HomeSecurityChinese hackers influence US policy on international issues

Chinese hackers influence US policy on international issues

Chinese hackers now appear to be focusing on influencing the decision-making processes of the US government, targeting organizations involved in shaping international policy.

Chinese hackers

In April 2025, a sophisticated intrusion into a US nonprofit organization revealed the persistent efforts of these attackers to establish access network and collect policy-relevant information. The threat actors demonstrated significant technical sophistication, employing multiple evasion techniques and exploiting various vulnerabilities to maintain control of the compromised infrastructure for several weeks.

See also: Booking.com: New Phishing Attack Targets Travelers Through Compromised Accounts

The campaign reflects a broader pattern of Chinese state espionage targeting institutions that influence policy. The initial reconnaissance began on April 5, 2025, when attackers conducted mass vulnerability scans on organizations’ servers, attempting to exploit vulnerabilities such as CVE-2022-26134 (Atlassian OGNL Injection), CVE-2021-44228 (Log4j), CVE-2017-9805 (Apache Struts), and CVE-2017-17562 (GoAhead RCE). These scanning activities laid the groundwork for subsequent exploit and network compromise.

Chinese hackers influence US policy on international issues

Symantec security analysts identified multiple tactical indicators linking this campaign to established Chinese threat groups , including Space Pirates, Kelp (Salt Typhoon), and Earth Longzhi .

See also: Landfall spyware targeted Samsung Galaxy phones

Chinese hackers used DLL sideloading for persistence

Forensic evidence directly demonstrated performance in China through several attack methodologies. The attackers used DLL sideloading as their primary persistence, leveraging a legitimate VipreAV component named vetysafe.exe to execute the malicious payload sbamres.dll.

This technique exploits Windows' dynamic library search order, "planting" malicious code that legitimate applications automatically load and execute. The attackers created a scheduled task that runs every 60 minutes with SYSTEM privileges, executing msbuild.exe to load an unknown XML configuration file containing embedded code.

See also: Cavalry Werewolf group attacks government organizations

Chinese hackers influence US policy on international issues

This code then established communication with a command and control server. The sophisticated approach allowed the attackers to maintain persistent access while evading traditional security detection mechanisms, demonstrating evolving capabilities in targeting US policy institutions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS