Microsoft has seized dozens of malicious websites it discovered were being used by the state-run hacker group Nickel in Chinato target organizations in the US and 28 other countries worldwide.

See also: Chinese hackers hack data for future quantum decryption
In their attacks, hackers from the Nickel group, also known as KE3CHANG, APT15, Vixen Panda, Royal APT or Playful Dragon, compromised servers of government agencies, diplomatic entities and non-governmental organizations (NGOs) in 29 countries, mainly in Europe and Latin America.
"We believe these attacks were largely used to gather intelligence from government agencies, think tanks, and human rights organizations," said Tom Burt, Corporate Vice President of Customer Security at Microsoft.
Microsoft was able to destroy the Nickel group's infrastructure after the U.S. District Court for the Eastern District of Virginia approved an injunction following a complaint filed on December 2.
According to the court ruling, the domains were redirected “to secure servers by changing the authoritative name servers to NS104a.microsoftintemetsafety.net and NS104b.microsoftintemetsafety.net.”
See also: Are Russian cybercriminals seeking collaborations with Chinese hackers?
Microsoft's Digital Crimes Unit (DCU) first identified the group behind these malicious domains in 2016. Mandiant tracks them as Ke3chang and says they have been active since at least 2010.

Since 2019, it has been observed targeting government entities across Latin America and Europe, according to Microsoft's Threat Intelligence Center (MSTIC) and Digital Security Unit (DSU).
Nickel's ultimate goal is to deploy malware on compromised servers that allows its operators to monitor the activity of their victims, as well as collect data and amplify it on servers under their control.
These Chinese-backed hackers are using compromised third-party VPN providers, credentials stolen in spear-phishing campaigns, and exploits targeting unpatched Exchange Server and SharePoint servers to compromise their targets' networks.
See also: Chinese hackers behind attacks on ten Israeli hospitals?
In March 2020, the group used the Necurs spam botnet to distribute malware payloads and infect millions of computers in the US.
According to Microsoft, before it was taken down, Necurs sent approximately 3.8 million spam messages to more than 40.6 million targets in just 58 days.
