Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.
Perspective Coverage
6 publishers
- Builder
- Builder 33%
- Operator
- Operator 53%
- Investor
- Investor 14%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence64
Volexity attributes September 1 spear-phishing at multiple NGOs to the Chinese cluster UTA0560. The chain used two Chrome flaws and one in Windows ALPC, and a second China-nexus actor ran the same chain.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
Proofpoint says two of the three bugs in the BlueMoon chain were fixed in public Chromium source before they reached stable Chrome. Defenders could close one link: an old Windows build.
Publishers:proofpoint.com
Reality
- Evidence62
- Adoption50
- Hype gap+12
- Incentives66
- Confidence58
buildOne report1 publisher Volexity says UTA0560 and JungleBamboo ran the same V8-to-kernel chain against separate targets on September 1, from separate infrastructure and with the same shellcode, while the V8 fix sat in Chromium source.
Publishers:volexity.com
Reality
- Evidence62
- Adoption58
- Hype gap+10
- Incentives60
- Confidence64
Black Lotus Labs spent a year mapping a service layer that hands reconnaissance, encrypted relays and routing to several Chinese state operators at the same time. IP-overlap attribution assumes that cannot happen.
Publishers:lumen.com
Reality
- Evidence45
- Adoption35
- Hype gap+28
- Incentives75
- Confidence45
Lumen's Black Lotus Labs spent a year mapping a four-part framework sold to Chinese espionage operators. Its indicators belong to a supplier, so hunt the service rather than one group's habits.
Reality
- Evidence52
- Adoption58
- Hype gap+18
- Incentives66
- Confidence48
Seqrite's Myanmar campaign hides a Go backdoor's traffic in UDP 443, with a single HTTP request in the whole chain. The monitoring gap travels regardless of your threat model.
Reality
- Evidence54
- Adoption32
- Hype gap+12
- Incentives62
- Confidence48