What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Familiar targets are being reached through unfamiliar delivery methods. Microsoft’s 2024 account describes Chinese-linked influence and cyber operations alongside North Korean espionage and cryptocurrency campaigns. The examples are not evidence that “Asian threat actors” form one group: they involve different state-linked actors, objectives and regions. Separate regional data from INTERPOL shows that cybercrime affecting Asia and the South Pacific is also broadening, with phishing, ransomware, DDoS and deepfake-enabled fraud all increasing in measured categories.

What the reported activity actually covers

The May 16, 2024 Microsoft Security partner article, republished by Dark Reading, describes observations beginning in June 2023. Its two main threads are distinct:

  • Chinese-linked activity: cyber targeting of South Pacific island entities, regional adversaries in the South China Sea and the US defense industrial base, plus influence campaigns using localized or AI-generated material.
  • North Korean activity: cryptocurrency theft, intelligence collection and software-supply-chain intrusions aimed at revenue and access.

These state-linked examples should not be treated as a survey of all cybercrime in Asia. INTERPOL’s later regional assessment covers a much wider population of criminal incidents and law-enforcement reporting.

How Chinese-linked operators adapted familiar influence tactics

AI-assisted narratives and localization

Microsoft said influence operators experimented with new media and improved AI-generated or AI-enhanced content to intensify divisions in the United States and tensions in the Asia-Pacific region. One cited example involved conspiracy claims about the 2023 Maui fires, accompanied by AI-generated imagery and posts in at least 31 languages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Tapo 1080P Indoor Security Camera, Baby Monitor, Dog Camera, Wired, C100
  • ENDLESS POWER FROM SOLAR ENERGY: Just 45 minutes of direct sunlight powers the camera for a full day of use, while the built-in battery lasts up to 180 days on a single charge during cloudy days. Solar charging requires temperatures above 32°F.△
  • EASY WIRE-FREE INSTALLATION: Place the Tapo SolarCam C402 KIT where you need it without relying on nearby outlets. Install the camera and solar panel together or separately using the included 13 ft cable for flexible placement.
  • PRIORITIZE WHAT MATTERS: Set activity zones to monitor specific areas for motion or people. Free person and motion detection helps reduce unwanted alerts and notifies you when activity is detected.
  • VERSATILE VIDEO STORAGE: Store footage locally via a microSD card (up to 512GB)* or via cloud with a Tapo Care cloud subscription. Tailor your security to suit your needs, whether indoor or outdoor, you have the storage option you need.
  • FULL-COLOR 1080P, DAY AND NIGHT: See clearly in low light with a large-aperture lens and built-in spotlights. Capture full-color night vision up to 30 ft away to monitor for possible intruders or motion.

The important change is not that AI creates an entirely new objective. The objective—shaping political perceptions—remains familiar. Generative tools make it easier to produce variants, translate messages and tailor them to local audiences, potentially reducing the cost and time required to operate across many channels.

Storm-1376’s reported scale

Microsoft described Storm-1376 as a prolific user of AI-generated content and said its campaigns extended across more than 175 websites and 58 languages. Those figures are Microsoft’s characterization of the campaigns reported in 2024, not an independently verified current count. The article’s expectation that China would continue creating and amplifying AI-generated content was a forecast made before the 2024 US election; it should not be read as a present-day prediction.

Rank #2
Sale
JINSWY 10.1" Security Monitor, 1024x600 HD Display Small HDMI Monitor
  • Enhanced Visual Experience: Immerse yourself in clear and vibrant visuals with the JINSWY 10.1-inch mini monitor. Featuring a 1024×600 resolution, 16:9 aspect ratio, 300 cd/m² brightness, and a 500:1 contrast ratio, it delivers sharp images and balanced colors for everyday viewing. Designed for practical display performance, it offers reliable clarity for work, monitoring, and entertainment.
  • Versatile Video Inputs: Equipped with HDMI, VGA, BNC, AV, and USB ports, this small HDMI monitor is compatible with Raspberry Pi, DSLR cameras, PCs, DVDs, TV boxes, Xbox, Nintendo Switch, CCTV systems, car backup cameras, video switchers, FPV setups, and more. Easily turn it into a mini TV by connecting it to a TV box. Perfect for use as a security camera monitor or as part of a small computer monitor setup.
  • Portable & Durable Design: JINSWY mini monitor features a slim, lightweight profile with a durable plastic shell, built to withstand everyday use. Measuring 9.92 × 6.5 × 1.34 inches, it is compact enough for mobile, embedded, or space-limited environments — ideal for applications ranging from backup cameras to security systems, and more. This VGA monitor is designed for long-lasting performance across various setups.
  • Flexible Installation Options: Mount the portable small computer monitor on the wall using a standard VESA 75 mount (not included) or set it up on a desk with the included adjustable stand. The included remote controller allows for easy operation within a range of 10 meters, adding convenience and flexibility to your setup.
  • Wide Range of Applications: Suitable for various uses including home security systems, vehicle displays, Raspberry Pi projects, office multitasking, and entertainment setups. Whether used as a mini monitor, small HDMI monitor, security camera monitor, or VGA monitor, it adapts seamlessly to different environments and needs.

How North Korean operations turn trust into access

Microsoft linked North Korean operations in 2023 to cryptocurrency theft, intelligence collection involving the United States, South Korea and Japan, and revenue generation that supports the government’s weapons program. The named cases show several different routes into organizations that otherwise rely on ordinary business workflows.

Sapphire Sleet: fake meetings and recruiting

Microsoft said Sapphire Sleet used fake virtual-meeting invitations, attacker-controlled domains and fraudulent recruiting sites. Targets reportedly included executives and developers at cryptocurrency, venture-capital and other financial organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
ZOSHING 17inch Security Monitor,Wall-Mounted Monitors Supports USB/Full Format Video Playback,CCTV Monitors with AV/HDMI Input/VGA/Headphone Output,Built-in Speaker, Remote Control
  • 17inch LED Security Monitor, Ultra fine pixel pitch for close viewing in surveillance applications,170 °viewing angle for fewer restrictions on your range of vision
  • CCTV monitor:With multiple ports: HDMI, AV, 3.5mm Audio Input/Output and VGA. perfect for connecting with CCTV monitor and DVR system. Also works for PC, DVD Box and MP5 etc..
  • Functions: This security monitor screen comes with 2 built-in speakers. With built-in USB port media player. It can play movies or videos simply by USB disk. Great for Home/Office/Store Surveillance Camera STB, DVR, NVR, PC, DVD Player.
  • Package Included & Best Service: 17inch CCTV security monitor x1,Power Adaptor x 1, Remote Control x 1,Manual x 1. DOA or within 30 days free money back, or unconditional replacement within 1 Year. Should you have any problem please feel free to contact us, we always stand behind the products.
  • monitor for security cameras

A meeting or job approach is persuasive because it matches a legitimate reason for opening a link, sharing information or installing software. Technical controls therefore need to be paired with verification procedures: confirm the sender through an independent channel, inspect the destination domain and avoid downloading interview or meeting software from an unsolicited message.

Jade Sleet: malicious GitHub collaboration

Microsoft said Jade Sleet operators impersonated developers or recruiters, invited targets to collaborate on GitHub repositories and persuaded them to clone and execute the contents. The repositories contained malicious npm packages.

Rank #4
Jexiop 16inch Security Monitor,Wall-Mounted Monitors Supports USB/Full Format Video Playback,CCTV Monitors with AV/HDMI Input/VGA/BNC,Built-in Speaker,Remote Control
  • 16inch LED Security Monitor, Ultra fine pixel pitch for close viewing in surveillance applications,170 °viewing angle for fewer restrictions on your range of vision
  • CCTV monitor:With multiple ports: HDMI, AV, 3.5mm Audio Input/Output and VGA. perfect for connecting with CCTV monitor and DVR system. Also works for PC, DVD Box and MP5 etc..
  • Functions: This security monitor screen comes with 2 built-in speakers. With built-in USB port media player. It can play movies or videos simply by USB disk. Great for Home/Office/Store Surveillance Camera STB, DVR, NVR, PC, DVD Player.
  • Package Included & Best Service: 15.6inch CCTV security monitor x1,Power Adaptor x 1, Remote Control x 1,Manual x 1. DOA or within 30 days free money back, or unconditional replacement within 1 Year. Should you have any problem please feel free to contact us, we always stand behind the products.
  • monitor for security cameras

This route exploits developer trust and the normal use of package managers. A compromise at an IT provider can also create downstream access to its customers, making software provenance and build controls as important as email filtering. Teams should review unfamiliar repositories, pin and audit dependencies, run untrusted code in isolated environments and require review before package installation in production workflows.

Onyx Sleet: exploiting TeamCity

Microsoft associated Onyx Sleet with exploitation of TeamCity vulnerability CVE-2023-42793 for remote code execution and administrative control, and linked the actor to supply-chain attacks affecting at least 10 victims. These are claims in the 2024 article. Administrators should use current JetBrains and national vulnerability advisories for patching and exposure guidance rather than relying on this summary for remediation details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Chinese influence and North Korean intrusion compared

Dimension Chinese-linked activity North Korean activity
Primary objective Influence, narrative shaping and selected cyber-espionage targets Revenue generation, intelligence collection and downstream access
Reported targets Political audiences, South Pacific entities, South China Sea adversaries and the US defense industrial base Cryptocurrency and financial organizations, developers, IT providers and organizations running exposed servers
Initial routes Localized AI-generated or AI-enhanced posts, images and websites Fake meetings or jobs, malicious repositories and exploitation of a known server vulnerability
Evidence window Microsoft observations described from June 2023, including 2023 activity Microsoft examples of 2023 operations
What cannot be inferred Reported website and language counts are not a current independent census These cases do not represent every North Korean operation or all regional cybercrime
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the broader regional data shows

INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment covers January 2024 through March 2025. It draws on information from 18 member countries, private-sector contributions, operational case studies and threat analysis. Its scope is regional cybercrime and law-enforcement readiness, not a direct remeasurement of Storm-1376, Sapphire Sleet, Jade Sleet or Onyx Sleet.

Reported indicators

  • More than 135,000 ransomware-related attacks were reported in the region in 2024.
  • DDoS attacks rose 92 percent in 2024 compared with 2023.
  • Discussions of deepfakes on selected cybercriminal forums and Telegram channels popular among Southeast Asian threat actors rose 600 percent from February to June 2024. This measures discussion volume, not confirmed deepfake incidents.
  • Surveyed countries reported that cybercrime represented 30 percent of all nationally recorded crime in more than half of cases; 33 percent reported more than 10,000 cyber-scam cases.
  • INTERPOL reported that 5.5 people per 1,000 in the region clicked phishing links monthly, approximately twice the global average.
  • System intrusions accounted for approximately 80 percent of 2024 data breaches, with malware present in 83 percent and ransomware in 51 percent of cases.
  • More than 6.5 billion cyber threats were detected and mitigated in 2024 according to TrendAI data supplied to INTERPOL. This is a detection and mitigation count, not a count of unique attacks or victims.

These figures use different populations, sources and denominators. They should not be combined into a single regional risk rate, and they do not establish that every incident was conducted by a state-linked group.

What organizations should change first

Protect cloud and internet-facing systems

  • Inventory cloud applications, exposed servers, CI/CD systems and third-party connections.
  • Patch internet-facing products according to current vendor advisories, prioritizing remote-code-execution and administrative-control flaws.
  • Use phishing-resistant multifactor authentication for privileged and developer accounts where available.
  • Separate build, package-publishing and production privileges; log unusual repository cloning, package installation and administrative activity.

Make trusted workflows harder to abuse

  • Verify recruiting, meeting and investment approaches through a known contact method.
  • Require code review and provenance checks for unfamiliar GitHub repositories and npm packages.
  • Run downloaded scripts and interview tasks in disposable, isolated environments.
  • Train staff with realistic, role-specific exercises rather than relying only on annual awareness modules.

Prepare for influence and impersonation

  • Give communications teams a process for authenticating urgent executive, supplier and public-facing messages.
  • Preserve suspicious posts, domains, images and account details so investigators can compare variants.
  • Coordinate cyber, legal, communications and leadership teams before responding publicly to suspected manipulation.

Improve response and information sharing

INTERPOL recommends stronger cloud security, public education, incident-response capability, real-time intelligence sharing and cooperation among law enforcement, government, industry and civil society. It also identifies shortages in specialized forensic tools, targeted training and technical capacity, with uneven cybersecurity maturity across the region. Neal Jetton, INTERPOL’s Cybercrime Director, summarized the need for “strengthening operational cooperation, information sharing and cyber resilience” as digital adoption accelerates.

What newer reporting adds—and what it does not prove

Trellix’s April 2026 report, based primarily on data from October 1, 2025 through March 31, 2026, described APT36/Transparent Tribe using AI code generation to produce implants in Nim, Zig, Crystal, Rust and Go, while using legitimate cloud services for communications. It also described a Vietnamese actor generating PureRAT scripts in January 2026. These are Trellix observations from a defined reporting window; Trellix cautions that no organization sees every internet-connected system or every unreported incident. They indicate continued experimentation with AI and trusted services, not a universal trend or proof that the older Microsoft attributions apply to every later campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limits when interpreting the headline

The Dark Reading article is a Microsoft-authored partner perspective, not an independent survey. Actor names, campaign descriptions, victim counts and forecasts should be attributed to Microsoft. INTERPOL’s release combines survey responses and partner data, while Trellix’s report is vendor telemetry with stated visibility limits. None of these sources documents controlled testing or proves that a particular consumer or enterprise product will stop the described activity.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.