{"id":10953,"date":"2026-02-26T10:03:44","date_gmt":"2026-02-26T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/26\/google-disrupts-chinese-hackers-infrastructre-which-breached-53-telecom-and-government-entities\/"},"modified":"2026-02-26T10:03:44","modified_gmt":"2026-02-26T10:03:44","slug":"google-disrupts-chinese-hackers-infrastructre-which-breached-53-telecom-and-government-entities","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/26\/google-disrupts-chinese-hackers-infrastructre-which-breached-53-telecom-and-government-entities\/","title":{"rendered":"Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities"},"content":{"rendered":"<p>    Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A suspected Chinese state-linked hacking group has been caught running one of the most far-reaching cyber espionage operations ever uncovered \u2014 silently breaching telecom providers and government bodies across four continents for nearly a decade. <\/p>\n<p>Google has now stepped in to dismantle that operation entirely, severing the group\u2019s persistent access and releasing threat intelligence to help affected organizations identify and respond.<\/p>\n<p>Google Threat Intelligence Group (GTIG) and Mandiant took coordinated action to disrupt a global espionage campaign tied to a threat actor tracked as UNC2814 \u2014 assessed to be linked to the People\u2019s Republic of China (PRC). <\/p>\n<p>GTIG has monitored this group since 2017. By February 18, 2026, the investigation confirmed 53 victims across 42 countries, with suspected infections in at least 20 more nations spanning Africa, Asia, and the Americas. <\/p>\n<p>That scope reflects nearly a decade of deliberate, focused effort targeting some of the world\u2019s most sensitive communication infrastructure.<\/p>\n<p>The campaign centered on a previously undocumented backdoor called GRIDTIDE. <\/p>\n<p>Rather than using dedicated command servers, GRIDTIDE routes communications through Google Sheets \u2014 treating spreadsheet cells as a live messaging channel between the attacker and compromised machines. <\/p>\n<p>This disguised malicious traffic as routine cloud activity, making it extremely difficult for standard network defenses to detect. <\/p>\n<p>UNC2814 has no known overlap with the publicly reported Salt Typhoon group; it targets entirely different victims using distinct methods, tools, and procedures.<\/p>\n<p><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/disrupting-gridtide-global-espionage-campaign?linkId=56917417\" id=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/disrupting-gridtide-global-espionage-campaign?linkId=56917417\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Cloud analysts identified GRIDTIDE<\/a> after a Mandiant Threat Defense investigation flagged suspicious behavior on a customer\u2019s CentOS Linux server. <\/p>\n<p>A detection alert surfaced a binary named\u00a0<code>\/var\/tmp\/xapt<\/code>\u00a0\u2014 crafted to resemble a common system tool \u2014 that had launched a shell with root-level privileges and was running commands to confirm complete machine control. <\/p>\n<p>That discovery gave investigators the critical thread needed to unravel UNC2814\u2019s full operation. The binary name\u00a0<code>xapt<\/code>\u00a0was deliberately chosen to impersonate the legacy package management utility found in Debian-based Linux systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiktvks3w4OL5jJWHtWWsLUW5DIzFiTEWPaYlKmle5NVJpaTWuoJkAOtVuD59h2Cs8KKFg3MQ9vSyT48F6oOZiFczWpNZFnCdDsHzhW7fz5-ZAnqI2yVL4BkQQgsnrAwLpoGNLUnRfJdhK-tsuv_cYw8nP4Cjz3xqxh2T7MwCYe4v5yoV0awhf7Kik8eOA\/s16000\/GRIDTIDE%2520infection%2520lifecycle%2520%28Source%2520-%2520Google%2520Cloud%29.webp?ssl=1\" alt=\"GRIDTIDE infection lifecycle (Source - Google Cloud)\"><figcaption class=\"wp-element-caption\">GRIDTIDE infection lifecycle (Source \u2013 Google Cloud)<\/figcaption><\/figure>\n<\/div>\n<p>While the exact initial access vector has not been confirmed, UNC2814 has a history of breaking in by compromising internet-facing <a href=\"https:\/\/cybersecuritynews.com\/2-million-web-servers-worldwide\/\" id=\"7495\" target=\"_blank\" rel=\"noreferrer noopener\">web servers<\/a> and edge network devices. <\/p>\n<p>Once inside, the group relied on legitimate built-in <a href=\"https:\/\/cybersecuritynews.com\/vgauth-flaws-of-vmware-tools\/\" id=\"117613\" target=\"_blank\" rel=\"noreferrer noopener\">system tools<\/a> to move laterally \u2014 a technique known as \u201cliving off the land\u201d \u2014 avoiding new software that could trigger security alerts. <\/p>\n<p>Targeted systems included machines holding personally identifiable information such as names, phone numbers, national ID numbers, and voter registration records, all consistent with PRC intelligence-collection priorities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"gridtides-persistence-and-command-and-control\"><strong>GRIDTIDE\u2019s Persistence and Command-and-Control<\/strong><\/h2>\n<p>After securing access, UNC2814 embedded GRIDTIDE by registering a systemd service at\u00a0<code>\/etc\/systemd\/system\/xapt.service<\/code>. <\/p>\n<p>The malware ran via the\u00a0<code>nohup<\/code>\u00a0command, ensuring it kept running well after the attacker\u2019s session ended. <\/p>\n<p>As a secondary communication channel, the group deployed SoftEther VPN Bridge, opening an encrypted outbound tunnel to external infrastructure that metadata suggests has been active since July 2018.<\/p>\n<p>GRIDTIDE is a C-based backdoor capable of executing shell commands, uploading files to compromised hosts, and exfiltrating data. <\/p>\n<p>It uses a 16-byte AES-128 encryption key to unlock its Google Drive configuration, which holds the service account credentials and Spreadsheet ID needed for C2 access. <\/p>\n<p>Once connected, it clears the spreadsheet\u2019s first 1,000 rows, fingerprints the victim machine \u2014 collecting hostname, OS version, local IP, and time zone \u2014 then stores that data in cell V1. <\/p>\n<p>Commands arrive through cell A1, and results return through a defined cell range. All traffic is encoded in URL-safe Base64 to bypass web filters and network inspection tools.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCL3Hx5JmPxuDqV62lHF6BRjCboqYYAeclfyYah-wo7y2-JwxVEBvxKTm2WZB-cckfXTNwVz0xdZVQaIQkhh9Y37WtGoIm6GFjTvYky_hX4lZUhF55EsytvuG1WLIFC6Py_lwkYsn5T6htqCvCQ4_hzmxypJ4hTwgqUBMccPMgaKHIpy4gUXrD5pBniV4\/s16000\/GRIDTIDE%2520execution%2520lifecycle%2520%28Source%2520-%2520Google%2520Cloud%29.webp?ssl=1\" alt=\"GRIDTIDE execution lifecycle (Source - Google Cloud)\"><figcaption class=\"wp-element-caption\">GRIDTIDE execution lifecycle (Source \u2013 Google Cloud)<\/figcaption><\/figure>\n<\/div>\n<p>Organizations should monitor outbound HTTPS connections to Google Sheets API endpoints \u2014 especially requests involving\u00a0<code>batchClear<\/code>,\u00a0<code>batchUpdate<\/code>, and\u00a0<code>valueRenderOption=FORMULA<\/code>\u00a0\u2014 from non-browser processes. <\/p>\n<p>Security teams should also check for systemd services in unexpected directories, binaries running from\u00a0<code>\/var\/tmp\/<\/code>, and SoftEther VPN components on <a href=\"https:\/\/cybersecuritynews.com\/hardening-linux-servers\/\" id=\"108825\" target=\"_blank\" rel=\"noreferrer noopener\">Linux servers<\/a>. <\/p>\n<p>Applying GTIG\u2019s published YARA rule for GRIDTIDE and cross-referencing the released IOC list with internal logs will help confirm whether any residual exposure from this campaign remains.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-disrupts-chinese-hackers-infrastructre\/\">Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-disrupts-chinese-hackers-infrastructre\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities A suspected Chinese state-linked hacking group has been caught running one of the most far-reaching cyber espionage operations ever uncovered \u2014 silently breaching telecom providers and government bodies across four continents for nearly a decade. Google has now stepped in to dismantle that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10953","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10953"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10953"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10953\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}