Thursday, March 5, 2026
33.1 C
New Delhi

What Is Phantom Taurus? Chinese Hacker Group Targets Foreign Ministers’ Emails In Years-Long Espionage Drive

Show Quick Read

Key points generated by AI, verified by newsroom

A team of cybersecurity experts has uncovered a sweeping cyber-espionage campaign in which suspected Chinese hackers infiltrated the email servers of foreign ministers and diplomats worldwide. According to researchers at Palo Alto Networks’ Unit 42, the attackers gained access to Microsoft Exchange servers, enabling them to search for sensitive information at select foreign ministries.

The findings, first reported by Bloomberg, suggest that the group has been operating for nearly three years, pursuing intelligence that aligns with Beijing’s geopolitical agenda.

Keywords Point To High-Level Diplomacy

Investigators discovered that the hackers specifically combed through servers for terms tied to the 2022 China-Arab summit in Riyadh. Their searches even included the names of Chinese President Xi Jinping and First Lady Peng Liyuan in relation to the event.

“When I found them searching for specific diplomatic keywords and then exfiltrating emails from embassies and military operations, I realised this was a serious intelligence collection effort,” said Lior Rochberger, senior researcher at Palo Alto Networks.

While the researchers avoided naming affected nations, their report highlighted how the hackers’ activity “align consistently with the People’s Republic of China (PRC) economic and geopolitical interests.” The group has been labelled Phantom Taurus by the company.

China Dismisses Allegations

Responding to the report, Liu Pengyu, spokesperson for the Chinese Embassy in Washington, argued that cyberattacks are a global issue. “Cyberspace is highly virtual, difficult to trace, and involves a diverse range of actors,” he said. “Tracing the source of cyberattacks is a complex technical issue that requires solid and full evidence.”

Broader Pattern Of Cyber Aggression

The revelations add to growing evidence of Chinese-linked hacking activity across industries and governments. Earlier this month, Google said a Chinese group had breached US technology companies. In another case, suspected hackers impersonated the Republican chair of the House Select Committee on China in an attempt to extract details about trade negotiations.

Assaf Dahan, director of threat intelligence at Palo Alto Networks, noted that many of the breaches had “a tight correlation to specific geopolitical events or military manoeuvres.” The company’s research also pointed to efforts targeting information related to countries such as Afghanistan and Pakistan.

The latest disclosure underlines how state-linked hackers are increasingly blurring the line between diplomacy and digital espionage, raising alarms within global cybersecurity circles.

Go to Source

Hot this week

Magnus Carlsen set to make classical return in May at Sigeman Chess 2026, Arjun Erigaisi to represent India

Magnus Carlsen will be competing in Sweden before he he heads home for the Norway Chess tournament. This will mark his first appearance in a closed round-robin classical tournament outside his home country in 3 years. Read More

Iran sends second ship to Indian Ocean, Sri Lanka fears US military may launch another strike

President Anura Kumara Dissanayake reviewed Iran’s request to allow the vessel into its waters for safety as tensions escalate after a US submarine attack killed 87 Iranian sailors near Galle Go to Source Read More

Trump Is Bombing Iran Without A War Declaration. Can A US President Get Away With It?

With the Senate having declined to restrict his authority, Trump retains full discretion over the scope and continuation of US military operations against Iran. Read More

‘Baseless And Not True’: US Rejects Reports Of F-15E Eagle Crash In Iran

Hours after reports of Iranian air defenses hitting a US F-15E, US Central Command called them “baseless,” stating on X that rumors of the crash in Iran are “NOT TRUE. Read More

GK: Which Mountain Is Called ‘Roof Of The World’?

It forms one of the highest plateaus on the earth. Read More

Topics

Magnus Carlsen set to make classical return in May at Sigeman Chess 2026, Arjun Erigaisi to represent India

Magnus Carlsen will be competing in Sweden before he he heads home for the Norway Chess tournament. This will mark his first appearance in a closed round-robin classical tournament outside his home country in 3 years. Read More

Iran sends second ship to Indian Ocean, Sri Lanka fears US military may launch another strike

President Anura Kumara Dissanayake reviewed Iran’s request to allow the vessel into its waters for safety as tensions escalate after a US submarine attack killed 87 Iranian sailors near Galle Go to Source Read More

Trump Is Bombing Iran Without A War Declaration. Can A US President Get Away With It?

With the Senate having declined to restrict his authority, Trump retains full discretion over the scope and continuation of US military operations against Iran. Read More

‘Baseless And Not True’: US Rejects Reports Of F-15E Eagle Crash In Iran

Hours after reports of Iranian air defenses hitting a US F-15E, US Central Command called them “baseless,” stating on X that rumors of the crash in Iran are “NOT TRUE. Read More

GK: Which Mountain Is Called ‘Roof Of The World’?

It forms one of the highest plateaus on the earth. Read More

BBC suggests licence fee could be cut if more people pay

Five of the BBC’s 14-strong board, including the chairman, are currently appointed by the government. Read More

‘Tickets Were Priced Up To Rs 1.9 Lakh’: Stranded Travellers Return On Special Dubai-Ahmedabad Flight

A relief flight from Dubai landed safely in Ahmedabad early Thursday, bringing 170 stranded Indian passengers. Families welcomed their loved ones after days of anxiety. Read More

Related Articles