Chinese State-Sponsored Group Targets Global Networks
ID: cd5405e2-fefd-5ca2-969f-c6e8ecf66865
STIX ID: report--cd5405e2-fefd-5ca2-969f-c6e8ecf66865
Feed Name: Cyble Blog
Chinese state-sponsored APT actors have been conducting large-scale, stealthy cyber espionage against telecommunications providers, ISPs, and critical infrastructure since at least 2021 by exploiting known router and network-device vulnerabilities (e.g., CVE-2024-21887, CVE-2024-3400, CVE-2018-0171) to establish persistent footholds, intercept credentials via embedded packet capture and weak AAA configurations, modify router ACLs and services, and use multi-hop encrypted tunneling and pivoting tools to exfiltrate data and blend C2 traffic with normal operations; international agencies have issued joint advisories and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
