安全客August 11, 2026🇨🇳Translated from Chinese

Chinese Courts Hand Down 16-Year and 32-Year Sentences to Ransomware Operators

Chinese courts have imposed significant prison sentences on two ransomware operators, marking a notable escalation in the prosecution of cyber extortion cases. One defendant received a 16-year term while the second was sentenced to 32 years, reflecting the severity of their respective roles in ransomware campaigns.

The longer sentence was linked to more extensive criminal activity, including the deployment of ransomware that caused substantial financial losses and operational disruption. Authorities emphasized that the cases demonstrate a firm stance against ransomware groups targeting organizations or individuals within China.

These verdicts are part of a wider pattern of increased enforcement actions against ransomware actors. Chinese law enforcement has intensified investigations into encryption-based extortion schemes, leading to multiple high-profile prosecutions in recent years.

Related articles

AntiMalwareRansomware & Extortion

Telegram Removed from App Store After Extortionist Plants AI-Modified CSAM in Archived Message

Pavel Durov stated that an extortionist edited an old public group message by inserting AI-altered child sexual abuse material, allowing the post to evade detection by active chat participants while enabling a direct report to Apple. The tactic triggered automatic removal of Telegram and experimental Telegram X from the App Store in multiple countries including Russia, Turkey, and the United States on August 4. Apple restored the applications after Telegram deleted the prohibited content and blocked the responsible account, with the entire outage lasting approximately ninety minutes. During the incident, push notifications failed for some iOS users, while macOS and Android versions remained unaffected. Durov criticized Apple for suspending the app without prior contact and warned that the same mechanism could be used against any user-generated content platform. Telegram urged Apple to apply equal scrutiny to all incoming reports rather than acting on isolated complaints that bypass normal moderation filters.

BoletimSecRansomware & Extortion

Cl0p Exploits Critical Windchill Vulnerability CVE-2026-12569 to Steal Industrial Designs

The Cl0p extortion group is actively targeting internet-exposed PTC Windchill and FlexPLM servers to exfiltrate engineering projects, technical specifications, and other sensitive data. The campaign focuses on organizations in the industrial, automotive, aerospace, defense, and retail sectors. Attackers leverage the critical remote code execution vulnerability CVE-2026-12569, which stems from unsafe deserialization and carries a CVSS score of 9.8, allowing unauthenticated exploitation over the network. The intrusion chain also combines a WSDL endpoint information disclosure in FlexPLM with a login mechanism weakness in Windchill to gain initial access and execute commands without valid credentials. After compromise, operators deploy JSP web shells to maintain persistence, explore files, and prepare data for exfiltration. Affected systems often contain unreleased product designs, engineering drawings, and strategic manufacturing documents. The activity began in early June 2026, with extortion emails sent to hundreds of employees starting July 20 to increase internal pressure ahead of potential data leaks.

BoletimSecRansomware & Extortion

Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers

The Chaos ransomware group has adopted a new Rust-based trojan called msaRAT to conceal its command-and-control communications inside legitimate browser sessions. The malware launches Chrome or Edge in invisible mode and controls it via the Chrome DevTools Protocol, keeping all outbound traffic restricted to localhost. It then injects JavaScript to negotiate a WebRTC connection through Cloudflare Workers before routing data over Twilio TURN servers, preventing the attackers' real infrastructure from appearing in network logs. Commands are executed through cmd.exe, and the implant includes queuing mechanisms that support reliable transfer of files, screenshots, and larger data volumes. In the analyzed incident, operators delivered the malware via an MSI installer disguised as a Windows update that loaded the msaRAT DLL directly into memory. The technique does not exploit any vulnerabilities in Chrome or Edge and is designed to blend malicious traffic with normal corporate browser activity.

BoletimSecRansomware & Extortion

Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257

Operators linked to the Qilin ransomware group have been actively exploiting an authentication bypass vulnerability in Palo Alto Networks PAN-OS to gain initial access to corporate networks. The attacks, observed in June 2026, targeted the GlobalProtect VPN service running on Palo Alto firewalls and were tracked under CVE-2026-0257. Attackers used specially crafted authentication cookies to establish unauthorized VPN sessions, after which they harvested credentials from Windows LSASS processes and Active Directory NTDS databases. Lateral movement relied heavily on PsExec and administrative shares, supplemented by tools such as AnyDesk, Ngrok, LogMeIn, and NetExec. Before deploying the ransomware binary stored as win.exe in C:\PerfLogs\, the threat actors disabled Microsoft Defender real-time protection and cleared event logs. The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 as well as certain Prisma Access editions, while Panorama and Cloud NGFW remain unaffected.