<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>China-Apt on CuraSec</title><link>https://curasec.metacog.co.kr/tags/china-apt/</link><description>Recent content in China-Apt on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/china-apt/index.xml" rel="self" type="application/rss+xml"/><item><title>FBI Disrupts China-Linked QTFY Hacking Platforms QScan and QTRouter</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-fbi-disrupts-china-linked-qtfy-infrastructure-used-to-steal/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-fbi-disrupts-china-linked-qtfy-infrastructure-used-to-steal/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No specific exploited software, CVEs, or patches associated with QTFY&amp;rsquo;s platforms are named, so there is no concrete remediation action; file as context on Chinese state-sponsored tooling targeting critical infrastructure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Research published TTPs and any emerging IOCs tied to QScan and QTRouter, then build or tune hunt queries targeting behaviors associated with QTFY activity before the actor pivots to new infrastructure post-disruption.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful background for board or leadership briefings on nation-state threat trends; no specific vendor breach or near-term regulatory action is indicated, so no immediate escalation is warranted.&lt;/li>
&lt;/ul></description></item><item><title>China-Nexus APT Exploits VMware vCenter CVE-2026-59310, Drops Babuk Ransomware</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-dep/</link><pubDate>Mon, 17 Aug 2026 11:37:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-dep/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVE-2026-59310 (CVSS 9.8) is under active APT exploitation with a public PoC; patch VMware vCenter to the vendor-released fixed version immediately — do not wait for a maintenance window given confirmed in-the-wild exploitation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Assume-breach posture for any vCenter environment: hunt for signs of post-exploitation activity and Babuk-derived ransomware staging since the patch release date, and build detections around directory-traversal followed by unusual process spawning from vCenter services.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A China-nexus APT is actively deploying ransomware via a critical vCenter flaw — confirm whether your environment runs vCenter, verify patch status with your engineering team this week, and prepare a brief for leadership given the ransomware and nation-state dimensions.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Storm-1175 Deploys StormEncryptor Ransomware, Likely via N-central Flaw</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-china-linked-hackers-deploy-new-stormencryptor-ransomware-li/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-china-linked-hackers-deploy-new-stormencryptor-ransomware-li/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your environment includes N-able N-central (common in MSP-managed or hybrid estates), apply any available patches and audit for signs of unauthorized remote execution; the vector is described as likely rather than confirmed, so no KEV urgency, but RMM tools are high-value pivot points.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Storm-1175 has shifted tooling from Medusa to a new C++ ransomware appending .encrypted; build or tune endpoint detections for that extension and ransomware-stage behaviors, and track this actor&amp;rsquo;s TTPs as Microsoft Threat Intelligence is actively reporting on the campaign.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether internal teams or managed service providers in your supply chain run N-central, and if so request a security posture attestation; a financially motivated China-linked actor deploying ransomware via RMM tooling is a credible MSP supply-chain risk worth queuing for this quarter&amp;rsquo;s vendor-risk review.&lt;/li>
&lt;/ul></description></item><item><title>China-Nexus JadeProx Deploys New TriBack Loader Against Gov/Healthcare</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A newly documented Windows loader from a China-nexus cluster, but no specific vulnerable software, patch, or configuration action is identified — useful for understanding adversary tradecraft in government and healthcare environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Group-IB&amp;rsquo;s exposure of the JadeProx cluster and TriBack Loader provides actor-profile and malware-family context, but the summary lacks published IOCs or ATT&amp;amp;CK-mapped TTPs needed to build or tune detections immediately.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> China-nexus targeting of government and healthcare sectors in Asia and Latin America is worth tracking for sector-risk awareness, but no vendor breach or imminent regulatory trigger warrants same-week leadership action.&lt;/li>
&lt;/ul></description></item></channel></rss>