Feds: Chinese hacking operations have been in critical infrastructure networks for five years
ID: 0be49769-3242-583b-9c47-115bffbd1d47
STIX ID: report--0be49769-3242-583b-9c47-115bffbd1d47
Feed Name: CyberScoop
Joint U.S. agencies warn that Chinese state-sponsored APT "Volt Typhoon" has maintained long-term access (at least five years) to IT networks of U.S. critical infrastructure, using living-off-the-land techniques, credential harvesting, and vulnerabilities in public-facing routers/VPNs to enable lateral movement toward operational-technology systems; agencies assess the footholds could allow disruption of HVAC, energy, water controls and surveillance, though disruptive actions have not been confirmed. The advisory also notes the disruption of the KV botnet that targeted small/home routers used to gain access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
