Chinese 'ORB' Networks Conceal APTs, Render Static IoCs Irrelevant
ID: 82dbe6a4-d858-5109-9659-57d7b5634c10
STIX ID: report--82dbe6a4-d858-5109-9659-57d7b5634c10
Feed Name: Dark Reading
Threat Score
## Executive summary The report describes how Chinese threat actors have developed large, short-lived Operational Relay Box (ORB) networks—comprised of VPS, compromised routers, and IoT devices—that proxy and rotate traffic at scale to evade attribution; it highlights named ORBs (Florahox, Spacehop), links to APT activity (e.g., APT31, APT5), and urges defenders to move from static IP-based IoCs to behavior- and infrastructure-based detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
