logo

China-linked Threats to Operational Technology

ID: c4546181-a6ce-5b87-a5fb-3ccc05cc6262

STIX ID: report--c4546181-a6ce-5b87-a5fb-3ccc05cc6262

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2024-03-21

Date Updated: 2026-04-29

...
...

**Executive Summary:** This Threat Spotlight examines four China-nexus APT incidents (Volt Typhoon, APT27, APT31, BlackTech) over the last 12 months that impacted or targeted operational technology and related IT systems, detailing observed TTPs—such as RDP lateral movement, exploitation of public-facing appliances, PowerShell/WMI abuse, firmware/router backdoors, and multi-stage backdoors like ChargeWeapon—and offering prioritized detection and mitigation guidance while warning that Chinese APTs will likely continue focusing on OT for espionage and potential disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.