Chinese cyber-espionage groups used the same sophisticated hacking tool in campaigns targeting U.S. aerospace companies, nongovernmental organizations, mining companies, and commodity traders, according to two cybersecurity firms that separately investigated the activity.
Volexity, a Virginia-based cybersecurity firm, said on Sept. 21 its discovery of another Chinese hacking group using the same tool added to evidence of coordinated sharing within China’s cyber-espionage community.
The company said the widespread adoption “suggests a coordinated effort within the Chinese CNE community,” referring to computer network exploitation, and assessed that the core tool was likely shared, customized, and used by multiple groups.
Proofpoint, a U.S. cybersecurity company, separately documented on Sept. 9 the same capability in campaigns against a small number of U.S. NGOs, mining companies, commodity-trading firms, and multiple U.S. aerospace companies. It found several espionage groups adopting the tool within days of one another, with most of the observed clusters having a suspected China nexus.
Neither company has publicly identified who developed the tool or how it reached the different hacking groups.
The Epoch Times asked both companies whether they had identified its developer or distributor and whether they had found additional U.S. targets. Neither responded by publication time.
Same Tool, Different Targets
The hacking groups pursued different victims and installed different spying software after gaining access, but researchers found that they relied on the same underlying break-in capability.
The attacks took advantage of previously unknown weaknesses in Google Chrome and Microsoft Windows. If successful, they could allow hackers to install spying software and maintain access to a victim’s computer.
Volexity said the additional Chinese operator it identified used the same attack chain on Sept. 3 and 4, when the vulnerabilities were still unpatched.
The company cautioned that what Volexity and Proofpoint have observed may represent only part of the activity.
“The full scope and impact are likely far broader,” Volexity said.
Fake Websites Used to Reach Targets
The newly identified group also used fake versions of trusted news and policy websites to lure intended targets.
In one campaign, Asian government entities received a Chinese-language email centered on imprisoned Hong Kong activist Chow Hang-tung. The link led to a fake site impersonating China Digital Times, a U.S.-based publication covering China, censorship, and politics, according to Volexity.
Another fake site impersonated the Center for American Progress (CAP), a Washington-based policy organization.
Volexity also identified fake sites mimicking two publications; The Conversation, which publishes articles by academic researchers, and the Borneo Bulletin, an English-language daily newspaper in Brunei. The company said the range of impersonated organizations may offer clues about the intended targets.
The Epoch Times has reached out to CAP and China Digital Times for comments. Neither responded by publication time.
Separate China-Linked Activity
Separately, cybersecurity firm ESET on Sept. 17 identified a China-aligned espionage campaign targeting governments and other organizations across Latin America, including a Panamanian legal entity involved in the dispute over two major ports near the Panama Canal. ESET has not identified a technical link between that activity and the campaigns documented by Volexity.
Barbara James, a public relations specialist at ESET, told The Epoch Times on Sept. 23 that malware was deployed on some computers in the Panamanian organization’s network in late December 2025 and January 2026, with further attempts between February and June of 2026.
James said ESET’s assessment of the likely espionage purpose was based on which organization was targeted and when.
ESET did not directly observe the hackers accessing or removing materials related to the port dispute. James said the limits of the company’s anonymized data meant it also could not rule out that such access occurred.