logo

Chinese 'ORB' Networks Conceal APTs, Render Static IoCs Irrelevant

ID: 82dbe6a4-d858-5109-9659-57d7b5634c10

STIX ID: report--82dbe6a4-d858-5109-9659-57d7b5634c10

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

## Executive summary The report describes how Chinese threat actors have developed large, short-lived Operational Relay Box (ORB) networks—comprised of VPS, compromised routers, and IoT devices—that proxy and rotate traffic at scale to evade attribution; it highlights named ORBs (Florahox, Spacehop), links to APT activity (e.g., APT31, APT5), and urges defenders to move from static IP-based IoCs to behavior- and infrastructure-based detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.