logo

Chinese-linked hacking units increasingly use ‘ORBs’ to obfuscate espionage, researchers say

ID: 5c548f83-eee4-5cc2-ab19-c437ced7f084

STIX ID: report--5c548f83-eee4-5cc2-ab19-c437ced7f084

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-05-22

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Mandiant warns that Chinese-linked actors increasingly use operational relay box networks (ORBs) — distributed clusters of compromised small/home routers and leased virtual private servers — to conceal espionage and reconnaissance activity. These ORBs, often operated by contractors and shared across campaigns (for example, Spacehop and activity tied to Volt Typhoon), maintain large, geographically distributed pools of short-lived IPs that cycle frequently (tens to hundreds of thousands of IPs with 60–90 day turnover), making IOC-based detection ineffective and requiring behavior-based profiling and tracking of the ORBs themselves.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.