United States federal authorities have launched an investigation into a sophisticated malware that targeted sensitive trade negotiations between Washington and Beijing.

The attack, which appeared in July 2025, included phishing emails purporting to have been sent by Representative John Moolenaar, chairman of the Committee on Strategic Competition between the United States and the Communist Party of China.
The malicious campaign targeted US trade groups, law firms and government agencies with emails aimed at gathering information about America's trade strategy in relation to China.
The timing of the attack proved particularly strategic, as it occurred just before crucial U.S.-China trade talks in Sweden, which ultimately led to an extension of a tariff truce until early November, when President Donald Trump and Chinese leader Xi Jinping will meet at an Asian economic summit.
See also: How Microsoft Azure Storage Logs help with security breach investigation
Who is behind the malware campaign?
Cybersecurity experts believe that APT41, a notorious hacker group with ties to Chinese intelligence.
Reuters analysts identified the attack as part of a broader cyberespionage linked to Beijing, aimed at obtaining information about White House recommendations for controversial trade negotiations.
The complex nature of the operation suggests state support and the capabilities of state hackers.

The fake emails used social engineering tactics, with subject lines like “Your opinions are needed.” They also asked recipients to consider what appeared to be legislative proposals.
However, opening the attached bill enabled the malware to spread, potentially giving attackers extensive access to organizations' networks and sensitive communications.
Complex infection mechanisms
The malicious campaign demonstrated sophisticated infection mechanisms, designed to establish persistent access, evading detection systems.
The emails contained malicious attachments that likely contained embedded macros or exploited zero-day vulnerabilities in office applications. Upon execution, the malware established command and control communications, allowing remote access to compromised systems.
See also: Lazarus APT uses ClickFix technique to steal data
The perpetrators used advanced spoofing to imitate Representative Moolenaar's official correspondence, possibly harvesting genuine email signatures.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This approach demonstrates the attackers' reconnaissance capabilities and their understanding of US political structures and communication patterns
The campaign was discovered when Moolenaar's committee staff began receiving inquiries about emails they had never sent, prompting an internal investigation.
The U.S. Capitol Police and the FBI have launched formal investigations, although authorities declined to comment on specific details.

embassy in Washington denied involvement, stating that it "strongly opposes and combats all forms of cyberattacks and cybercrime," while calling for accusations based on evidence rather than baseless allegations.
See also: Abuse of iCloud Calendar to send phishing emails
This case highlights once again how thin the line between diplomacy and cyberwarfare has become. The involvement of a potential Chinese APT group, with such a well-designed phishing script, is not just an attack on cybersecurity; it is a strategic act of political pressure. The fact that the campaign coincided with crucial US-China trade talks shows that the internet has become yet another battlefield, where the “bullets” are bits and the targets are commercial strategies and political stakes.
It is characteristic that attacks of this type target the weakness of the human factor, through social engineering. No matter how advanced firewalls and detection systems are, if an executive opens the wrong attachment, the result can be disastrous. This proves that security is not only a matter of technology, but also of culture – education, vigilance and continuous testing of an organization's resistances.
