Blog on Chinese cyber operations, online surveillance, always on the hunt for leaked documents : NetAskari.com | deaddrop.netaskari.online

World
Pinned Tweet
Just as Trump and Xi might be shaking hands today we are delivering deep dive into more data from the company 'ZRON'. A digital Espionage-as-a-service shop, that hacked US embassy emails, runs big-data analysis operations on national and foreign targets for China's security services. There is a lot of ground to cover, so stay with us and let's go. 1/13
2
50
163
24,224
NetAskari retweeted
I have tried reverse engineering apps with AI. It fucking sucks. AI isn't reverse engineering shit, it is using other people's already reverse engineered code and slopping them together, this isn't the end of the world. Even if it was and suddenly anyone can analyse code. GOOD. Those vulnerabilities aren't created because of AI, they were just discovered with the help of AI. What's the answer to this problem? BUILD BETTER, BE BETTER. That's it. If AI is this insane hacking machine, then why can't it do the opposite, why can't it help defenders?
The Death of Software.
58
10
226
21,193
Chinese operators definitely having not given up on the Coruna/Darksword eco system. There seems to be some developments. More to come soon I guess.
2
13
97
7,179
Definitely seem to work till 26.1 by the looks of it. So the initial 'announcement' we have seen earlier in our Darksword/Ghostwave C2 setup has been fulfilled .
2
952
NetAskari retweeted
New: iPhones have an automatic reboot feature which quietly reboots the phone after a certain time; cops were freaking out about this when we revealed it in 2024. Now, phone hackers have a way around it, according to a leaked video 404media.co/cops-can-bypass-…
16
136
587
78,466
NetAskari retweeted
Finally, a paper on steganography with real-world impact! MI5 published an espionage alert naming the China General Technology Research Institute (CGTRI) as a funding channel for China's Ministry of State Security (MSS). According to MI5 CGTRI exists mainly to pay for academic research that makes MSS better at espionage. More than 100 UK-linked academics contributed to projects it funded, covering AI, cybersecurity. Now that MI5 has made the link public, every academic is assumed to know.
4
24
59
3,242
NetAskari retweeted
My clanker and I did some analysis on the iOS 26.7.1 CoreGraphics patch. As the diff from @blacktop indicates (github.com/blacktop/ipsw-dif…), some small changes. It likely has to do with glyphs and I got a small PoC crashing Quick Look delivered by a PDF. 1/2
3
11
63
10,661
NetAskari retweeted
New: Through a series of complex agreements with cities, the White House built a massive license plate camera database accessible to the feds. The program aggregates data across license plate companies (Flock, Axon, more) & is searchable by many agencies: 404media.co/how-cities-are-f…
12
300
452
32,001
NetAskari retweeted
There is something very odd about the timeline here. The man was arrested around September 16. ShinyHunters told me it hacked the FBI on September 21, and we broke news of the breach on September 22. So, the FBI hack appears to have happened way after the arrest. It’s not like the FBI and its Dutch partners jumped into action in the wake of the hack. It’s the other way around. They’re just announcing it now. The FBI is suggesting this is a counter to the massive hack, but it's not x.lingyaoai.com/FBIDirectorKash/status…
NO SAFE HAVEN. Working with our Dutch National Police partners, the FBI helped put an alleged leader of ShinyHunters—a global cybercrime threat actor—behind bars. And we’re not done. FBI teams are working new leads RIGHT NOW. More arrests are on the table. If you attack Americans from behind a keyboard anywhere in the world, we will find you. -DKP🇺🇸
19
160
581
45,266
Chinese researchers claims to have breached a Pixel 9, with vanilla Android: Ghostlock.
Replying to @OukaroMF
src @canyie2977 已同意转发
5
14
117
16,794
Great work by @ashl3y_shen on China's UAT-11587 and their operations against foreign countries political players.
🔥 New blog drop! My research introduces UAT-11587, a China-nexus group targeting government and policy organizations in 8 countries with the Antino backdoor. After a preview at @labscon_io, full technical analysis, campaign details & IoCs are now live: blog.talosintelligence.com/c…
2
13
54
6,846
The 'Antino' backdoor timeline from the report.
1
454
This is also China: VPN routers with 'dedicated' lines openly advertised. At the same time the govt is fining and charging ( at times ) people for running VPN services or even just using them ( with mixed success ).
这家IPdodo算是我看过最精美的翻墙路由器了 这个开模应该要花不少钱,而且他们的跨境专线合法合规 按月付费呢! 四川威算科技有限公司
1
15
3,153
Travel restrictions of members of key IT companies, state employees and scientists have been in place for quite a while, now it seems to also include members of the 'flourishing' AI industry.
China has expanded overseas travel restrictions for top AI professionals in private firms to include the families of key personnel bloomberg.com/news/articles/…
1
9
1,633
NetAskari retweeted
Confidential records reviewed by ICIJ for the #ChinaCapital investigation reveal how the Industrial and Commercial Bank of China’s London units courted high-risk clients to secure resources and alliances for Xi Jinping’s regime. buff.ly/HrYda5m
1
17
30
7,658
CyberStrikeAI is getting so heavily utilized lately by Chinese operators, it is quite noticeable.
While sweeping open directories on @etugenio, I came across a server in the US🇺🇸 on PEG TECH's network with port 8888 exposed. It wasn't a victim, but rather a box where a Chinese🇨🇳 speaking operator had left their entire offensive arsenal exposed to the internet. At the center of it was an AI-driven pentest framework. The operator calls it "Sinian." It organizes each attack technique into its own SKILL.md playbook, while sinian_pipeline.py chains them together into an autonomous attack pipeline. The same environment also hosts a plugin-based webshell C2 with modules for lateral movement, database dumping, SOCKS proxying, persistence, and log timestomping. The targets include Chinese payment and virtual-goods platforms such as tokenpay, dujiaoka, acg-faka, and epay, whose source trees were exposed through publicly accessible .git repositories. The attacks appear to rely on a ThinkPHP deserialization chain. Tooling targeting Shanghai health-card and Guangxi police-certificate systems also suggests that the operation extends into account-opening and real-name verification fraud. Stolen data is exfiltrated to a Telegram bot. Host: app.etugen.io/trashpile/104.… Content: Sinian AI pentest toolkit + webshell C2 + qingmeng-backdoor Exfiltration: Telegram bot Framework: CyberStrikeAI Exploits: CVE-2024-44902 - CVE-2025-63888 - phpggc Targets: tokenpay - dujiaoka - acg-faka - epay Fraud tooling: shanghai_health_card.py - guangxi_police_cert.py ATT&CK: T1059.004/.006 · T1552.003 · T1530 · Webshell #CTI #opendir #usa #china #war #hack #webshell
4
17
125
14,972
NetAskari retweeted
ok I'm genuinely proud of what we've built at DNSAudit.io, seriously. A security team messaged me today to say thanks... They ran one of their domains through it this morning, and found an issue they didn't know was there. Honestly that made my day!! 🥳 It started as a small tool I built for myself, and now it does what I always wanted: you put in a domain and in about 30 seconds you see what's wrong with its DNS. Dangling records, lame delegation, no DNSSEC, weak SPF/DMARC, missing registrar locks, old subdomains nobody remembers creating You don't need to install anything or give it access to your zones... it just looks at your domain from the outside, like anyone on the internet can. The screenshot is from a real scan. A nameserver that stopped answering but is still in the delegation. Nobody notices these until someone else does. Try it on your own domain, and tell me what it finds: dnsaudit.io
6
4
13
594
中国洗钱团伙一直以来在帮朝鲜黑客洗钱,包括这次 @bitget 的3.87亿美元被盗资金。 被 @zachxbt 等链上侦探点过名的有王逸聪、肖何等人。 他们表面上都是正规 OTC 商家,实际上运营着跨境洗钱网络和 FreeCity 等中国暗网。
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen laundering funds from the Kelp DAO $292M exploit earlier this year. I've observed the same pattern after multiple TraderTraitor attributed exploits, and I've closely tracked these groups. I plan to share more of my data on them in coming weeks. Currently, funds are being chain-hopped via bridges and being deposited into mixing services such as Wasabi. Alias 1 - Cc Discord: cc02006 Discord ID: 1351486674386948148 Txn: F08657EFAEAE7B58217CD17A22BF4779582E5D080C2E92E173BC239A5D828363 Alias 2 - jack Discord: jack_34808 Discord ID: 1553705721768714377 Txn: 68583D313A0CCC99F2702D61D05A242A69C86CAE09ED252B65F34B677C377F69 Alias 3 - Melon Discord: under0346 Discord ID: 1394240539108573215 Txn 1: ABE2AEF8B10057E60F8259CA2CA2CD5D71D38D254960FEEE89CB3C95A964873F Txn 2: 7BE290865901DEB1680A6D692A11392D1FDDACA0D31C48F26DCB249F2444BD6B Alias 4 - lolo / Marin TG: pvpcz TGID: 6223514198 Discord: losern Discord ID: 1024415186527985704 Txn: 8E935C19D00F40639B78BF1FD094FE48C92118F3E586AB52DF93851080CCCE15 Alias 5 - HELP ME Discord: helpme031897 Discord ID: 1554035533817188384 Txn: 7C58CAD760EBBED54F2CA4D2146D056910B7B6688B4F524396DC8807353C2379
34
44
226
85,351
"Jasmine had no technical skills and zero interview experience of any kind, yet within days of arrival she was assigned a persona, handed a two-to-three-week account-building quota, and booked in front of a client CEO." - THE WOMEN BEHIND NORTH KOREA'S IT WORKER OPERATIONS: haydenmckenzie.com/research/…
4
21
1,884
I think this is the threat level that needs to be more in the focus, rather than 'did an LLM go rouge' debate. I think it is very obvious that AI is a force-multiplier for most red-team operations. Even more so than for defenders I would wager. It helps with recon, analysis, planning and scaling etc. Also replay attacks are much easier to pull off, with far less costs and overhead. The bar has just been lowered.
Eyal’s original finding is a good example of what defenders should assume is already happening: an attacker using autonomous AI agents against hundreds of online shops, with a reported average cost of around $25 per target. His follow-up now includes some nice additional work from @_ChezDaniela on the skimmer side of the campaign. Instead of chasing rotating C2 domains, she focused on more stable characteristics of the injected code and its packer - and expanded the hunt from one observed injection to 50+ shops. Her write-up goes into the details: medium.com/@ping.from.dani/o…
4
1,629