China-linked Threats to Operational Technology
ID: c4546181-a6ce-5b87-a5fb-3ccc05cc6262
STIX ID: report--c4546181-a6ce-5b87-a5fb-3ccc05cc6262
Feed Name: ReliaQuest Blog
**Executive Summary:** This Threat Spotlight examines four China-nexus APT incidents (Volt Typhoon, APT27, APT31, BlackTech) over the last 12 months that impacted or targeted operational technology and related IT systems, detailing observed TTPs—such as RDP lateral movement, exploitation of public-facing appliances, PowerShell/WMI abuse, firmware/router backdoors, and multi-stage backdoors like ChargeWeapon—and offering prioritized detection and mitigation guidance while warning that Chinese APTs will likely continue focusing on OT for espionage and potential disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
