Adversary Intelligence — 2026-05-04

45,000 Attacks and 5,300 Backdoors Tied to China-Linked Cybercrime Operation

SOCRadar's Threat Research Team reported on April 30 that a China-linked cybercrime operation has logged approximately 45,000 attack attempts using a centralized automation framework it calls Paperclip and OpenClaw. The operation has implanted backdoors on more than 5,300 hosts, with 3,981 running the "d2" implant and 1,393 running the "pl" implant, plus 900 webshell deployments. Attackers used 136 automated FOFA accounts to sustain reconnaissance against fintech companies, Web3 platforms, and security vendors, exploiting known RCE vulnerabilities including CVE-2025-55182, CVE-2025-66478, and Log4Shell (CVE-2021-44228). Post-compromise, the group harvests AI API keys, Stripe tokens, and database credentials, and tracks approximately 22,000 cryptocurrency addresses through OKLink and Tatum blockchain intelligence APIs.

Analysis
Per a single SOCRadar report, unverified by any independent source, a China-linked operation has crossed from opportunistic intrusion into infrastructure-scale credential harvesting: two proprietary frameworks, automated reconnaissance at volume, and a persistent implant footprint sized to sustain ongoing collection. Targeting confirms near-real-time monetization: AI API keys, Stripe tokens, and active blockchain monitoring of roughly 22,000 addresses are revenue-conversion assets, not intelligence holdings. Log4Shell remaining productive here reflects a patching gap that automated tooling exploits at low cost. PRC-linked operations against financial technology infrastructure are likely to maintain or exceed this tempo through Q3 2026. The attribution may instead reflect shared criminal toolkits or deliberate false-flag construction rather than a unified state-affiliated campaign.
1 sources
  1. 45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation - Hackread

View in full brief →

UNCLASSIFIED // OPEN SOURCE