Security researchers at Proofpoint spotted a cyber espionage campaign conducted by a group previously linked to China. The hackers have been using a recently patched.NET vulnerability, tracked as CVE-2017-8759, in attacks aimed at organizations in the United States. The attackers have been active since at least 2014, they are known for the use of a remote access trojan (RAT) named NanHaiShu. The threat actors targeted various U.S. and Western European organizations with ties to the maritime sector.”]
Source: http://securityaffairs.co/wordpress/64499/hacking/china-cyber-espionage-group.html