Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

May 30, 2026

AI-Generated npm Malware Leaks Its Own GitHub Token

May 29, 2026

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

May 29, 2026
Facebook X (Twitter) Instagram
Saturday, May 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms
News

Chinese Hackers Exploit Iran War to Target Maritime and Energy Firms

Team-CWDBy Team-CWDMay 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Hacking groups linked to China have exploited the war in the Middle East in attempts to compromise maritime and energy companies in the region, cybersecurity researchers at ESET have warned.

Published on May 28, the latest ESET APT Activity Report warned that nation-state backed APT groups are actively targeting geopolitical hotpots, especially the Gulf region, following US military operations against Iran.

Chinese espionage and hacking operations also continue to target organizations around the world, in line with Beijing’s interests.

This included targeting of government organizations in Central America and an attempted espionage campaign against an AI and robotics company in South Korea.

ESET noted that the latter aligns with the Chinese Communist Party’s (CCP) interest in strategic technologies prioritized under its ‘Made in China 2025’ industrial development policy.

Hacks in Line With China’s Economic Interests 

China has actively attempted to exploit instability in the Middle East, and ESET said that it has seen evidence of that China-aligned groups were being mobilized to improve Beijing’s visibility into maritime, energy and political developments in the region.

The report noted that China’s interest in the Middle East wasn’t limited to the Gulf, but that cyber operations have also actively targeted Syria. SteppeDriver, a China-linked APT group has targeted Syrian government networks.

ESET researchers suggest that this activity is linked to Chinese commercial interest in Syria’s reconstruction projects, as well as Beijing’s security concerns surrounding Uyghur fighters present in Syria.

The report also noted that during the coverage period of October 2025 to March 2026, Chinese espionage and hacking groups also took a significant interest in central and south America.

This included an operation by China-aligned APT FamousSparrow, which targeted a Venezuelan governmental entity connected to maritime affairs. Researchers noted that the aim of this activity was likely to monitor the resilience of oil shipments to the country following the US military strike in January.

Other activity in the region included a malware campaign by China-aligned group UNC5221, which targeted entities in Cambodia and Panama. It was also UNC5221 which targeted the AI and robotics company in South Korea.

Russian Hacking Campaigns

According to the ESET, Russia-aligned threat actors continued to focus their activity on Ukraine, especially against organizations and individuals connected to the military and defense.

Russian APT groups also heavily targeted drone manufacturers, and organizations involved in drone research and development. They also directed cyber-attacks against logistics and transportation companies outside Ukraine in an effort to disrupt Ukrainian defensive efforts against the Russian invasion.

The period also saw what ESET described as “intensified destructive activity” by Sandworm, the cyberwarfare unit linked to Russia’s military intelligence service, which deployed wiper malware against infrastructure and services in Ukraine.

ESET has also previously attributed an attack against the Polish energy sector in December 2025 to Sandworm activity.

Iranian APT Activity

ESET noted that the US war against Iran has coincided with a decline in activity by established Iran-aligned APT groups, likely linked to restrictions on internet usage placed on the population by the Iranian regime. The internet outage has hindered the ability of Iranian hacking groups to operate effectively.

However, the report also noted that there has been a spike in activity by proxy-groups and hacktivists operations, which appear to support Iranian interests by targeting nations viewed as hostile to the regime, including the US and Israel.

In the Middle East, Israel remained the principal focus of Iran-aligned and Iran-linked activities. Targets range from organizations affected by espionage intrusions to device manufacturers hit by destructive tooling. 



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHighly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
Next Article GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
Team-CWD
  • Website

Related Posts

News

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

May 30, 2026
News

AI-Generated npm Malware Leaks Its Own GitHub Token

May 29, 2026
News

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

In memoriam: David Harley

November 12, 2025

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.