logo

U.S. org suffered four month intrusion by Chinese hackers

ID: 6ef06c82-df91-5805-bec2-218613af236d

STIX ID: report--6ef06c82-df91-5805-bec2-218613af236d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-12-05

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Symantec observed China-based threat actors maintain persistent access to multiple machines in a large U.S. organization with a China presence from April to August 2024, using Kerberoasting, living‑off‑the‑land tools (PowerShell, WMI, PsExec), renamed/open-source utilities (FileZilla/Putty components, PSCP), WinRAR, and DLL sideloading to establish persistence, perform reconnaissance, lateral movement, and likely exfiltrate email/data from Exchange servers; some tools overlap with prior Chinese campaigns, but firm attribution remains tentative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.