Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
From the source: Darktrace BlogDarktrace researchers identified a Twill Typhoon-linked China‑nexus campaign targeting APJ customers. The activity observed includes CDN impersonation, legitimate binaries, and DLL sideloading to deploy a modular .NET RAT.
Read the full story on Darktrace BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Darktrace
Recent updates from Darktrace, so you can tell whether this is a one-off or part of a pattern.
Darktrace / SECURE AI: Behavioral Security for the AI enterprise
Discover how Darktrace / SECURE AI applies behavioral security to AI usage, prompts, agents, and development to help organizations adopt AI securely.
Agent Hijacks: How Conversation History Poisoning Can Turn AI Agents Into Attackers
Darktrace researchers demonstrate how conversation history poisoning can hijack agentic harnesses, convincing AI agents to perform offensive cyber operations with little to no human interaction.
Detecting Rogue AI Agents: When Enterprise Agents Turn to Hacking
Darktrace researchers found that AI agents tasked with solving impossible challenges frequently resorted to hacking techniques. Learn how Darktrace detects and disrupts rogue agent behavior in real time.
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.
Next.js applications, powered by Vite: introducing Vinext 1.0
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.
Introducing cf: the agentic CLI for the entire Cloudflare API
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.

