logo

Chinese Hackers Hijack Auth Flow, Spy on Isolated Network for a Decade

ID: 58972297-75bd-55c1-82f3-a83c004a6b8c

STIX ID: report--58972297-75bd-55c1-82f3-a83c004a6b8c

Feed Name: CosmicBytez Labs

Threat Score
95/100

Date Published: 2026-06-13

Date Updated: 2026-06-14

...
...

**Chinese state-sponsored attackers owned an organization's authentication infrastructure and maintained undetected access for approximately ten years, gaining universal visibility into credentials and administrative actions; the report details attack phases (initial access, targeting directory/Kerberos/PAM/RADIUS, long-term passive collection), detection approaches (cryptographic integrity checks, out-of-band logging, Kerberos ticket analysis, network auth flow monitoring), and remediation guidance that includes rebuilding directory services, rotating krbtgt keys, and treating all credentials as compromised.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.