logo

Chinese hackers abuse geo-mapping tool for year-long persistence

ID: 3281307f-7c29-599a-8918-be3a7120d337

STIX ID: report--3281307f-7c29-599a-8918-be3a7120d337

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Chinese APT abused ArcGIS SOE for year-long stealthy access**: Researchers attribute a long-term intrusion to Flax Typhoon where attackers uploaded a malicious Java SOE to a public ArcGIS server to act as a REST-based web shell, then installed SoftEther VPN Bridge (calling back to 172.86.113.142) to persist, move laterally, dump credentials (SAM, LSA) and access internal systems—impacting municipalities, utilities and critical infrastructure operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.