logo

Chinese hackers targeting ‘high value’ North American critical infrastructure, Cisco says

ID: fd53be2e-51ee-5727-a5cc-76aee69a0191

STIX ID: report--fd53be2e-51ee-5727-a5cc-76aee69a0191

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2026-01-15

Date Updated: 2026-05-01

...
...

Cisco Talos researchers reported a year-long campaign by Chinese government-backed actors (UAT-8837) that gained access to multiple North American critical infrastructure organizations using compromised credentials and exploitable servers, including active exploitation of a SiteCore zero-day (CVE-2025-53690). The actors used post-exploitation tools such as Earthworm to exfiltrate credentials, map internal endpoints, and create reverse tunnels to attacker-controlled infrastructure, indicating sophisticated capabilities and potential access to zero-day exploits and targeting of operational technology and federal entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.