Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Google Disrupts Chinese Hackers Targeting Telecoms, Governments
    Cybersecurity

    Google Disrupts Chinese Hackers Targeting Telecoms, Governments

    adminBy adminFebruary 26, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    China APT disrupted
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google announced on Wednesday that it has disrupted a significant China-linked cyberespionage campaign targeting telecoms and government organizations worldwide.

    The threat actor, tracked by Google’s Threat Intelligence Group (GTIG) and Mandiant as UNC2814, has been active since at least 2017. It has been described as one of the most far-reaching and impactful campaigns encountered in recent years.

    According to Google, this elusive threat actor has targeted at least 53 organizations across 42 countries in the Americas, Asia, and Africa. There is suspicion that the cyberspies may have targeted at least 20 other countries.

    “The attacker was using API calls to communicate with SaaS apps as command-and-control (C2) infrastructure to disguise their malicious traffic as benign, a common tactic used by threat actors when attempting to improve the stealth of their intrusions,” the tech giant explained. “Rather than abusing a weakness or security flaw, attackers rely on cloud-hosted products to function correctly and make their malicious traffic seem legitimate.”

    The threat actor has used a new backdoor named GridTide, which enables shell command execution, and file uploads and downloads.

    “The backdoor leverages Google Sheets as a high-availability C2 platform, treating the spreadsheet not as a document, but as a communication channel to facilitate the transfer of raw data and shell commands,” Google explained.

    The company’s researchers observed GridTide on an endpoint containing personal information such as names, dates of birth, phone numbers, voter IDs, and national IDs. The targeting of this type of data suggests that the hackers may have been trying to track and monitor individuals of interest. 

    Advertisement. Scroll to continue reading.

    “GTIG did not directly observe UNC2814 exfiltrate sensitive data during this campaign,” Google said. “However, historical PRC-nexus espionage intrusions against telecoms have resulted in the theft of call data records, unencrypted SMS messages, and the compromise and abuse of lawful intercept systems.”

    While the targeting of telecoms companies by a Chinese threat actor is reminiscent of the group called Salt Typhoon, Google noted that it has found no overlaps between Salt Typhoon and UNC2814.

    Disrupting the UNC2814 campaign

    To disrupt UNC2814’s campaign, GTIG, Mandiant and their partners eliminated cloud resources used by the GridTide malware. 

    They also took down all the infrastructure associated with the cyberespionage operation. This included sinkholing current and historical domains to sever access to compromised environments.

    In addition, they disabled accounts used by the hackers (including Google Cloud accounts used for C&C), and terminated access to the Google Sheets instances used by the malware.

    Victims have been notified and assisted with incident response. Google has also released IoCs designed to help organizations detect GridTide and other UNC2814 activity. 

    Google expects this disruption to significantly set back UNC2814’s efforts to build out its global footprint.

    Related: RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

    Related: Google Says Chinese ‘Lighthouse’ Phishing Kit Disrupted Following Lawsuit 

    Related: RaccoonO365 Phishing Service Disrupted, Leader Identified

    Chinese disrupts Google Governments hackers targeting telecoms
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGalaxy users are finding free $50 credits in their Samsung accounts
    Next Article This Samsung Galaxy S26 Ultra preorder deal is on a whole different level
    admin
    • Website

    Related Posts

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    Google Clarifies How It Picks Thumbnails For Search, Discover

    March 3, 2026

    AI went from assistant to autonomous actor and security never caught up

    March 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026

    Google Clarifies How It Picks Thumbnails For Search, Discover

    March 3, 2026
    Categories
    • Blogging (32)
    • Cybersecurity (572)
    • Privacy & Online Earning (80)
    • SEO & Digital Marketing (357)
    • Tech Tools & Mobile / Apps (709)
    • WiFi / Internet & Networking (103)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Best High-Yield Checking Accounts for March 2026

    March 3, 2026

    This amazing ESP32 projector integrates with Home Assistant and displays whatever you want

    March 3, 2026

    SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

    March 3, 2026
    Most Popular
    • Best High-Yield Checking Accounts for March 2026
    • This amazing ESP32 projector integrates with Home Assistant and displays whatever you want
    • SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
    • Google Clarifies How It Picks Thumbnails For Search, Discover
    • These budget-friendly wireless earbuds deliver a pleasant experience while still being easy on the wallet
    • AI went from assistant to autonomous actor and security never caught up
    • Segway Cube 1000 Portable Power Station hits lowest price ever!
    • How Microsoft, partners are tackling ‘huge, huge task’ of making security software safer
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.