Chinese-linked hacking units increasingly use ‘ORBs’ to obfuscate espionage, researchers say
ID: 5c548f83-eee4-5cc2-ab19-c437ced7f084
STIX ID: report--5c548f83-eee4-5cc2-ab19-c437ced7f084
Feed Name: CyberScoop
Mandiant warns that Chinese-linked actors increasingly use operational relay box networks (ORBs) — distributed clusters of compromised small/home routers and leased virtual private servers — to conceal espionage and reconnaissance activity. These ORBs, often operated by contractors and shared across campaigns (for example, Spacehop and activity tied to Volt Typhoon), maintain large, geographically distributed pools of short-lived IPs that cycle frequently (tens to hundreds of thousands of IPs with 60–90 day turnover), making IOC-based detection ineffective and requiring behavior-based profiling and tracking of the ORBs themselves.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
