world map I've seen in a report and I gotta say it's freaking me out. https://twitt…
  • @byron_wan Byron Wan on x
    Microsoft has successfully obtained a court warrant allowing it to seize 42 domains used by 🇨🇳 cyber-espionage group Nickel (aka APT15, Mirage, Vixen Panda, Ke3Chang) in recent operations that targeted organizations in the US and 28 other countries. 1/n https://therecord.media/..…
  • @nytimesbusiness @nytimesbusiness on x
    “Our disruption will not prevent Nickel from continuing other hacking activities, but we do believe we have removed a key piece of the infrastructure the group has been relying on,” a Microsoft executive said. https://www.nytimes.com/...
  • @infosecsherpa @infosecsherpa on x
    “The group was likely using the websites to install malware that helped it gather data from government agencies and other groups, the company said.” via @nytimes https://www.nytimes.com/...