Chinese hackers hid in US infrastructure network for 5 years
ID: f17627f8-2713-5dc2-aef3-ddaac990aede
STIX ID: report--f17627f8-2713-5dc2-aef3-ddaac990aede
Feed Name: Bleeping Computer
Volt Typhoon, a PRC-linked advanced persistent threat, infiltrated and maintained undetected footholds in multiple U.S. critical infrastructure networks (communications, energy, transportation, water) for at least five years using living-off-the-land techniques, stolen credentials, and a SOHO-router botnet (KV-botnet); U.S. agencies (CISA, NSA, FBI and Five Eyes) warn the group seeks to pre-position access to OT systems for potential disruptive operations and have issued detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
