logo

Chinese APT40 hackers hijack SOHO routers to launch attacks

ID: 382c1d64-d299-572d-80bb-19d66c81f9d9

STIX ID: report--382c1d64-d299-572d-80bb-19d66c81f9d9

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-07-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A joint advisory from multiple international cybersecurity agencies details APT40 (Kryptonite Panda)'s cyber-espionage operations: rapid exploitation of disclosed vulnerabilities (e.g., Log4J, Confluence, ProxyLogon), hijacking end-of-life SOHO routers to proxy malicious traffic, deploying web shells for persistence, harvesting credentials via Kerberoasting, conducting RDP lateral movement and SMB exfiltration to C2 servers; the report includes two 2022 case studies and prescribes mitigations such as timely patching, network segmentation, MFA, disabling unused services, and replacing EoL networking gear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.