• Book Dewayne Hart
  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
  • Speaker Bio
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Blog
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Blog
Facebook-f Linkedin-in Youtube X-twitter Globe
Order books

A Pro-China Influence Network of Fake News Sites

Posted on November 23, 2024 by admin

[ad_1]

Nov 23, 2024Ravie LakshmananCloud Security / Threat Intelligence

Fake News Sites

Government agencies and non-governmental organizations in the United States have become the target of a nascent China state threat actor known as Storm-2077.

The adversary, believed to be active since at least January 2024, has also conducted cyber attacks against the Defense Industrial Base (DIB), aviation, telecommunications, and financial and legal services across the world, Microsoft said.

The activity cluster, the company added, overlaps with a threat group that Recorded Future’s Insikt Group is tracking as TAG-100.

Attack chains have involved targeting various internet-facing edge devices using publicly available exploits to gain initial access and drop Cobalt Strike as well as open-source malware such as Pantegana and Spark RAT, the cybersecurity company noted back in July.

Cybersecurity

“Over the past decade, following numerous government indictments and the public disclosure of threat actors’ activities, tracking and attributing cyber operations originating from China has become increasingly challenging as the attackers adjust their tactics,” Microsoft said.

Storm-2077 is said to orchestrate intelligence-gathering missions using phishing emails to harvest valid credentials associated with eDiscovery applications for follow-on exfiltration of emails, which could contain sensitive information that could enable attackers to advance their operations.

“In other cases, Storm-2077 has been observed gaining access to cloud environments by harvesting credentials from compromised endpoints,” Microsoft said. “Once administrative access was gained, Storm-2077 created their own application with mail read rights.”

Fake News Sites

The disclosure comes as Google’s Threat Intelligence Group (TAG) shed light on a pro-China influence operation (IO) called GLASSBRIDGE that employs a network of inauthentic news sites and newswire services to amplify narratives that are aligned with the country’s views and political agenda globally.

The tech giant said it has blocked more than a thousand GLASSBRIDGE-operated websites from showing up in its Google News and Google Discover products since 2022.

Fake News Sites

“These inauthentic news sites are operated by a small number of stand-alone digital PR firms that offer newswire, syndication and marketing services,” TAG researcher Vanessa Molter said. “They pose as independent outlets that republish articles from PRC state media, press releases, and other content likely commissioned by other PR agency clients.”

This includes companies known as Shanghai Haixun Technology (which includes the HaiEnergy cluster), Times Newswire/Shenzhen Haimai Yunxiang Media (aka the PAPERWALL campaign), Shenzhen Bowen Media, and DURINBRIDGE, the last of which is a commercial firm distributing content for Haixun and DRAGONBRIDGE.

Cybersecurity

Shenzhen Bowen Media, a China-based marketing firm, is also said to operate World Newswire, the same press release service used by Haixun to place pro-Beijing content on the subdomains of legitimate news outlets, as revealed by Google’s Mandiant in July 2023.

Some of the subdomains identified were markets.post-gazette[.]com, markets.buffalonews[.]com, business.ricentral[.]com, business.thepilotnews[.]com, and finance.azcentral[.]com, among others.

“The inauthentic news sites operated by GLASSBRIDGE illustrate how information operations actors have embraced methods beyond social media in an attempt to spread their narratives,” Molter said. “By posing as independent, and often local news outlets, IO actors are able to tailor their content to specific regional audiences and present their narratives as seemingly legitimate news and editorial content.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Recent Posts

  • Secure to Scale: 7 Executive Strategies to Align Cybersecurity With Business Growth
  • No Blind Spots: A Veteran’s Blueprint to Protect Critical Infrastructure
  • Cybersecurity as a Growth Lever: A Board-Ready Playbook for CIOs and CTOs
  • From Reaction to Readiness: Building a Cybersecurity Mindset for Proactive Defense
  • Cybersecurity Leadership in 2026: Executive Decisions that Drive Resilience and Growth

Recent Comments

No comments to show.

Archives

  • March 2026
  • February 2026
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Cyber News
  • Uncategorized

Book Dewayne Hart for your next event

  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
Facebook-f Linkedin-in Youtube X-twitter Globe
© 2025 Dewayne Hart | Cybersecurity Leadership & Innovation
no_deposit_bonus