惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
MyScale Blog
MyScale Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
P
Proofpoint News Feed
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
罗磊的独立博客
G
Google Developers Blog
Y
Y Combinator Blog
博客园 - 【当耐特】
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
J
Java Code Geeks
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
美团技术团队
宝玉的分享
宝玉的分享
Jina AI
Jina AI
小众软件
小众软件
T
Tailwind CSS Blog
A
About on SuperTechFans

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Chinese Hackers Exploit Iran War to Target Maritime and E...
Danny Palmer · 2026-05-29 · via www.infosecurity-magazine.com

Hacking groups linked to China have exploited the war in the Middle East in attempts to compromise maritime and energy companies in the region, cybersecurity researchers at ESET have warned.

Published on May 28, the latest ESET APT Activity Report warned that nation-state backed APT groups are actively targeting geopolitical hotpots, especially the Gulf region, following US military operations against Iran.

Chinese espionage and hacking operations also continue to target organizations around the world, in line with Beijing’s interests.

This included targeting of government organizations in Central America and an attempted espionage campaign against an AI and robotics company in South Korea.

ESET noted that the latter aligns with the Chinese Communist Party’s (CCP) interest in strategic technologies prioritized under its ‘Made in China 2025’ industrial development policy.

Hacks in Line With China's Economic Interests 

China has actively attempted to exploit instability in the Middle East, and ESET said that it has seen evidence of that China-aligned groups were being mobilized to improve Beijing’s visibility into maritime, energy and political developments in the region.

The report noted that China’s interest in the Middle East wasn’t limited to the Gulf, but that cyber operations have also actively targeted Syria. SteppeDriver, a China-linked APT group has targeted Syrian government networks.

ESET researchers suggest that this activity is linked to Chinese commercial interest in Syria’s reconstruction projects, as well as Beijing’s security concerns surrounding Uyghur fighters present in Syria.

The report also noted that during the coverage period of October 2025 to March 2026, Chinese espionage and hacking groups also took a significant interest in central and south America.

This included an operation by China-aligned APT FamousSparrow, which targeted a Venezuelan governmental entity connected to maritime affairs. Researchers noted that the aim of this activity was likely to monitor the resilience of oil shipments to the country following the US military strike in January.

Other activity in the region included a malware campaign by China-aligned group UNC5221, which targeted entities in Cambodia and Panama. It was also UNC5221 which targeted the AI and robotics company in South Korea.

Russian Hacking Campaigns

According to the ESET, Russia-aligned threat actors continued to focus their activity on Ukraine, especially against organizations and individuals connected to the military and defense.

Russian APT groups also heavily targeted drone manufacturers, and organizations involved in drone research and development. They also directed cyber-attacks against logistics and transportation companies outside Ukraine in an effort to disrupt Ukrainian defensive efforts against the Russian invasion.

The period also saw what ESET described as “intensified destructive activity” by Sandworm, the cyberwarfare unit linked to Russia's military intelligence service, which deployed wiper malware against infrastructure and services in Ukraine.

ESET has also previously attributed an attack against the Polish energy sector in December 2025 to Sandworm activity.

Iranian APT Activity

ESET noted that the US war against Iran has coincided with a decline in activity by established Iran-aligned APT groups, likely linked to restrictions on internet usage placed on the population by the Iranian regime. The internet outage has hindered the ability of Iranian hacking groups to operate effectively.

However, the report also noted that there has been a spike in activity by proxy-groups and hacktivists operations, which appear to support Iranian interests by targeting nations viewed as hostile to the regime, including the US and Israel.

In the Middle East, Israel remained the principal focus of Iran-aligned and Iran-linked activities. Targets range from organizations affected by espionage intrusions to device manufacturers hit by destructive tooling.