• News/
  • https://www.theregister.com/2025/09/24/google_china_spy_report/

Suspected Chinese spies broke into 'numerous' enterprises

The Register
·
Jessica Lyons
·
Published Sep 24, 2025
·
Updated

Unknown intruders – likely China-linked spies – have broken into "numerous" enterprise networks since March and deployed backdoors, providing access for their long-term IP and other sensitive data stealing missions, all the while remaining undetected on average for 393 days, according to Google Threat Intelligence. In a paper published today, the threat hunters attribute these network intrusions to UNC5221 and other related suspected Chinese threat groups. UNC5221 has been abusing zero-days in buggy Ivanti gear since at least 2023. Google notes that this UNC crew is separate from Silk Typhoon (aka Hafnium), believed to be behind the December break-in at the US Treasury Department. UNC in Google's threat-group naming taxonomy stands for "Uncategorized," as opposed to FIN (financially motivated) or APT (advanced persistent threat, which means government-backed). [Editor's note: read all about the various security companies' methods for naming cyber crews here... then go bang your head against the wall.] Since March, Google's Mandiant Consulting and incident response team have responded to these UNC5221-related break-ins across legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and technology companies. "The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims," Google Threat Intelligence wrote. ...

Read full article

Affected Software

1 affected component
Ivanti gear=2023
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses suspected Chinese espionage operations targeting numerous enterprise networks through the deployment of backdoors.

2

What security implications are discussed?

The security implications include unauthorized access to sensitive data and intellectual property potentially stolen by foreign spies.

3

What products or software are affected?

The affected software mentioned in the article is Ivanti Gear, specifically version 2023.

4

How long have these espionage activities been occurring?

The reported espionage activities have been ongoing since March.

5

What is the goal of the intruders in these cyberattacks?

The goal of the intruders is to gain long-term access for stealing intellectual property and sensitive data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203