logo

Chinese spies spent months inside aerospace engineering firm's network via legacy IT

ID: 3c9ab3ca-874e-536a-8a77-2c339cf1b9b0

STIX ID: report--3c9ab3ca-874e-536a-8a77-2c339cf1b9b0

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-09-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A Chinese state-sponsored APT gained access to a US-headquartered engineering manufacturer's network by exploiting an exposed IBM AIX server running an Apache Axis admin portal with default credentials. Operators installed an AxisInvoker web shell, harvested Kerberos data and added SSH keys for persistence, then expanded into the Windows environment using NTLM relay, Cobalt Strike, and a fast-reverse proxy to enumerate and attempt credential theft; the intrusion persisted for roughly four months before detection and removal, raising significant supply-chain and intellectual-property theft concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.