Chinese Hackers Hijack Auth Flow, Spy on Isolated Network for a Decade
ID: 58972297-75bd-55c1-82f3-a83c004a6b8c
STIX ID: report--58972297-75bd-55c1-82f3-a83c004a6b8c
Feed Name: CosmicBytez Labs
**Chinese state-sponsored attackers owned an organization's authentication infrastructure and maintained undetected access for approximately ten years, gaining universal visibility into credentials and administrative actions; the report details attack phases (initial access, targeting directory/Kerberos/PAM/RADIUS, long-term passive collection), detection approaches (cryptographic integrity checks, out-of-band logging, Kerberos ticket analysis, network auth flow monitoring), and remediation guidance that includes rebuilding directory services, rotating krbtgt keys, and treating all credentials as compromised.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
