ThinkPatternGet the app
Story
TECHNOLOGY · SEP 25, 2026

Chinese Cyber-Espionage Groups Target U.S. Aerospace and Mining Firms

Chinese hacking groups used a shared sophisticated tool to target U.S. aerospace companies, NGOs, and mining firms via Chrome and Windows vulnerabilities.

Multiple Chinese cyber-espionage groups coordinated a campaign targeting U.S. aerospace companies, nongovernmental organizations, mining firms, and commodity traders. The attackers utilized a shared, sophisticated hacking tool that was adopted by several groups within days of each other, indicating a coordinated effort within China's computer network exploitation community.

Volexity and Proofpoint separately identified the activity, which involved exploiting previously unknown vulnerabilities in Microsoft Windows and Google Chrome. These exploits allowed the hackers to install spying software and maintain persistent access to targeted systems. To lure victims, the groups deployed fraudulent versions of trusted websites, including The Conversation, China Digital Times, the Borneo Bulletin, and the Center for American Progress.

Cybersecurity experts warn that the identified attacks are likely only a fraction of a larger operation. Volexity stated that the full scope and impact of the campaign are likely far broader than what has been currently documented.


Reported across 2 outlets
Actors
Government of ChinaProofpoint

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play