CuraSec

tag: China-Apt · 4 items

2026-08-27 · The Hacker News · source ↗ #nation-state#china-apt#infrastructure
  • Engineer — Learn: No specific exploited software, CVEs, or patches associated with QTFY’s platforms are named, so there is no concrete remediation action; file as context on Chinese state-sponsored tooling targeting critical infrastructure.
  • SOC/IR — Plan: Research published TTPs and any emerging IOCs tied to QScan and QTRouter, then build or tune hunt queries targeting behaviors associated with QTFY activity before the actor pivots to new infrastructure post-disruption.
  • Leader — Learn: Useful background for board or leadership briefings on nation-state threat trends; no specific vendor breach or near-term regulatory action is indicated, so no immediate escalation is warranted.
2026-08-17 · The Hacker News · source ↗ #vmware-vcenter#china-apt#ransomware
  • Engineer — Act: CVE-2026-59310 (CVSS 9.8) is under active APT exploitation with a public PoC; patch VMware vCenter to the vendor-released fixed version immediately — do not wait for a maintenance window given confirmed in-the-wild exploitation.
  • SOC/IR — Act: Assume-breach posture for any vCenter environment: hunt for signs of post-exploitation activity and Babuk-derived ransomware staging since the patch release date, and build detections around directory-traversal followed by unusual process spawning from vCenter services.
  • Leader — Act: A China-nexus APT is actively deploying ransomware via a critical vCenter flaw — confirm whether your environment runs vCenter, verify patch status with your engineering team this week, and prepare a brief for leadership given the ransomware and nation-state dimensions.
  • Signals: CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-08-11 · The Hacker News · source ↗ #ransomware#rmm-exploitation#china-apt
  • Engineer — Plan: If your environment includes N-able N-central (common in MSP-managed or hybrid estates), apply any available patches and audit for signs of unauthorized remote execution; the vector is described as likely rather than confirmed, so no KEV urgency, but RMM tools are high-value pivot points.
  • SOC/IR — Plan: Storm-1175 has shifted tooling from Medusa to a new C++ ransomware appending .encrypted; build or tune endpoint detections for that extension and ransomware-stage behaviors, and track this actor’s TTPs as Microsoft Threat Intelligence is actively reporting on the campaign.
  • Leader — Plan: Confirm whether internal teams or managed service providers in your supply chain run N-central, and if so request a security posture attestation; a financially motivated China-linked actor deploying ransomware via RMM tooling is a credible MSP supply-chain risk worth queuing for this quarter’s vendor-risk review.
2026-07-24 · The Hacker News · source ↗ #china-apt#malware-loader#healthcare
  • Engineer — Learn: A newly documented Windows loader from a China-nexus cluster, but no specific vulnerable software, patch, or configuration action is identified — useful for understanding adversary tradecraft in government and healthcare environments.
  • SOC/IR — Learn: Group-IB’s exposure of the JadeProx cluster and TriBack Loader provides actor-profile and malware-family context, but the summary lacks published IOCs or ATT&CK-mapped TTPs needed to build or tune detections immediately.
  • Leader — Learn: China-nexus targeting of government and healthcare sectors in Asia and Latin America is worth tracking for sector-risk awareness, but no vendor breach or imminent regulatory trigger warrants same-week leadership action.