logo

State hackers turn to massive ORB proxy networks to evade detection

ID: 9cc58021-5065-53bf-b8c7-b233288d9fd3

STIX ID: report--9cc58021-5065-53bf-b8c7-b233288d9fd3

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-05-22

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Security researchers (Mandiant) warn that China-linked state-backed hackers increasingly use operational relay box (ORB) proxy meshes—hybrids of leased VPS and compromised devices—to proxy and obfuscate cyberespionage activity. The report describes ORB3/SPACEHOP and ORB2/FLORAHOX, names associated implants and tools (e.g., FLOWERWATER, PETALTOWER, SHIMMERPICK), cites use in exploiting CVE-2022-27518 and other operations tied to APT groups (APT5, APT31), and highlights significant detection, attribution, and enterprise defense challenges posed by these transient, multi-actor infrastructures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.