How Typhoon APTs Infiltrate Infrastructure Without Leaving a Trace by Lucie Cardiet
ID: a44e2537-b63b-52a9-a11f-bbf22f37baee
STIX ID: report--a44e2537-b63b-52a9-a11f-bbf22f37baee
Feed Name: Vectra AI Blog
The report profiles three Chinese state-linked APT clusters (Volt, Flax, Salt Typhoon) that carry out covert, long-duration intrusions against telecom, utilities, government, and ISP backbones worldwide. Rather than deploying obvious malware, they rely on living-off-the-land techniques, compromised routers, legitimate VPNs, and in some cases kernel-level implants to maintain persistence, conduct surveillance, and pre-position for disruption — forcing defenders to prioritize behavior-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
