Russian tech firm attacked by Chinese state hackers in allied attack

  • Chinese APT Jewelbug infiltrated a Russian IT provider, dwelling undetected for five months
  • Attackers used renamed Microsoft debugger to bypass defenses and exfiltrate data via Yandex Cloud
  • Symantec says China-based actors now target Russia despite perceived geopolitical alignment

Chinese hackers were recently seen targeting Russians, which raised eyebrows among the western cybersecurity community who perceive the two countries as allies in cyberspace and beyond.

Earlier this week, security outfit Symantec published a new report in which it detailed the work of Jewelbug, a Chinese state-sponsored threat actor that’s been “highly active in recent months.” In the report, Symantec said Jewelbug was seen going after targets in South America, South Asia, Taiwan and, most notably, Russia.

In early 2025, Jewelbug managed to sneak into the network of a Russian IT service provider, and remain there for no less than five months. During that time, they accessed code repositories and software build systems that they could leverage to run supply chain attacks against the IT service provider’s customers.

7zup.exe and Yandex

The compromise was spotted when researchers found a file named 7zup.exe on the IT provider’s system. This is a renamed copy of a legitimate, Microsoft binary, called CDB (Microsoft Console Debugger).

This tool can be used to run shellcode, bypass application whitelisting, launch executables, run DLLs, and terminate security solutions, Symantec added.

“Use of a renamed version of cbd.exe is a hallmark of Jewelbug activity,” the report reads. “Microsoft recommends that CDB should be blocked from running by default and whitelisted for specific users only when it’s explicitly needed.”

With the help of CBD, Jewelbug managed to dump credentials, establish persistence, and elevate privileges via scheduled tasks. They tried to cover their tracks by clearing Windows Event Logs, and used Yandex Cloud to exfiltrate data. Yandex is a Russian cloud service provider, which was probably chosen since it’s commonly used in the country and doesn’t usually raise any red flags.

“The targeting of a Russian organization by a Chinese APT group shows, however, that Russia is not out-of-bounds when it comes to operations by China-based actors,” Symantec concluded.

Via The Register

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

This robot vacuum delivers impressive mopping, but there are some quirks to know about before you buy

SwitchBot S20: two-minute reviewThe SwitchBot S20 is a hybrid robot vacuum with a particularly impressive mopping setup. While most robot vacuums feature flat mop...

What legacy business intelligence technology can learn from video games

In the last decade, business intelligence (BI) and data visualization have grown into a critical business functions. However, while BI and data viz tools...

A federal jury ruled that Apple has to pay $634 million for infringing smartwatch patents

In a longstanding and complicated legal battle between Apple and Masimo, a recent ruling from a California jury may be the first step towards...

MIT researchers and beauty brand Amorepacific made a wearable patch that analyzes skin aging

Researchers at MIT have been working with the South Korean beauty company Amorepacific for the past few years to develop a wearable "electronic skin"...

I’ve been testing digital photo frames for years, and I’ve just found my favorite design – Pexar’s innovative rear-lit stunner

Pexar Starlight 15.6-inch digital photo frame: reviewThe Pexar Starlight 15.6-inch digital photo frame is an innovative photo frame built on the third-party Frameo platform....

Asus ROG NUC has a major mini PC rival – this new challenger offers fantastic specs for work and gaming, and comes from a...

Thunderobot Mix G2 delivers a 17% GPU boost over ROG NUC 2025The top configuration includes Core Ultra 9 275HX and RTX 5090 GPUNight Owl...

Here’s another chance to get the Shokz OpenRun Pro for a record-low price

Experienced runners will tell you that not all headphones and earbuds are created equal. If you regularly pound the streets, you'll care about more...

LTO tape storage is still going strong despite Elon Musk’s efforts to wipe it out – and there’s now even 40TB cartridges for the...

LTO’s 40TB cartridge pushes tape storage into the AI-driven futureAramid film gives magnetic tape the strength to expand its lifespanMagnetic tape storage remains the...

This Shark upright might not be the fanciest vacuum in town, but in terms of cleaning power I can’t fault it

Shark Stratos Upright AZ3002: two-minute reviewProduct infoThis is the vacuum on review:Shark Stratos DuoClean PowerFins Hair Pro Upright Vacuum AZ3002Shark can be erratic with...

Here are 25 of our favorite outdoorsy deals from REI’s massive Holiday Sale

You can snag the high-end Garmin Fenix 8 for a whopping $250 off right now. REI doesn’t do Black Friday, but that doesn’t mean you...