Description

A newly identified Chinese state-sponsored threat group, Storm-2077, has been actively targeting U.S. government agencies and NGOs since early 2024. According to Microsoft, the group has also expanded its focus to various global industries, including the Defense Industrial Base (DIB), aviation, telecommunications, financial services, and the legal sector. Their tactics involve exploiting internet-facing devices to deploy tools like Cobalt Strike, Pantegana, and Spark RAT, enabling initial access. Storm-2077's primary objective appears to be intelligence gathering, achieved through phishing campaigns to harvest credentials and exfiltrate sensitive emails via eDiscovery applications or by accessing cloud environments through compromised endpoints. The group's activities are associated with TAG-100, a threat group tracked by Recorded Future's Insikt Group. In a parallel development, Google has exposed GLASSBRIDGE, a pro-China influence campaign utilizing fake news websites and public relations firms to promote pro-Beijing narratives worldwide. Operated by companies such as Shanghai Haixun Technology and Shenzhen Bowen Media, GLASSBRIDGE replicates the appearance of independent media outlets while republishing content from Chinese state media. It also commissions other pieces to appear legitimate. These operations exploit subdomains of established news platforms and disseminate propaganda through newswire services like Times Newswire and World Newswire. Since 2022, Google has blocked more than a thousand sites linked to GLASSBRIDGE from its platforms. These events underscore the increasing sophistication of China's cyber and influence operations. Groups like Storm-2077 prioritize credential harvesting and cloud exploitation to secure broad access to sensitive information, while influence campaigns such as GLASSBRIDGE circumvent social media restrictions by imitating trusted local news outlets. Both efforts aim to further China's political objectives and strategic interests, targeting key industries and governments on a global scale.