Treasury workstations hacked by China-linked threat actors
ID: a3a691d2-2eb5-533e-9d55-dfdc69969507
STIX ID: report--a3a691d2-2eb5-533e-9d55-dfdc69969507
Feed Name: CyberScoop
The U.S. Department of the Treasury disclosed that several workstations were accessed after a threat actor gained a stolen vendor key for BeyondTrust’s cloud remote-support service; the actor was able to override security, remotely access certain Treasury user workstations, and view some unclassified documents. The vendor detected anomalous activity in early December, patched identified instances by Dec. 16, and the incident—attributed to a China state-sponsored APT—is being investigated by CISA, the FBI, intelligence partners, and third-party forensics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
