{"slug": "five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar", "title": "Five Eyes exposes Chinese hacking network as researchers warn of AI cyberwar arms race", "summary": "Five Eyes intelligence agencies, led by Britain's National Cyber Security Centre (NCSC), issued a joint advisory accusing a Chinese technology company of enabling state-linked hacking operations worldwide, with the FBI reporting the attackers' arsenal includes MicroScan, a Python-based application containing more than 1,300 penetration-testing scripts. The advisory, co-signed by agencies from Australia, Canada, New Zealand, Japan and Spain, links the activity to hacking groups Ethereal Panda and Red Juliett and to a \"substantial\" botnet used by the advanced persistent threat group Flax Typhoon, whose victims included government organizations, law enforcement agencies, healthcare providers and religious institutions. NCSC Director of Operations Paul Chichester said the exposed malicious cyber activities \"should be extremely concerning for all network defenders,\" as researchers warned Beijing holds the \"strongest structural foundation for AI-enabled cyber operations\" among the West's major adversaries.", "body_md": "[Cyberwar](https://www.machine.news/tag/cyberwarfare/)\n\n# Five Eyes exposes Chinese hacking network as researchers warn of AI cyberwar arms race\n\n\"We will continue to call out malicious actors and the malevolent ecosystem they operate in,\" GCHQ's cybersecurity wing vows.\n\nFive Eyes intelligence agencies have issued a warning about a Chinese technology company accused of enabling state-linked [cyberwar](https://www.machine.news/tag/cyberwarfare/) operations worldwide.\n\nThe advisory comes as researchers warn that Beijing has the \"strongest structural foundation for AI-enabled cyber operations\" among the West's major adversaries, with a fast-growing ecosystem of domestic models and a military-civil research base enabling strategic independence.\n\nUrging organisations to improve their defences, Britain's National Cyber Security Centre (NCSC), part of GCHQ, accused a company linked to the Chinese government of \"heedless malicious cyber activity against the UK and its allies\".\n\nLast year, the UK government sanctioned the company, which we have decided not to name.\n\nIt allegedly provides tools, infrastructure and personnel to support Chinese state-linked hacking operations worldwide.\n\nAttackers supported by the company have reportedly used automated scanning tools and hands-on exploitation techniques to compromise networks and steal sensitive data from targets including [critical infrastructure](https://www.machine.news/tag/critical-infrastructure/) organizations. \n\nIt is also accused of operating a \"substantial\" botnet utilised by the advanced persistent threat group Flax Typhoon.\n\nPaul Chichester, NCSC Director of Operations, said: \"The extensive malicious cyber activities and services... that have been exposed today should be extremely concerning for all network defenders.\n\n\"The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat.\n\n\"We will continue to call out malicious actors and the malevolent ecosystem they operate in.\"\n\n## Inside China's global hacking operation\n\nAccording to the FBI, the attackers' arsenal includes MicroScan, a Python-based application containing more than 1,300 penetration-testing scripts, alongside tools designed to compromise email accounts and steal credentials.\n\nThe hackers have allegedly exploited website vulnerabilities, launched password-spraying attacks against Microsoft Exchange accounts and installed legitimate VPN software on compromised machines to maintain access while evading detection.\n\nInvestigators also uncovered malware and scripts designed to steal emails, extract sensitive information from corporate directories and transfer stolen data to attacker-controlled servers.\n\nVictims included government organisations, law enforcement agencies, healthcare providers and religious institutions.\n\nThe latest advisory also linked its operations to activity associated with hacking groups known as Ethereal Panda and Red Juliett, although the agencies caution that these classifications do not necessarily describe identical groups.\n\nAs well as the NCSC and FBI, agencies from the other three Five Eyes nations, Australia, Canada and New Zealand, co-signed the warning, alongside Japan and Spain.\n\n## READ MORE: [China’s Red Menshen “sleeper cell” spies caught hiding deep inside global telecoms networks](https://www.machine.news/chinas-red-menshen-sleeper-cell-spied-on-telecom-and-goverment-networks/)\n\n[Benny Czarny](https://www.linkedin.com/in/bennyczarny/?ref=machine.news), CEO and founder at [OPSWAT](https://www.opswat.com/?utm_source=chatgpt.com), told [Machine](https://www.machine.news/) the advisory highlighted the growing importance of [critical infrastructure](https://www.machine.news/tag/critical-infrastructure/) protection (CIP).\n\nHe said: \"Another CIP warning involving old school VPN access and firewalls. How many more breaches do we need to witness before we change the architecture?\n\n\"Operating systems and products need constant updates, credentials can be exposed, and administrators can make mistakes. Legacy VPNs and traditional firewalls remain valuable controls, but they are reachable, configurable, and therefore vulnerable to exploitation.\"\n\nCzarny argued that critical infrastructure facilities that only need to transmit monitoring data should deploy data diodes, which physically enforce one-way communication, preventing attackers from using the connection to access systems or issue commands, whether using AI or conventional hacking techniques.\n\n## The People's Republic of AI: Beijing's growing AI cyberwar capabilities\n\nThis week, [research from TrendAI](https://www.trendaisecurity.com/en-us/resources-insights/deep-research/from-state-ai-ecosystems-to-global-apt-cyberthreats?utm_source=chatgpt.com) examined the capabilities of four nations, China, Russia, North Korea and Iran, and reported that Beijing is \"best positioned to integrate AI into cyber operations\".\n\nThis is down to the \"depth and redundancy\" of its domestic AI ecosystem, which enables it to fall back on domestic models if Western access is cut off.\n\nIts vast research base, backed by close cooperation between civilian technology companies and the military, also gives it an advantage on the world stage.\n\nChinese state-linked hackers are already using AI to identify vulnerabilities, develop exploits, create malware and automate attacks. Researchers uncovered one operation involving AI-generated malicious code and another in which attackers used Anthropic's Claude before switching to a Chinese model when access became unreliable.\n\n## READ MORE: [Five Eyes probes LLM-wielding hacker-for-hire in China’s state-controlled digital underworld](https://www.machine.news/five-eyes-tracks-llm-wielding-hacker-for-hire-in-chinas-state-controlled-digital-underworld/)\n\nDespite US restrictions on advanced chips, China's growing range of domestic AI models is reducing its dependence on Western technology and helping its hackers sustain operations against [critical systems](https://www.machine.news/tag/critical-systems/) even when foreign services become unavailable.\n\n[Feike Hacquebord](https://www.linkedin.com/in/feike-hacquebord-33902b5/?ref=machine.news), Principal Threat Researcher at TrendAI, said: \"The important shift is that state-backed attackers do not need to own the most advanced AI models to benefit from them. What matters is access. We are already seeing AI used to speed up reconnaissance, social engineering, malware development and post-compromise activity.\n\n\"For defenders, this means focusing less on which model an attacker might be using and more on the increased speed, scale and automation AI brings to established attack techniques.\"\n\n## Wanted: Hafnium hacker linked to Covid-19 research theft\n\nSeparately, the US [government](https://www.machine.news/tag/government/) has announced a reward of up to $10 million for information about Chinese hacker Zhang Yu, who is accused of working for Beijing's intelligence services to steal sensitive American research.\n\nZhang and an alleged accomplice, Xu Zewei, reportedly targeted Covid-19 research at US universities before participating in the notorious HAFNIUM hacking campaign, which exploited Microsoft Exchange vulnerabilities and compromised thousands of computers worldwide.\n\nXu was arrested in Italy and extradited to the US in April 2026, while Zhang remains at large. US authorities accuse China of using private companies and contractors to conduct cyber espionage while concealing the government's involvement.\n\n## READ MORE: [China-linked \"Fire Ant\" hackers nest inside telecoms routers to swarm critical infrastructure](https://www.machine.news/china-linked-fire-ant-hackers-nest-inside-telecoms-routers-to-swarm-critical-infrastructure/)\n\nCommenting on the announcement, John Hammond, principal [security](https://www.machine.news/tag/security/) researcher at [Huntress](https://www.huntress.com/?ref=machine.news), said: \"I'm glad to see this case is still being pursued five years later. At Huntress, we had a front-row seat to just how far the Exchange attacks reached. We had visibility into the attackers' own infrastructure and could see tens of thousands of backdoors across compromised servers.\n\n\"The affected organisations included water utilities and county governments, so you're talking about attacks reaching into services people rely on every day. We worked with the FBI and other researchers on the response, and our team spent weeks calling organisations to tell them they'd been compromised.\n\n\"People who run these campaigns should not assume geography or time will erase what they leave behind.\"\n\n*Machine welcomes comment from Chinese cybersecurity professionals and is committed to impartial, evidence-based reporting. We encourage anyone wishing to offer a different perspective or contribute to our coverage to get in touch via our* *contact page**.*", "url": "https://wpnews.pro/news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar", "canonical_source": "https://www.machine.news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar-arms-race/", "published_at": "2026-10-09 11:17:09+00:00", "updated_at": "2026-10-09 11:23:01.329474+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["Five Eyes", "National Cyber Security Centre", "GCHQ", "FBI", "Flax Typhoon", "Ethereal Panda", "Red Juliett", "Paul Chichester"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar", "markdown": "https://wpnews.pro/news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar.md", "text": "https://wpnews.pro/news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar.txt", "jsonld": "https://wpnews.pro/news/five-eyes-exposes-chinese-hacking-network-as-researchers-warn-of-ai-cyberwar.jsonld"}}