“If they are sitting on their adversaries’ networks — media organizations, or government entities or their defense companies — they are able to flip a switch if conflict were to occur.” These words from SentinelOne’s Tom Hegel, as quoted by The Register, encapsulate the chilling reality uncovered by a year-long investigation into one of the most sweeping cyberespionage campaigns attributed to China-linked threat actors in recent memory.

The operation, initiated as early as June 2024, has compromised a minimum of 75 organizations in sectors of critical infrastructure globally, such as manufacturing, government, finance, telecommunications, and research. SentinelLABS uncovered this operation following their own infrastructure being hit a foiled breach attempt that saw a worldwide pursuit of other victims as well as the perpetrators of the attacks. The activity was traced to three well-known China-nexus advanced persistent threat (APT) organizations: APT15 (Ke3Chang/Nylon Typhoon), UNC5174, and APT41 each with long histories of targeting sensitive industries and conducting cyberespionage on behalf of Chinese state interests on several continents.
APT15, for example, is renowned for its worldwide operations into telecommunications, IT services, and government entities, frequently using quickly growing operational relay box (ORB) networks to hide attribution and sustain persistent access. UNC5174, valued by Mandiant as a China Ministry of State Security contractor, is expert in zero-day exploitation and is an initial access broker who occasionally resells compromised assets to other actors. APT41, on the other hand, is notorious for its double life as both an espionage and financially motivated actor, and is most closely tied to ShadowPad modular backdoor deployment and development.
ShadowPad’s technical complexity has also rendered it a tool of choice for Chinese cyber operators. Initially discovered in 2017 and originally APT41-exclusive, ShadowPad has since spread among several Chinese APTs and is now a signature of state-sponsored espionage and supply chain attacks. It is modular in architecture to enable operators to load plugins dynamically for keylogging, credential theft, exfiltration of files, and lateral movement. Interestingly, ShadowPad is often distributed through DLL side-loading, employing legitimate signed executables that are susceptible to search order hijacking a measure that makes detection and forensics more challenging. Attackers in recent attacks have employed programs like SentinelMemoryScanner.exe and Logger.exe, combined with malicious DLLs, to decode and run the payload completely in memory, frequently erasing evidence after execution to avoid analysis.
The technical sophistication of the campaign reaches into sophisticated obfuscation and anti-analysis methods. New ShadowPad samples utilize own algorithms to encrypt payloads in the Windows registry, utilizing machine-specific values such as the volume serial number to decrypt them. The malware exploits DNS over HTTPS (DoH) as a method for command-and-control (C2) communication, evading traditional network monitoring by concealing DNS queries in encrypted web traffic. Some also include anti-debugging functionality and runtime integrity checks, again increasing the bar for defenders and researchers following these operations.
Detection, hence, needs a multi-layered solution. Behavioral anomaly detection, such as that employed by companies like Darktrace, has been found to be vital in detecting lateral movement through SMB and WMI, data staging, and exfiltration even when attackers leverage breached VPN credentials and legitimate tools to hide in plain sight. For example, Darktrace saw attackers take advantage of Check Point VPN vulnerabilities (specifically CVE-2024-24919), lateral movement to drop ShadowPad onto domain controllers, and then exfiltrate gigabytes of confidential information to a network of compromised C2 sites within Europe’s finance and manufacturing industries.
Mapping these TTPs in the MITRE ATT&CK framework uncovers a full playbook: initial access through valid accounts (T1078.002), exploitation of remote services (T1210), privilege escalation by default accounts (T1078.001), defense evasion by masquerading (T1036.005) and obfuscated files (T1027), lateral movement through SMB (T1021.002), and exfiltration through C2 channels (T1041). The use by attackers of publicly known tools such as GOREshell and dsniff combined with bespoke malware demonstrates a mix of open-source and bespoke capability, with infrastructure frequently controlled by third-party providers to further complicate attribution.
Tactically, the campaign is consistent with a wider Chinese pre-positioning doctrine of positioning cyber assets inside adversary networks for future employment. Canada’s Communications Security Establishment, in its 2025 threat assessment, wrote that Beijing is “very likely” incorporating cyber activity into military planning to gain an advantage… in the event of a major crisis or conflict with the U.S. Not just espionage is the goal but, potentially, the ability to disrupt, degrade, or destroy key infrastructure on a whim a judgment shared by several Western intelligence agencies monitoring Chinese cyber policy.
The victimology of this campaign is revealing. In addition to attacking conventional government and defense targets, the attackers have moved into cybersecurity providers, IT logistics companies, and large media outlets. This move into the supply chain and information network emphasizes a realization that penetrating or disrupting these nodes can provide disproportionate strategic gain. As SentinelLABS noted, “Cybersecurity companies are high-value targets for threat actors due to their protective roles, deep visibility into client environments, and ability to disrupt adversary operations.”
Operational infrastructure supporting these attacks is also fluid. ORB networks, deployed quickly and continuously evolving, offer robust C2 channels and enable cross-group coordination. Domain registration trends, common server fingerprints, and SSH key reuse among malware samples indicate an advanced ecosystem in which access, tools, and infrastructure are rented or brokered by multiple entities a signature of the contemporary Chinese cyberespionage world as observed by SentinelLABS.
For IT security professionals and threat intelligence analysts, the strategic and technical takeaways are obvious. Prognostication and defense against such campaigns require not just endpoint and network layer vigilance but also an intimate knowledge of emerging TTPs, instant sharing of indicators of compromise, and the implementation of advanced detection technologies able to bring out granular behavioral anomalies. The continuous national modernization of cybersecurity laws, i.e., the UK’s Cyber Security and Resilience Bill, is a testament to the pressing necessity to be resilient against nation-state actors who increasingly consider the world’s digital infrastructure as target and battleground for the next generation of conflict.

