logo

Chinese Hackers Operate Undetected in U.S. Critical Infrastructure for Half a Decade

ID: e08ba43c-1477-5f43-b245-65ecbdb181e6

STIX ID: report--e08ba43c-1477-5f43-b245-65ecbdb181e6

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

U.S. agencies (CISA, NSA, FBI) and Five Eyes partners say the China-linked APT known as Volt Typhoon has maintained long-term, stealthy access in IT networks of U.S. and Guam critical infrastructure since at least 2021, using living-off-the-land tools, credential theft, targeted log deletion, and multi-hop proxy routing to pre-position for potential disruptive operations against OT environments; the advisory also notes a separate influence operation (PAPERWALL) tied to pro-Beijing content sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.