Daily Drop (1239)
02-05-26
Thursday, Feb 05, 2025 // (IG): BB // GITHUB // SN R&D
Leapfrogging China’s Critical Minerals Dominance
Bottom Line Up Front (BLUF): The CFR report highlights that while China controls around 60–70% of global rare earth processing capacity, it’s the refining and chemical conversion stages that create real dependencies. The U.S. has underinvested in these areas, and efforts remain fragmented across federal agencies. The report calls for a national strategy that emphasizes public-private coordination, tech innovation, and closer ties with allied producers like Australia and Canada. It also encourages funding for recycling tech, substitutes for rare earths, and improvements in domestic permitting processes.
Analyst Comments: The idea of out-mining China is a geopolitical fantasy—Beijing controls not just reserves, but the processing choke points, which are far harder to replicate. The CFR’s call to leapfrog rather than compete directly echoes similar strategies used in telecom (e.g., bypassing Huawei with Open RAN) and clean energy. From a cyber risk perspective, any expansion in minerals tech, especially around processing facilities and rare earth alternatives, will be an espionage magnet. Expect Chinese APTs to ramp up surveillance and infiltration efforts targeting R&D labs, joint ventures, and advanced material supply chains.
READ THE STORY: CFR
A U.S.–China Sanctions Trade? National Interest Explores Risks of Escalation in Economic Warfare
Bottom Line Up Front (BLUF): A National Interest analysis warns that the United States and China are sliding into a reciprocal sanctions cycle, where export controls and economic restrictions increasingly provoke countermeasures rather than compliance. What began as targeted controls on semiconductors and advanced tech now risks hardening into a self-sustaining sanctions trade with limited strategic upside and growing collateral damage.
Analyst Comments: This is the danger zone for sanctions policy: when measures become habitual responses rather than calibrated tools. The article correctly flags that Beijing is no longer absorbing pressure—it’s responding asymmetrically through mineral export controls, regulatory harassment, and informal trade coercion. As costs rise for allies and firms, the political durability of sanctions weakens. From a security lens, escalation won’t stay economic. When sanctions constrain options, cyber operations become an attractive release valve—deniable, scalable, and targeted at chokepoints like logistics, IP-heavy firms, and energy systems. Without clearer objectives, thresholds, and off-ramps, sanctions risk entrenching rivalry without delivering decisive outcomes.
READ THE STORY: The National Interest
U.S. National Cyber Strategy to Be Built on Six Pillars: Federal Official Signals Shift Toward Long-Term Resilience
Bottom Line Up Front (BLUF): Nick Leiserson, Assistant National Cyber Director for Cyber Policy and Programs, previewed six key focus areas of the upcoming National Cyber Strategy Implementation Plan, emphasizing resilience, accountability, and public-private coordination.
Analyst Comments: The six pillars indicate a move away from whack-a-mole response models and toward embedding resilience, regulation, and real consequences into the ecosystem. Notably, the emphasis on software liability and international norms shows the U.S. is finally confronting the structural incentives that keep digital infrastructure brittle. If these ideas make it from speech to statute, we could see real change in how both federal and private-sector actors are held accountable. But implementation remains the hard part—especially under political pressure and industry resistance.
READ THE STORY: Meritalk
Amaranth Dragon Weaponizes CVE-2025-8088: Chinese APT Exploits New Privilege Escalation Bug in Espionage Campaign
Bottom Line Up Front (BLUF): Checkpoint Research has identified the Chinese APT group Amaranth Dragon actively exploiting CVE-2025-8088, a recently disclosed Windows privilege escalation vulnerability. The zero-day has been used in a targeted espionage campaign against government and telecom sectors in Southeast Asia and the South Pacific, enabling attackers to execute code with SYSTEM-level privileges.
Analyst Comments: Amaranth Dragon has a history of strategic targeting in alignment with Beijing’s geopolitical priorities, and this campaign fits the pattern: quiet privilege escalation used as a pivot for long-term persistence. The speed of weaponization—exploited in the wild before public disclosure—suggests either access to private exploit brokers or internal research capability. Organizations in diplomatic, defense, and telecom sectors should prioritize telemetry review for lateral movement and privilege escalation, especially in hybrid Windows environments.
READ THE STORY: Checkpoint
SolarWinds Web Help Desk Flaw Exposes Customers to RCE Risk: Critical Bug Remains Unpatched
Bottom Line Up Front (BLUF): Researchers have disclosed a critical vulnerability in SolarWinds Web Help Desk (WHD) that could allow unauthenticated remote code execution (RCE). Despite the severity, no patch has been released, and SolarWinds has remained largely silent. The flaw puts numerous IT and support environments at risk, particularly in government, education, and healthcare sectors.
Analyst Comments: Web Help Desk is deeply embedded in IT support workflows, often with privileged backend access, making it a prime pivot point for lateral movement. The lack of immediate vendor response is unacceptable given SolarWinds’ breach history. Expect exploitation in the wild if it’s not already happening. Organizations should consider isolating WHD instances, applying compensating controls (e.g., WAF rules, network segmentation), and preparing for emergency patch deployment or product replacement if SolarWinds doesn’t act soon.
READ THE STORY: InfoSecMag
New Ransomware Gang ‘Full Godfather Cartel’ Emerges: Sophisticated Ops, Familiar Codebase, and Ruthless Tactics
Bottom Line Up Front (BLUF): A newly identified ransomware group calling itself the Full Godfather Cartel (FGC) is making waves with high-impact attacks and sophisticated extortion methods. According to Dark Reading, the gang appears to be a rebrand or offshoot of known ransomware actors, using a mix of custom tooling and recycled code to rapidly compromise enterprise environments, particularly in finance, logistics, and manufacturing.
Analyst Comments: The reuse of elements from Conti and REvil playbooks suggests deep familiarity with successful TTPs, while the group’s communications and leak site branding indicate a calculated focus on psychological pressure. FGC’s ops show signs of initial access via third-party IT vendors, suggesting a supply chain angle. Their pivot to data destruction threats and multi-channel extortion (email, SMS, dark web leaks) reflects the evolving economics of ransomware: fast pressure equals faster payouts. Defenders should prioritize visibility into MSP activity, endpoint privilege abuse, and exfil pathways.
READ THE STORY: DR
Foreign Cyberattacks on the Rise, German Intelligence Warn
Bottom Line Up Front (BLUF): China is intensifying its crackdown on cross-border cyber fraud, targeting scam syndicates operating in Southeast Asia with mass deportations, expanded AI surveillance, and joint law enforcement operations. According to CyberNews, the campaign reflects Beijing’s growing concern over the scale and reputational risk of cybercrime originating from neighboring countries but affecting Chinese citizens.
Analyst Comments: China’s moves here signal a sharp pivot from passive toleration to aggressive suppression of cybercriminal ecosystems that once thrived with tacit approval or indifference. The shift is likely driven by internal political pressure and reputational risk as scams targeting Chinese nationals balloon into a national security concern. From a cyber defense standpoint, Beijing’s use of AI for behavioral profiling and cross-border tracking also foreshadows how state-level cyber policing may evolve—blending surveillance, predictive analytics, and political enforcement. Watch for knock-on effects in regional cybercrime flows as displaced actors pivot to Western targets or deepen operational security.
READ THE STORY: The European Conservative
Operation Midnight Hammer Revealed: U.S. Used Cyber Weapons to Disable Iranian Air Defenses During 2025 Nuclear Strikes
Bottom Line Up Front (BLUF): In a previously undisclosed cyber component of Operation Midnight Hammer, the U.S. military used cyber weapons to digitally disrupt Iranian air defense systems during coordinated strikes on nuclear facilities in June 2025. According to U.S. officials cited by The Record, the operation marks a significant milestone in the normalization of integrated cyber-kinetic operations.
Analyst Comments: The operation leveraged “aim points” such as routers and servers rather than attempting to penetrate fortified nuclear facilities directly. Officials declined to specify the exact systems targeted but noted the complexity of the campaign. Cyber effects were also used in the 2025 Venezuela operation that ousted President Nicolás Maduro, including blackouts and radar disruption. Defense officials now publicly acknowledge that cyber capabilities are being “layered” into global operations as standard practice. Pentagon leaders highlighted a new non-kinetic effects cell tasked with integrating cyber, information, and electronic warfare into mission planning.
READ THE STORY: The Record
DOJ Reveals Jeffrey Epstein Employed DOJ Docs Reveal Epstein Employed Elite Hacker for Operational Security and Digital Counter-Surveillance
Bottom Line Up Front (BLUF): Newly surfaced DOJ documents indicate that Jeffrey Epstein retained the services of a well-known cybersecurity expert during the peak of his criminal enterprise. As reported in a LinkedIn analysis by cybersecurity researcher Pim Eijne, the hacker allegedly helped Epstein build hardened digital infrastructure, scrub metadata, and deploy tools for evading surveillance and detection.
Analyst Comments: The involvement of a top-tier hacker suggests Epstein actively sought to digitally obscure activities, manage communications securely, and potentially monitor associates or adversaries. From a cyber threat perspective, this parallels tactics used in organized crime and state-level tradecraft: data minimization, encryption layering, and digital access control designed to resist law enforcement or media discovery. The fact that such expertise was employed by a private criminal network underscores the blurring line between cybercrime and elite-enabled abuse.
READ THE STORY: LinkedIn (CSH)
China’s Intelligence Community (CIC) Profiled: Overlapping Agencies, Expanding Global Reach, and a Blurred Civil-Military Line
Bottom Line Up Front (BLUF): A new intelligence profile by Grey Dynamics provides a comprehensive breakdown of the Chinese Intelligence Community (CIC), highlighting the structure, objectives, and operational reach of China’s sprawling state security apparatus. The report underscores the strategic fusion of civilian, military, and political intelligence, which supports Beijing’s long-term goals of geopolitical influence, technology acquisition, and regime security.
Analyst Comments: China's approach differs from Western intelligence models by design: overlapping mandates, institutional redundancy, and coordination through Party control rather than formal oversight. The Ministry of State Security (MSS) leads most external operations, blending SIGINT, HUMINT, and cyber capabilities, while the People’s Liberation Army CSF (PLA-CSF) handles military cyber and space-based ISR. Add in United Front-linked influence networks and commercial entities like Huawei or ByteDance, and you’re looking at a multi-vector threat that is difficult to attribute and harder to counter.
READ THE STORY: Grey Dynamics
U.S.–China Economic Decoupling Deepens Around Tech and Minerals: Strategic Competition Shifts From Tariffs to Tech Sovereignty
Bottom Line Up Front (BLUF): The U.S.–China economic relationship is entering a new phase of strategic decoupling, with both countries accelerating moves to sever dependence on each other for critical technologies and minerals, according to The Wall Street Journal. Rather than broad tariffs, both sides are focusing on tech self-sufficiency, export controls, and investment restrictions, reshaping global supply chains and deepening geopolitical fault lines.
Analyst Comments: The U.S. is tightening controls on advanced chip exports and outbound investment in sensitive sectors, while China is responding with mineral export curbs, especially on rare earths and battery metals. This tit-for-tat dynamic has major implications for cybersecurity and national defense: both sides are prioritizing resilient, state-aligned supply chains in sectors like semiconductors, quantum, and AI.
READ THE STORY: WSJ
China Freezes New Deals With Panama After Ports Contract Voided: Strategic Retaliation Targets Trade, Infrastructure, and Shipping
Bottom Line Up Front (BLUF): China is instructing state-owned firms to pause new investments and halt infrastructure negotiations with Panama, following the country's Supreme Court decision to void CK Hutchison’s contract to operate two key Panama Canal ports. According to Bloomberg, Beijing is also tightening customs inspections on Panamanian goods and urging shipping companies to consider rerouting cargo, signaling broader economic retaliation tied to geopolitical influence and control over global maritime chokepoints.
Analyst Comments: Beijing is weaponizing its economic footprint—port investments, customs enforcement, and trade leverage—to punish Panama and deter others from aligning too closely with U.S. efforts to block Chinese influence over strategic infrastructure. The Panama Canal is a global trade artery, and Beijing’s aggressive response reflects its long-term competition with Washington for dominance in critical logistics and chokepoints. The implication for security professionals: this isn’t just about ports. These moves telegraph how China may use commercial leverage in tandem with political pressure and digital influence—including possible cyber or supply chain disruptions—when its overseas strategic interests are threatened. Expect Chinese cyber activity to increase around maritime logistics, arbitration proceedings, and infrastructure sectors in Latin America and other Belt and Road-linked regions.
READ THE STORY: Bloomberg
China Tightens Grip on Latin America: Strategic Investments, Military Ties, and Infrastructure Expansion Challenge U.S. Influence
Bottom Line Up Front (BLUF): A Geopolitical Intelligence Services report details how China has entrenched itself as Latin America's leading trade and infrastructure partner—expanding influence through strategic port ownership, telecom dominance, and military cooperation, while facing new resistance from the U.S. and a regional rightward political shift. Beijing’s dominance of 5G infrastructure, mineral extraction, and trans-Pacific trade routes positions it as a long-term competitor for influence in the Western Hemisphere.
Analyst Comments: Over two decades, China has leveraged soft power, state-backed investment, and commercial proxies to build a quasi-permanent economic footprint across Latin America. From ports in Panama and Peru to Huawei-led 5G rollouts and data centers in Mexico, China is shaping the region’s digital and physical infrastructure—often without firing a shot. The U.S. is responding, but late. Trump’s second-term administration is now actively pressuring regional governments to block Chinese involvement in critical infrastructure, reassert control over the Panama Canal, and roll back tech partnerships. While political momentum is shifting toward U.S.-aligned, right-wing governments, China’s entrenchment—particularly in telecoms and rare earth supply chains—will be difficult to unwind without a sustained, well-funded U.S. counterstrategy.
READ THE STORY: GIS
China’s ‘Big Short’: Billionaire Trader Who Nailed Gold Rally Bets Aggressively Against Silver
Bottom Line Up Front (BLUF): Chinese billionaire trader Bian Ximing, who earned nearly $3 billion betting on gold since 2022, has built the largest net short position in silver on the Shanghai Futures Exchange. As silver prices plunged more than 16% in recent days, his position has generated roughly 2 billion yuan ($288M) in paper gains, underscoring how speculative positioning—not fundamentals—is driving extreme volatility in precious metals markets.
Analyst Comments: Bian Ximing—operating largely through Zhongcai Futures Co.—now holds a short position equivalent to about 450 tons of silver (30,000 contracts) on the Shanghai Futures Exchange. He began ramping up the trade in late January as silver hit record highs in China, steadily increasing exposure despite sharp price swings. Bian previously built a long silver position that earned more than 1.3 billion yuan in profits before flipping bearish in November. After weeks of choppy trading and some losses, he held firm through last week’s rally—only to be rewarded as silver collapsed. Including earlier losses, Bloomberg estimates his net profit near 1 billion yuan, with gains likely increasing as prices continue to fall.
READ THE STORY: Bloomberg
Canada–China Partnership Signals Beijing’s Preference for Quiet, Issue-Specific Engagement Over Formal Alliances
Bottom Line Up Front (BLUF): A new analysis from the Union of Concerned Scientists argues that a recently announced Canada–China cooperation agreement highlights how Beijing prefers pragmatic, narrowly scoped partnerships rather than binding alliances. The approach reflects China’s broader foreign policy trajectory: reduce strategic isolation, manage tensions with Western states, and advance core interests through selective cooperation—particularly on science, technology, and arms control—without altering its fundamental rivalry with the U.S.
Analyst Comments: Beijing isn’t seeking alliances in the Western sense; it’s seeking policy wedges. By engaging Canada on discrete technical issues, China signals openness to cooperation while avoiding concessions on contentious areas like Taiwan, human rights, or industrial policy. For security and cyber watchers, the takeaway isn’t the partnership itself—it’s the model. China increasingly uses scientific and technical cooperation as a diplomatic pressure valve, especially with U.S. allies frustrated by binary “with us or against us” frameworks. These arrangements help Beijing project reasonableness, gather insight into Western policy debates, and maintain access to expertise—even amid strategic competition.
READ THE STORY: UCS
Mustang Panda Targets Foreign Diplomats: Chinese APT Expands Espionage Campaign Using Customized Malware
Bottom Line Up Front (BLUF): China-linked APT group Mustang Panda (aka RedDelta) has been observed conducting a focused cyber-espionage campaign against foreign diplomats and embassies, leveraging spear-phishing emails and tailored malware to steal sensitive communications. According to HackRead, the activity aligns with Beijing’s ongoing efforts to collect diplomatic intelligence tied to geopolitical flashpoints in Asia and Europe.
Analyst Comments: Mustang Panda’s value to Beijing isn’t technical novelty; it’s reliability. The group consistently delivers intelligence on negotiations, policy intent, and alliance dynamics. For defenders in foreign ministries and international organizations, this campaign reinforces a hard truth: diplomatic networks remain among the softest high-value targets, often constrained by legacy systems, multilingual document exchange, and trust-based communications.
READ THE STORY: Hackread
Ukraine Works With Raytheon to Accelerate Patriot Missile Deliveries: Air Defense Becomes Top Strategic Priority
Bottom Line Up Front (BLUF): Ukraine’s Ministry of Defense has formally engaged Raytheon to speed up delivery and sustainment of Patriot air defense systems, aiming to counter Russia’s continued missile and drone strikes. The move reflects Kyiv’s urgent need to close air defense gaps as Russia increases the tempo and complexity of long-range attacks.
Analyst Comments: Patriot systems remain one of the few defenses capable of reliably intercepting ballistic and advanced cruise missiles, and Ukraine’s existing batteries are under constant strain. Direct coordination with Raytheon signals a shift toward industrial-level wartime sustainment, not just one-off donations from allies. From a strategic perspective, faster Patriot delivery also complicates Russia’s campaign calculus. Moscow has relied on saturation attacks to exhaust Ukrainian interceptors; improving delivery timelines, spare parts flow, and maintenance cycles blunts that advantage. Expect Russia to respond asymmetrically—likely through cyber operations targeting defense logistics, suppliers, or contractor networks tied to Western arms manufacturers.
READ THE STORY: United24
Zelenskyy Approves New Defense Plan Structure: Ukraine Formalizes Long-Term Warfighting and Recovery Strategy
Bottom Line Up Front (BLUF): President Volodymyr Zelenskyy has signed a decree approving a new structure for Ukraine’s national defense plan, reorganizing how military, economic, and societal defense efforts are coordinated. Reported by UNN, the move institutionalizes a whole-of-state approach to prolonged conflict, aligning battlefield operations with mobilization, resilience, and post-war recovery planning.
Analyst Comments: This decree signals that Kyiv is planning for endurance, not just survival. By restructuring the defense plan, Ukraine is moving away from ad hoc wartime decision-making toward a formalized, layered defense doctrine that integrates the Armed Forces, government ministries, critical infrastructure operators, and civilian resilience. From a security perspective, this also has cyber implications. A centralized defense architecture typically brings clearer command lines—but also larger digital attack surfaces. Expect Russia to probe coordination systems, logistics platforms, and civil-military interfaces tied to the new structure. Conversely, the decree likely improves Ukraine’s ability to absorb aid, synchronize Western support, and maintain continuity under sustained pressure.
READ THE STORY: UNN
Ukrainian “Vampire” Strike Drone Helps Rescue Two Captured Soldiers Near Huliaipole
Bottom Line Up Front (BLUF): Ukraine’s Vampire heavy strike drone played a decisive role in rescuing two Ukrainian servicemen from Russian captivity near Huliaipole in the Zaporizhzhia region. According to Militarnyi, the drone was used to suppress Russian positions and provide cover, enabling the soldiers to escape and return to Ukrainian lines.
Analyst Comments: Operationally, this underscores a broader shift: drones are now integral to tactical decision-making at the squad and platoon level, not just for reconnaissance or attrition. For Russia, it’s another reminder that even rear-area or ad hoc detention scenarios are vulnerable to rapid drone-enabled counteraction. Expect Russian forces to further prioritize EW and short-range air defenses around small-unit positions—though coverage gaps remain persistent.
READ THE STORY: Military
Russia Refocuses on Drones and Ground Forces: Modernization Aims for Adaptation, Not Transformation
Bottom Line Up Front (BLUF): Russia is reshaping its military around mass drone employment and reinforced ground forces, prioritizing adaptation over doctrinal overhaul. According to Militarnyi, a former deputy head of Ukraine’s Defense Intelligence (DIU) says Moscow is modernizing under battlefield pressure—scaling UAV production, integrating drones at the tactical level, and restructuring units to sustain prolonged ground combat.
Analyst Comments: A former DIU deputy chief stating that Russia is reorganizing its forces to embed drones directly into infantry and artillery units, rather than treating UAVs as separate assets. Moscow is also expanding domestic drone production to reduce reliance on Iranian supplies. The modernization effort includes improved electronic warfare coverage, simplified training pipelines, and adjustments to command structures to shorten decision cycles at the frontline. However, the source notes persistent weaknesses: limited innovation, uneven unit quality, and continued losses from Ukrainian precision strikes.
READ THE STORY: Militarnyi
Items of interest
Russian Hackers Weaponize Office Zero-Day Within Days: Rapid Exploitation Targets European Government Networks
Bottom Line Up Front (BLUF): Russian threat actors exploited a previously unknown Microsoft Office vulnerability within days of its discovery, using it in targeted attacks against European government and policy organizations. According to Dark Reading, the zero-day was rapidly integrated into spearphishing campaigns, bypassing standard defenses and enabling remote code execution (RCE) via malicious documents.
Analyst Comments: Russian APTs—likely groups such as APT28 or Sandworm—have shown a consistent ability to operationalize vulnerabilities almost immediately, especially when targeting diplomatic or defense-related networks. The attack chain appears tailored for precision: minimal indicators, rapid delivery, and selective targeting. For defenders, this underscores the urgent need for Office macro hardening, content disarm and reconstruction (CDR), and fast-track patch deployment pipelines. Expect follow-on payloads involving credential theft, C2 beacons, or even wipers in high-value environments.
READ THE STORY: DR
Chaining Vulnerabilities Like a Pro Bug Bounty Hunter (Video)
FROM THE MEDIA: Whether you're a beginner or an experienced bug hunter, this video will give you valuable insights and techniques to elevate your hacking game. Don't miss out—your next big find could be just one chain away.
Sina Kheirkhah - Unveiling the Ivanti vulnerability: from discovery to exploitation (Video)
FROM THE MEDIA: Unveiling the Ivanti vulnerability: from discovery to exploitation
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


