logo

The Data Chase: Understanding Chinese Espionage Strategies

ID: b557e631-6fa1-5907-aa19-96aa3470c563

STIX ID: report--b557e631-6fa1-5907-aa19-96aa3470c563

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2025-04-23

Date Updated: 2026-04-29

...
...

ReliaQuest investigated a February 2025 intrusion likely conducted by a China-linked APT against a US defense-technology customer; attackers exploited SharePoint and Ivanti vulnerabilities and brute-forced service accounts to move laterally to SFTP and domain controllers, deployed web shells and custom DLLs for persistence, used in-memory execution and log wiping to evade detection, and re-compromised the network after removal. The report provides technical TTPs, IOCs, attribution rationale, and mitigation guidance (log forwarding, segmentation, MFA, and GreyMatter automated playbooks) to defend against similar espionage-driven campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.