logo

Chinese hackers hid in US infrastructure network for 5 years

ID: f17627f8-2713-5dc2-aef3-ddaac990aede

STIX ID: report--f17627f8-2713-5dc2-aef3-ddaac990aede

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2024-02-07

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Volt Typhoon, a PRC-linked advanced persistent threat, infiltrated and maintained undetected footholds in multiple U.S. critical infrastructure networks (communications, energy, transportation, water) for at least five years using living-off-the-land techniques, stolen credentials, and a SOHO-router botnet (KV-botnet); U.S. agencies (CISA, NSA, FBI and Five Eyes) warn the group seeks to pre-position access to OT systems for potential disruptive operations and have issued detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.