Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid
ID: 5f7d40b0-ff93-5817-9f3e-0fdaa3f4b61e
STIX ID: report--5f7d40b0-ff93-5817-9f3e-0fdaa3f4b61e
Feed Name: The Register (Security)
The report describes a Chinese state-sponsored intrusion that used a stolen BeyondTrust Remote Support SaaS API key to remotely access some U.S. Treasury workstations and exfiltrate certain unclassified documents, including material from the Office of Foreign Assets Control (OFAC); BeyondTrust patched affected cloud instances and notified impacted customers. The Treasury attributed the breach to a China-backed APT actor and investigators identified DigitalOcean-hosted IP addresses connected to the activity; the article also references other major China-linked incidents such as the Salt Typhoon telecom intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
