Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

AI-Powered Analysis Exposes Massive 5,000-Domain Chinese Malware Operation

DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally. Active since June 2023, the network now comprises approximately 5,000 domains, with over 1,900 new domains…

DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally. Active since June 2023, the network now comprises approximately 5,000 domains, with over 1,900 new domains identified between May and November 2025.

Recent investigations reveal the network's shift from centralized infrastructure, primarily hosted on Alibaba Cloud Hong Kong, to a fragmented model utilizing domestic Chinese registrars and randomized domain naming patterns. This strategic move aims to enhance operational security and evade detection. Despite these efforts, analysts have identified recurring patterns in Service Oriented Architecture (SOA) emails, tracking IDs, and unique registrant names, linking the 1,900 new domains to the existing network. The infrastructure now spans five countries and employs eight unique registrars, compared to three registrars noted in early 2025.

To manage the extensive volume of malicious infrastructure, researchers deployed an experimental "agentic AI" system. This system features a two-layer architecture with an orchestration agent and specialized sub-agents for tasks such as code analysis and binary retrieval. The AI system processed over 1,900 malware delivery websites in the time usually required for 200 to 400 manual investigations.

In a bulk processing test, three AI agents analyzed 2,000 domains in approximately 10 hours, averaging 1 to 10 minutes per domain depending on complexity. The system effectively handled sites with anti-automation JavaScript and bot-detection mechanisms. AI agents identified malicious code, retrieved payloads, and generated YARA rules autonomously, altering the economics of defense against large-scale campaigns.

The malware cluster is specifically targeting Chinese-speaking demographics, using sophisticated spoofing of popular software to deliver trojans and credential stealers. Analysis of 2,393 recent domains shows a focus on communication tools and VPN services, likely to exploit users bypassing internet restrictions. Malware is often delivered via large files (100–250MB) to evade standard antivirus scanning.

Top Spoofed Application Categories (May–Nov 2025)

DomainTools Investigations has reported the expansion of a significant malware-delivery network targeting Chinese-speaking users globally.
Allison Burke · Thehackingpost

Category Domain Count Share Key Spoofed Brands

Communication Tools 391 24.2% WhatsApp, WhatsApp Web

VPN Services 363 22.4% LetsVPN (Kuailian), Kuailian Variants

Productivity 229 14.2% Google Services, Youdao, WPS Office

Advertisement

Web Browsers 109 6.7% Google Chrome

Crypto & Finance 105 6.5% ImToken, AICoin

The persistence of this network, along with its shift toward domestic infrastructure and complex evasion techniques, indicates its evolution into a potential service platform where affiliates may introduce their own malware. However, the deployment of agentic AI suggests that defenders can now effectively counteract large-scale threat operations.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories