Monday, August 31, 2026
LIVETop 10 International Tech News Today: AI, Chips, Apple, Cybersecurity and Startups///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Top 10 International Tech News Today: AI, Chips, Apple, Cybersecurity and Startups///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NetworkAI-assisted

OceanLotus Targets Xinchuang Ecosystem with Sophisticated Supply Chain Attacks

Cybersecurity The advanced persistent threat group, OceanLotus (APT32), has initiated a cyberespionage campaign targeting China's Xinchuang initiative, which aims to replace foreign technology with secure, domestic IT ecosystems. Targeting Linux Systems OceanLotus has shifted from Windows-centric attacks to targeting Linux-based…

OceanLotus Targets Xinchuang Ecosystem with Sophisticated Supply Chain Attacks

Cybersecurity

The advanced persistent threat group, OceanLotus (APT32), has initiated a cyberespionage campaign targeting China's Xinchuang initiative, which aims to replace foreign technology with secure, domestic IT ecosystems.

Targeting Linux Systems

OceanLotus has shifted from Windows-centric attacks to targeting Linux-based operating systems and internal supply chains. Security researchers have identified spear-phishing attacks throughout 2025 that adapt Windows attack methods for Linux environments within Xinchuang infrastructure.

The group uses Desktop Entry files (.desktop) as bait, disguised as legitimate documents. Upon execution, these files run a base64-encoded bash command, creating a scheduled task for persistent command-and-control (C2) communication. Additionally, attackers exploit pre-installed Java and Python environments on government ICT terminals.

OceanLotus has shifted from Windows-centric attacks to targeting Linux-based operating systems and internal supply chains.
Anthony Reid · The Hacking Post

Exploiting Document Viewer Vulnerabilities

In mid-2025, OceanLotus exploited CVE-2023-52076, a path traversal and arbitrary file write vulnerability in the Atril Document Viewer. By distributing malicious EPUB files, the attackers triggered the vulnerability to write a persistence file into the system's autostart directory and an encrypted payload into the .config folder, bypassing standard user defenses.

Internal Supply Chain Compromise

OceanLotus has shifted focus to internal network supply chain attacks, compromising domestic software used for terminal management. After initial access through phishing, the attackers attempted to brute-force internal security servers and likely deployed a zero-day exploit when brute-force attempts failed. Once in control of the management server, they distributed malicious update scripts to downstream endpoints, affecting both Linux-based Xinchuang terminals and legacy Windows systems.

Advertisement

This campaign underscores the evolving capabilities of OceanLotus, highlighting that even indigenized operating systems are vulnerable to advanced persistent threats when attackers exploit specific tools and supply chains designed to secure them.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories