London Daily

Focus on the big picture.
Wednesday, Jul 01, 2026

Chinese cyber spies 'posed as Iranians while targeting Israeli government'

Chinese cyber spies 'posed as Iranians while targeting Israeli government'

According to threat intelligence researchers, the hackers attempts to conceal their origin was more likely an effort to slow down response efforts than actually frame Iran.

A cyber espionage group from China masqueraded as Iranian hackers while breaking into and spying on Israeli government institutions, according to a new report by security researchers.

The report from security company FireEye, which unmasked the group alongside Israeli defence agencies, says there is insufficient evidence to link the espionage group to the Chinese state.

However, the company's threat analysts are confident that the espionage group is Chinese and that its targets "are of great interest to Beijing's financial, diplomatic, and strategic objectives".

The hackers' attempt to conceal their nationality was "a little bit unusual", according to Jens Monrad, who heads the work of FireEye's threat intelligence division Mandiant in EMEA.

"We have seen historically a few false flag attempts. We saw one during the Olympics in South Korea," he told Sky News, referencing Russian hackers pretending to be Chinese and North Korean.

"There might be several reasons why a threat actor wants to do a false flag - obviously it makes the analysis a bit more complex," Mr Monrad told Sky News.

The report focused on cyber spying targeting Israeli government institutions, IT providers, and telecommunications entities, but the group had additionally attempted to hack computer networks in the UAE and elsewhere.

Mr Monrad said the attempt to conceal the hackers' identity "wasn't very clever" but did slow the company's analysis of these incidents, which he added may have been the goal.

The Chinese group attempted to use Farsi in the parts of code which could be recovered by incident response teams, and also used hacking tools associated with Iranian groups that had previously been leaked online.

However, linguistic analysts at FireEye said the terms chosen by the group wouldn't have been used by native Farsi speakers.

"The use of Farsi strings, filepaths containing /Iran/, and web shells publicly associated with Iranian APT [Advanced Persistent Threat] groups may have been intended to mislead analysts and suggest an attribution to Iran," the report said.

FireEye said that although this group and the known state-sponsored group designated APT 27 had some overlaps, particularly in their targets, the company could only have low confidence in linking them together.

The Iranian government accused APT 27 of hacking into its networks in 2019.

Though the report was published this week, the hacking activities precede a warning in July from President Joe Biden about the growing likelihood of the US ending up in "a real shooting war with a major power" as a result of a cyber attack.

Speaking to Sky News previously - following then British defence secretary Gavin Williamson claiming that Moscow could cause "thousands and thousands and thousands" of deaths in the UK with a cyber attack - Mr Monrad cautioned that military responses to such an attack would requite a "very high certainty of attribution".

The new group, designated UNC 215 - meaning it is unclassified as either a state-sponsored group or one operating independently - also used the Hindi language and Arabic when targeting Uzbekistan.

FireEye's report stated: "This cyber espionage activity is happening against the backdrop of China's multi-billion-dollar investments related to the Belt and Road Initiative (BRI) and its interest in Israel's robust technology sector.

"China has conducted numerous intrusion campaigns along the BRI route to monitor potential obstructions [including] political, economic, and security," the company said, adding that it anticipates China will "continue targeting governments and organisations involved in these critical infrastructure projects".

The report follows the UK and allies accusing China of "systematic cyber sabotage" following an espionage operation earlier this year which also allowed criminals, potentially including those which Beijing used as contractors, to access the affected servers.

At the time, Chinese foreign ministry spokesman Zhao Lijian said: "The US ganged up with its allies and launched an unwarranted accusation against China on cybersecurity. It is purely a smear and suppression out of political motives. China will never accept this."

Newsletter

Related Articles

0:00
0:00
Close
Global Billionaire Numbers Rise 13 Percent Amid Artificial Intelligence Stock Boom
Body of Fifteen-Year-Old Boy Recovered from Manchester Reservoir
Major Rail Disruption in UK After Cows Stray Onto Intercity Tracks
UK Launches National Campaign to Reduce Water Consumption After Heatwave
Foreign Secretary David Lammy Raises Case of UK Woman Death with US Authorities
Shetland Islands Council Approves Subsea Tunnel Plans Linking Major Islands
Telegraph Media Group Takeover by German-Led Consortium Completed
Resident Doctors in England Accept Government Pay and Conditions Deal
Andy Burnham Sets Out Ten-Year Economic Vision Amid Labour Leadership Debate
Asylum Seekers in UK Face £10,000 Contribution Requirement Under New Law
UK Government Moves to Break Apple and Google App Store Dominance
New UK Steel Tariffs and Import Quotas Aim to Shield Domestic Industry
Damning Report Exposes Failures in Maternity and Neonatal Care Across England
Government Data Reveals Five Billion Pound Shortfall in UK Defence Budget
Prime Minister Keir Starmer Unveils Three Hundred Billion Pound Defence Investment Plan
UK Crime and Policing Act 2026 Comes into Force with New Justice System Reforms
UK Prime Minister Hosts NATO Secretary General Mark Rutte for Security Talks at Downing Street
UK Tightens Oversight of Emissions Trading Scheme Through New Ministerial Directions
UK Issues Statement at UN Security Council on Violence in the West Bank
UK Environment Agency Clears Illegal Waste Site in West Yorkshire After Court Action
UK Resident Sentenced for Fraudulently Claiming £30,000 in Covid Business Loans
UK Launches Taskforce to Help Young People Claim Dormant Child Trust Fund Savings
UK Gambling Commission Fines Betfred Operator Petfre Gibraltar £900,000 Over Social Responsibility Failures
UK Appoints Lord Collins as Global Envoy for LGBT+ Rights
UK Expands Detention Capacity to Support Removal of Foreign Criminals and Failed Asylum Seekers
UK Resident Doctors End Strike Action After Accepting Government Pay Deal
UK Tightens Sentencing for Domestic Killings with 25-Year Starting Point for Murder of Partners
UK to Build at Least Six New Royal Navy Warships Under Expanded Defence Programme
UK Government Unveils £5 Billion Defence Investment Plan Focused on Drones and Autonomous Warfare Systems
UK Economy Records 0.6% First Quarter Growth as Services and Manufacturing Drive Steady Expansion
Welsh Government Unveils New Agricultural Support Plan Focused on Sustainability and Rural Growth
UK Teacher Recruitment Shortfalls Continue in Science and STEM Subjects
Police Scotland Expands Cybercrime Investigations Amid Rising Digital Fraud
UK Universities Warn of Risk to International Student Numbers Amid Visa Changes
UK Defence Ministry Pivots Toward Greater Domestic Military Procurement
UK Launches National Rail Review After Repeated Service Disruptions
Northern Ireland Assembly Debates Long-Term Funding Settlement for Public Services
UK Accelerates Approval of North Sea Offshore Wind Projects to Expand Energy Capacity
UK Retail Sales Fall as Households Cut Discretionary Spending in June
UK Expands Border Intelligence Cooperation with France and Belgium to Target Smuggling Networks
Scottish Government Faces Pressure Over Delays in Major Infrastructure and Transport Projects
UK Launches Multi-Billion-Pound Artificial Intelligence Infrastructure Investment Fund
National Health Service Warns of Continued Emergency Department Strain Across England
Bank of England Signals Interest Rate Hold as Wage Growth Keeps Inflation Elevated
UK Sets Emergency Fiscal Strategy as Inflation Pressures and Weak Manufacturing Growth Persist
UK Launches New Measures to Improve Safety Standards in Night-Time Venues
UK Tightens Import Rules for Low-Value Parcels to Support Domestic Retailers
UK Launches £85 Million Obesity Care Programme Targeting Early Intervention Projects
UK Commits Up to $26 Million to Ebola Response in Democratic Republic of Congo
Security Industry Authority Flags Safety Failures in Night-Time Economy Inspections
×