Chinese Hackers Operate Undetected in U.S. Critical Infrastructure for Half a Decade
ID: e08ba43c-1477-5f43-b245-65ecbdb181e6
STIX ID: report--e08ba43c-1477-5f43-b245-65ecbdb181e6
Feed Name: The Hacker News
U.S. agencies (CISA, NSA, FBI) and Five Eyes partners say the China-linked APT known as Volt Typhoon has maintained long-term, stealthy access in IT networks of U.S. and Guam critical infrastructure since at least 2021, using living-off-the-land tools, credential theft, targeted log deletion, and multi-hop proxy routing to pre-position for potential disruptive operations against OT environments; the advisory also notes a separate influence operation (PAPERWALL) tied to pro-Beijing content sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
