logo

Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid

ID: 5f7d40b0-ff93-5817-9f3e-0fdaa3f4b61e

STIX ID: report--5f7d40b0-ff93-5817-9f3e-0fdaa3f4b61e

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-01-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

The report describes a Chinese state-sponsored intrusion that used a stolen BeyondTrust Remote Support SaaS API key to remotely access some U.S. Treasury workstations and exfiltrate certain unclassified documents, including material from the Office of Foreign Assets Control (OFAC); BeyondTrust patched affected cloud instances and notified impacted customers. The Treasury attributed the breach to a China-backed APT actor and investigators identified DigitalOcean-hosted IP addresses connected to the activity; the article also references other major China-linked incidents such as the Salt Typhoon telecom intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.