Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says
ID: fd53be2e-51ee-5727-a5cc-76aee69a0191
STIX ID: report--fd53be2e-51ee-5727-a5cc-76aee69a0191
Feed Name: The Record from Recorded Future News
Cisco Talos researchers reported a year-long campaign by Chinese government-backed actors (UAT-8837) that gained access to multiple North American critical infrastructure organizations using compromised credentials and exploitable servers, including active exploitation of a SiteCore zero-day (CVE-2025-53690). The actors used post-exploitation tools such as Earthworm to exfiltrate credentials, map internal endpoints, and create reverse tunnels to attacker-controlled infrastructure, indicating sophisticated capabilities and potential access to zero-day exploits and targeting of operational technology and federal entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
