logo

CISA Alert AA25-239A: Analysis, Simulation, and Mitigation of Chinese APTs

ID: 139c083a-c151-582c-9455-db025a11eed7

STIX ID: report--139c083a-c151-582c-9455-db025a11eed7

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-08-28

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

On August 27, 2025, CISA with NSA, FBI and international partners published a joint advisory attributing persistent global espionage campaigns since 2021 to Chinese state-sponsored APTs (Salt Typhoon / OPERATOR PANDA / RedMike / UNC5807 / GhostEmperor) that compromise routers and other network-edge devices by exploiting known CVEs, altering configurations (ACLs, TACACS+/SNMP), abusing SSH/Guest Shell, and tunneling (GRE/IPsec) to capture credentials, mirror traffic, and exfiltrate sensitive communications; the advisory lists high-priority CVEs, maps observed behaviors to MITRE ATT&CK, identifies impacted sectors (telecom, government, transportation, lodging, military), and provides defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.