Chinese Hackers Infiltrate U.S. Economic Policy Circles Using Fake Government Officials and VS Code Exploits

# Chinese Hackers Target US Officials with Sophisticated Spear-Phishing Campaign

A sophisticated cyber espionage campaign linked to Chinese state-sponsored hackers has been targeting high-profile US government officials, think tanks, and academic institutions using economic-themed lures focused on US-China relations.

## The Threat Actor

The campaign has been attributed to **TA415**, a China-aligned threat group with connections to the notorious APT41 and Brass Typhoon hacking collectives. Security researchers at Proofpoint identified this activity occurring throughout July and August 2025, coinciding with ongoing US-China trade negotiations.

## Attack Strategy

The hackers employed a clever impersonation strategy, masquerading as:
– The Chair of the Select Committee on Strategic Competition between the US and Chinese Communist Party
– Representatives from the US-China Business Council

Their primary targets included individuals specializing in international trade, economic policy, and US-China relations.

## How the Attack Works

### Initial Contact
Victims received convincing phishing emails from “uschina@zohomail[.]com” inviting them to exclusive briefings on US-Taiwan and US-China affairs. The attackers used Cloudflare WARP VPN to hide their true location.

### Malware Delivery
The emails contained links to password-protected archives hosted on legitimate cloud services like Zoho WorkDrive, Dropbox, and OpenDrive. These archives contained:
– A malicious Windows shortcut file (LNK)
– A decoy PDF document
– Hidden malware components

### System Compromise
Once activated, the attack chain:
1. Executes a batch script that runs **WhirlCoil**, an obfuscated Python loader
2. Creates persistent scheduled tasks (disguised as “GoogleUpdate” or “MicrosoftHealthcareMonitorNode”)
3. Establishes a Visual Studio Code remote tunnel for backdoor access
4. Harvests system information and user data
5. Sends stolen data to free request logging services

## Intelligence Gathering Objectives

This campaign appears designed to facilitate intelligence collection during sensitive US-China trade discussions. The sophisticated nature of the attack and its timing suggest state-sponsored motivations rather than financial gain.

## Broader Context

This activity aligns with recent warnings from the US House Select Committee on China about ongoing Chinese cyber espionage campaigns, including previous incidents where hackers impersonated Republican Congressman John Robert Moolenaar.

The use of legitimate cloud services and trusted software like Visual Studio Code demonstrates the evolving sophistication of state-sponsored cyber operations, making detection and attribution increasingly challenging for cybersecurity professionals.

Share This Article