Cyber espionage groups linked to China used a sophisticated hacking tool to attack U.S. targets in strategic sectors, an activity that security researchers consider a sign of coordination within the Chinese cyber espionage ecosystem.
The U.S. firm ''Volexity'' reported on September 21 that it identified a third Chinese actor using the same exploitation chain previously employed by other groups. The company noted that the widespread use of the same tool points to a possible exchange of capabilities among different actors in the Chinese network exploitation community.
Separately, the cybersecurity company ''Proofpoint'' documented campaigns that used the same capability against U.S. non-governmental organizations, mining companies, commodity trading firms, and several aerospace companies. Researchers detected that different groups began using the tool with only a few days' difference and that most of the observed groups had suspicious links to China.

Although investigations have not publicly established who developed the tool or how it was distributed among the various groups, evidence suggests that the core of the technology may have been shared, modified, and used by multiple operators. The firm also warned that the observed activity could represent only a fraction of the campaign and that the actual scope could be considerably larger.
The attacks are particularly concerning due to the nature of the targets. Aerospace companies are linked to advanced technologies and defense capabilities, while mining companies and commodity operators handle information related to strategic resources and international markets. The simultaneous interest in these sectors shows the value that economic, industrial, and technological intelligence can have within a spying campaign.
The tool exploited previously unknown vulnerabilities in Google Chrome and Microsoft Windows. When the attacks were successful, they could allow the installation of spyware and provide operators a way to maintain access to the compromised equipment. Volexity detected that an actor identified as ''UTA0565'' used the attack chain between September 3 and 4, before the vulnerabilities were patched through updates.











