[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz9wJ_3MQzMO7RpT2tZvZ9kANEzYGp71lqZ6xqKantAk":3},{"article":4,"iocs":50,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":34},"aa41e917-5728-407c-a988-eff8cd22a9c9","Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia","chinese-apt-abuses-multiple-cloud-tools-to-spy-on-mongolia-010f90","The threat actor gave itself plenty of options to support command and control, tapping Microsoft Outlook, Slack, Discord, and file.io for online espionage.","A Chinese state-sponsored threat actor has been conducting espionage operations against Mongolian targets by abusing legitimate cloud services—Microsoft Outlook, Slack, Discord, and file.io—as command and control channels. The adversary leveraged these widely-trusted platforms to evade traditional network detection and maintain persistent access to victim environments. This campaign demonstrates how attackers are increasingly weaponizing legitimate business tools to bypass security controls.","Chinese APT uses Outlook, Slack, Discord, and file.io for C2 in Mongolia espionage campaign.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fchinese-apt-abuses-cloud-tools-spy-mongolia","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt17fc2cec7ba9f5b3\u002F69e90f257417a71b03305c14\u002FBeijing_Ulaanbaatar-Trevor_Mogg-Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-24T01:00:00+00:00","2026-04-23T16:00:19.79584+00:00",8,[18,21,24,26,28],{"name":19,"type":20},"Chinese APT (unspecified)","threat_actor",{"name":22,"type":23},"Microsoft Outlook","technology",{"name":25,"type":23},"Slack",{"name":27,"type":23},"Discord",{"name":29,"type":23},"file.io","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":30,"icon":11,"name":32,"slug":33},"Nation-state","nation-state",[35,40,45],{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":41},{"id":42,"icon":11,"name":43,"slug":44},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":46},{"id":47,"icon":11,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]