Chinese hackers abuse geo-mapping tool for year-long persistence
ID: 3281307f-7c29-599a-8918-be3a7120d337
STIX ID: report--3281307f-7c29-599a-8918-be3a7120d337
Feed Name: Bleeping Computer
Threat Score
**Chinese APT abused ArcGIS SOE for year-long stealthy access**: Researchers attribute a long-term intrusion to Flax Typhoon where attackers uploaded a malicious Java SOE to a public ArcGIS server to act as a REST-based web shell, then installed SoftEther VPN Bridge (calling back to 172.86.113.142) to persist, move laterally, dump credentials (SAM, LSA) and access internal systems—impacting municipalities, utilities and critical infrastructure operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
