How China-Linked Hackers Are Targeting US Aerospace Firms and NGOs

China-linked groups used the same tool to exploit Chrome and Windows flaws in attacks on US aerospace firms and NGOs

The Narrative World    25-Sep-2026
Total Views |
FEATURED IMAGE- How China Linked Hackers Are Targeting US Aerospace Firms and NGOs
 
Multiple China-linked cyber-espionage outfits have been found using the same sophisticated break-in capability to target American aerospace firms, non-governmental organizations, mining companies and commodity traders, raising fresh alarms about coordinated computer network exploitation directed from Beijing.
 
Cybersecurity firms Volexity and Proofpoint have separately documented the activity. Volexity reported on 21 September that the discovery of yet another Chinese operator deploying the identical tool strengthens the assessment of systematic sharing within China’s cyber-espionage community. The widespread adoption, the firm noted, “suggests a coordinated effort within the Chinese Computer Network Exploitation (CNE) community,” with the core tool likely shared, customised and reused by multiple groups.

CHINA - IMAGE 1 (2)
 
Proofpoint, in its 9 September findings, recorded the same capability being employed against a limited number of US NGOs, mining and commodity-trading entities, as well as several American aerospace companies. Several distinct clusters most assessed to have a China nexus adopted the tool within days of one another. Neither firm has publicly named the developer or the distribution channel that placed the tool in the hands of these operators.
 
Same Capability, Divergent Targets
 
The groups pursued different victims and planted different surveillance implants once inside, yet all relied on the same underlying intrusion method. The attacks exploited previously unknown vulnerabilities in Google Chrome and Microsoft Windows. Successful exploitation allowed the operators to install spying software and maintain persistent access.

CHINA - IMAGE 2 (2)
 
Volexity observed one additional Chinese operator using the same attack chain on 3 and 4 September, while the vulnerabilities remained unpatched. The firm cautioned that the publicly known cases likely represent only a fraction of the activity: “The full scope and impact are likely far broader.”
 
Lures via Fake News and Policy Websites
 
The newly identified group also employed carefully crafted fake websites mimicking trusted media and policy platforms to reach intended targets. In one campaign, Asian government entities received a Chinese-language email focused on imprisoned Hong Kong activist Chow Hang-tung. The embedded link led to a spoofed site impersonating “China Digital Times”, the US-based outlet covering Chinese politics and censorship.
 
Another fake site mimicked the Center for American Progress, the Washington policy organization. Additional impersonations included The Conversation, which publishes academic commentary, and the “Borneo Bulletin”, Brunei’s English-language daily. The range of targets suggested by these decoys may indicate the operators’ broader intelligence priorities.

Another fake site mimicked the Center for American Progress
 
Wider Pattern of China-Aligned Operations
 
Separately, ESET reported on 17 September a China-aligned espionage campaign directed at governments and organizations across Latin America.

CHINA - IMAGE 4 (2)
 
One target was a Panamanian legal entity linked to the dispute over two major ports near the Panama Canal. Malware was deployed on some systems in that organization’s network in late December 2025 and January 2026, with further attempts continuing into June 2026.
 
ESET assessed the activity as likely espionage based on the identity of the target and the timing, though it could not confirm whether materials related to the port dispute were accessed or exfiltrated. No technical link has been established between this campaign and the tool-sharing activity documented by Volexity and Proofpoint.
 
 
These incidents fit a familiar pattern of Chinese cyber operations that prioritise strategic economic and technological intelligence. Aerospace, critical minerals, commodity trading and policy-influencing NGOs all sit at the intersection of national security and commercial advantage. The reuse of a single high-value exploit chain across multiple operators points to deliberate resource pooling rather than isolated freelancing.
 
For nations that value technological sovereignty and the integrity of their research and industrial base, the lesson is clear. Shared tooling, rapid adoption of zero-day vulnerabilities, and the systematic use of deceptive infrastructure are hallmarks of a state-directed enterprise that shows no sign of slowing.
 
 
Continuous vigilance, timely patching and rigorous scrutiny of anomalous network behaviour remain the minimum requirements for defence.
 
Written by
 
KEWALI KABIR JAIN
 
Kewali Kabir Jain
Journalism Student, Makhanlal Chaturvedi National University of Journalism and Communication