Between March and June 2025, at least three China-linked hacking groups launched spear-phishing campaigns aimed at Taiwan’s critical semiconductor ecosystem—extending their reach beyond manufacturing firms to include upstream suppliers and financial analysts. That’s according to a joint investigation by Proofpoint.
Three Distinct Threat Clusters
- UNK_FistBump
Focused on semiconductor design teams, packaging, manufacturing organizations, and supply-chain suppliers. The actors used employment-themed phishing emails, posing as graduate-level job seekers and sending malicious payloads disguised as resumes. These payloads drop either the Red Team tool Cobalt Strike or a custom C backdoor called Voldemort, which has been previously linked to Chinese nation-state actors like APT41 and Brass Typhoon. - UNK_DropPitch
This group took a more finance-oriented approach, targeting investment analysts in Taiwan and beyond. Their phishing emails lured recipients with links to fake PDFs, which then unpacked a ZIP containing a malicious DLL. This DLL backdoor, dubbed HealthKick, initiates a reverse shell and downloads Intel’s Endpoint Management Assistant (EMA) when valuable networks are found. One campaign even established a TCP reverse shell to a hard-coded VPS address around late May 2025 . - UNK_SparkyCarp
Credible intelligence identified them using a bespoke adversary-in‑the-middle (AitM) kit designed to harvest credentials. This campaign specifically targeted a Taiwanese semiconductor firm via credential-phishing infrastructure—likely to intercept OTP or MFA tokens—in March 2025.
Scope and Scale
Proofpoint’s investigation highlighted that approximately 15–20 organizations were compromised, including semiconductor manufacturers, smaller suppliers, and investment firms—including at least one U.S.-based financial institution.
A Reuters quote from Proofpoint threat researcher Mark Kelly underscores the expanding scope:
“We’ve seen entities that we hadn’t ever seen being targeted in the past being targeted.”
Tactics, Techniques, and Procedures (TTPs)
- Email Delivery Vectors: Actors compromised academic or corporate email accounts to send lures.
- Employment-Style Phishing: Fake resumes (.LNK files with embedded malicious code).
- DLL Side-Loading: Packaging backdoor payloads with trusted software to evade detection.
- Custom Malware Payloads: Use of advanced tools like Voldemort and HealthKick, emphasizing tailored espionage operations.
- Infrastructure Reuse and Overlap: C2 servers leveraged SoftEther VPN setups and reused TLS certs previously tied to malware families such as MoonBounce and SideWalk, although whether this reflects shared malware code or shared infrastructure is unclear
Geopolitical Context
These aggressive techniques align with recent U.S. export restrictions on AI-capable chips, which Taiwan produces in volume for global markets. Beijing’s push to advance its national semiconductor capabilities dovetails with persistent cyber activity targeting Taiwan’s microchip supply chain.
As Reuters notes, this is not a new phenomenon—China-aligned threat actors have long targeted the supply chain—but campaigns have intensified in both frequency and sophistication.
Official Response and Implications
While proof of data exfiltration wasn’t publicly confirmed, these intrusions reflect ongoing intelligence gathering efforts—likely aimed at gaining insights into semiconductor process technologies, roadmaps, and market analyses.
A Chinese embassy spokesperson told Reuters:
“Cyber attacks ‘are a common threat faced by all countries, China included,’ … and that the Asian country ‘firmly opposes and combats all forms of cyber attacks and cyber crime.’”
However, cybersecurity experts argue these acknowledgments ignore the heightened scale and tailored nature of state-sponsored digital espionage—particularly campaigns targeting emerging strategic industries.
What’s Next
- Enhanced Monitoring: Taiwan’s semiconductor ecosystem and financial services are likely ramping up internal phishing defenses.
- Supply-Chain Scrutiny: Peripheral suppliers must adopt stricter cybersecurity, given attackers’ widening focus beyond chip fab facilities.
- Cross-Border Intelligence Sharing: Collaboration between Taiwan, U.S., and allied cybersecurity agencies will be key in responding to and attributing such attacks.
Chinese-aligned cyber operators are clearly on heightened alert—and so must the defenders within Taiwan’s semiconductor ecosystem. The next battleground in tech-driven geopolitics may well play out in inboxes and command‑and‑control channels, just as much as in foundries and trade negotiations.
Please subscribe to the Newsletter so that you do not miss any critical update
