Sunday, April 5, 2026
27.5 C
New Delhi

What Is Phantom Taurus? Chinese Hacker Group Targets Foreign Ministers’ Emails In Years-Long Espionage Drive

Show Quick Read

Key points generated by AI, verified by newsroom

A team of cybersecurity experts has uncovered a sweeping cyber-espionage campaign in which suspected Chinese hackers infiltrated the email servers of foreign ministers and diplomats worldwide. According to researchers at Palo Alto Networks’ Unit 42, the attackers gained access to Microsoft Exchange servers, enabling them to search for sensitive information at select foreign ministries.

The findings, first reported by Bloomberg, suggest that the group has been operating for nearly three years, pursuing intelligence that aligns with Beijing’s geopolitical agenda.

Keywords Point To High-Level Diplomacy

Investigators discovered that the hackers specifically combed through servers for terms tied to the 2022 China-Arab summit in Riyadh. Their searches even included the names of Chinese President Xi Jinping and First Lady Peng Liyuan in relation to the event.

“When I found them searching for specific diplomatic keywords and then exfiltrating emails from embassies and military operations, I realised this was a serious intelligence collection effort,” said Lior Rochberger, senior researcher at Palo Alto Networks.

While the researchers avoided naming affected nations, their report highlighted how the hackers’ activity “align consistently with the People’s Republic of China (PRC) economic and geopolitical interests.” The group has been labelled Phantom Taurus by the company.

China Dismisses Allegations

Responding to the report, Liu Pengyu, spokesperson for the Chinese Embassy in Washington, argued that cyberattacks are a global issue. “Cyberspace is highly virtual, difficult to trace, and involves a diverse range of actors,” he said. “Tracing the source of cyberattacks is a complex technical issue that requires solid and full evidence.”

Broader Pattern Of Cyber Aggression

The revelations add to growing evidence of Chinese-linked hacking activity across industries and governments. Earlier this month, Google said a Chinese group had breached US technology companies. In another case, suspected hackers impersonated the Republican chair of the House Select Committee on China in an attempt to extract details about trade negotiations.

Assaf Dahan, director of threat intelligence at Palo Alto Networks, noted that many of the breaches had “a tight correlation to specific geopolitical events or military manoeuvres.” The company’s research also pointed to efforts targeting information related to countries such as Afghanistan and Pakistan.

The latest disclosure underlines how state-linked hackers are increasingly blurring the line between diplomacy and digital espionage, raising alarms within global cybersecurity circles.

Go to Source

Hot this week

Fide CEO hits back at Nakamura over criticism of ‘essential’ Candidates anti-cheating measures: ‘No other participant…’

Fide CEO Emil Sutovsky slammed Hikaru Nakamura over his criticism of the anti-cheating measures in place for the 2026 Candidates in Cyprus, with the latter even suggesting players were being treated like “Mossad agents in Iran”. Read More

‘Whole region will burn’: Iran slams Trump for ‘following Netanyahu’s commands’

Tehran hit back with a sharp warning, accusing Trump of pushing the US towards a wider regional crisis as tensions over the Strait of Hormuz escalate. Read More

‘They don’t have any role’: Iran Supreme Leader’s representative in India rejects Pakistan’s mediation claims

Iran Supreme Leader’s representative in India has dismissed claims that Pakistan is mediating between Iran and the United States, calling such reports untrue amid ongoing tensions in West Asia. Read More

‘Swears Like A Teenager’: Iran Embassies Join In To Mock Trump’s Expletive-Laden Hormuz Threat

Iranian embassies mock Trumps expletive threat to strike Iran if Strait of Hormuz stays blocked, replying with memes and jibes about his language and US global image. Read More

‘POTUS Is Ranting Like Unhinged Madman’: Trump’s Easter Sunday Iran Warning Sparks Outrage In US

Trump’s profanity‑laden warning to Iran has sparked a wide‑ranging reaction in the US with Democrats, media and citizens alarmed by the tone and implications of the message. Read More

Topics

Fide CEO hits back at Nakamura over criticism of ‘essential’ Candidates anti-cheating measures: ‘No other participant…’

Fide CEO Emil Sutovsky slammed Hikaru Nakamura over his criticism of the anti-cheating measures in place for the 2026 Candidates in Cyprus, with the latter even suggesting players were being treated like “Mossad agents in Iran”. Read More

‘Whole region will burn’: Iran slams Trump for ‘following Netanyahu’s commands’

Tehran hit back with a sharp warning, accusing Trump of pushing the US towards a wider regional crisis as tensions over the Strait of Hormuz escalate. Read More

‘They don’t have any role’: Iran Supreme Leader’s representative in India rejects Pakistan’s mediation claims

Iran Supreme Leader’s representative in India has dismissed claims that Pakistan is mediating between Iran and the United States, calling such reports untrue amid ongoing tensions in West Asia. Read More

‘Swears Like A Teenager’: Iran Embassies Join In To Mock Trump’s Expletive-Laden Hormuz Threat

Iranian embassies mock Trumps expletive threat to strike Iran if Strait of Hormuz stays blocked, replying with memes and jibes about his language and US global image. Read More

‘POTUS Is Ranting Like Unhinged Madman’: Trump’s Easter Sunday Iran Warning Sparks Outrage In US

Trump’s profanity‑laden warning to Iran has sparked a wide‑ranging reaction in the US with Democrats, media and citizens alarmed by the tone and implications of the message. Read More

‘Looks good to me’: Florida man cooks invasive green iguanas with waffles in viral video

A Florida man has gone viral after sharing his recipe for green iguana, an invasive species causing damage across the state, encouraging residents to turn the pest into a meal. Read More

Chabahar work to expand even more rapidly in post-war era’: Iran envoy

File photo- Chabahar port New Delhi: As bombs fall and sanctions bite across West Asia, Iran has said its economic engagement with India will remain steady during the war and grow faster once conditions stabilise. Read More

Related Articles