Microsoft says Chinese state-sponsored hackers compromised “critical infrastructure organizations” across US industries, with a focus on gathering intelligence
- Chinese state-sponsored hackers have compromised “critical” cyber infrastructure in a variety of industries …
CNBC Rohan Goswami
Related Coverage
- People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection Joint Cybersecurity Advisory
- Volt Typhoon targets US critical infrastructure with living-off-the-land techniques Microsoft Security Blog
- Chinese Malware Hits Systems on Guam. Is Taiwan the Real Target? New York Times · David E. Sanger
- China Hacks US Critical Networks in Guam, Raising Cyberwar Fears Wired
- NSA and Partners Identify China State-Sponsored Cyber Actor Using Built-in Network Tools When Targeting U.S. Critical Infrastructure Sectors Central Security Service · National Security Agency
- China rejects claim it is spying on Western critical infrastructure Reuters · Raphael Satter
- China hits back over Five Eyes blame for US infrastructure cyber attack ABC · Toby Mann
- Microsoft: Chinese hackers hit key US bases on Guam BBC · Hannah Ritchie
- Chinese state hackers infect critical infrastructure throughout the US and Guam Ars Technica · Dan Goodin
- Microsoft links attacks on American critical infrastructure systems to China CSO · Shweta Sharma
- Chinese hackers hit critical U.S. infrastructure, intelligence agencies warn Axios · Rebecca Falconer
- U.S. and International Partners Release Advisory Warning of PRC State-Sponsored Cyber Activity Cybersecurity and Infrastructure Security Agency CISA
- China hits back after Microsoft says state-sponsored group hacked critical US infrastructure Financial Times · Tabby Kinder
- Chinese hackers breach US critical infrastructure in stealthy attacks BleepingComputer · Sergiu Gatlan
- Microsoft and global intelligence agencies warn of Chinese state hackers infecting US critical infrastructure TechSpot · Rob Thubron
- China's Stealthy Hackers Infiltrate U.S. and Guam Critical Infrastructure Undetected The Hacker News
- Beware, Volt Typhoon: Chinese hackers pose clear, present danger to US, says Microsoft WRAL TechWire
- US, Microsoft Warn Chinese Hackers Attacking ‘Critical’ Infrastructure Agence France-Presse
- Microsoft says Chinese state-sponsored hackers penetrate critical U.S. infrastructure gHacks Technology News · Emre Çitak
- Five Eyes and Microsoft accuse China of attacking US infrastructure again The Register · Simon Sharwood
- Chinese hackers targeting critical U.S. infrastructure, Microsoft warns Digital Trends · Trevor Mogg
- China-backed hackers spying on US critical infrastructure, says Five Eyes The Guardian
- Chinese state-backed hacking group compromised US critical infrastructure orgs The Record · James Reddick
- Microsoft warns alleged Chinese hacking group is targeting critical infrastructure SiliconANGLE · Duncan Riley
- Volt Typhoon attacks attributed to China iTnews · Richard Chirgwin
- Chinese State Hacker ‘Volt Typhoon’ Targets Guam and US GovInfoSecurity.com · David Perera
- Microsoft says state-sponsored China actor targeting critical infrastructure in the US Neowin · Paul Hill
- Chinese-linked hackers target critical infrastructure in US and Guam CyberScoop · Christian Vasquez
- Stealth Cyberattacks by China's Volt Typhoon Threaten U.S. Infrastructure: Microsoft Unmasks Espionage Campaign CircleID
- Around the time that the Federal Bureau of Investigation was examining the equipment recovered from the wreckage of the Chinese spy balloon shot … Richard Staynings
- 📣 As professionals in the ever-evolving field of cybersecurity, it is our duty to stay ahead of the curve and protect our organizations from emerging threats. … Mike Slavick
- Fantastic work by the team exposing Volt Typhoon, a Chinese state-sponsored actor, uses living-off-the-land (LotL) and hands-on-keyboard TTPs … Jeremy Dallman
Discussion
-
@nsa_csdirector
Rob Joyce
on x
PRC cyber threats to critical infrastructure are real and use sophisticated tradecraft that doesn't always rely on malware. This advisory describes tradecraft for hunting their intrusions and detecting this activity. We want to hear about discoveries. https://media.defense.gov/..…
-
@ericgeller
Eric Geller
on x
CISA, NSA, FBI, and their Five Eyes partners have released an advisory about this activity, which they say could be occurring outside the U.S. as well. https://www.cisa.gov/... [image]
-
@arekfurt
@arekfurt
on x
It's important to really understand the implications of the fact that threat actors of many types are now regularly using legitimate remote access capabilities—both those built-in to OSes and from third party apps—to maintain persistent remote access into targets.
-
@markmackinnon
Mark MacKinnon
on x
“It was the focus on Guam that particularly seized the attention of officials who are assessing China's capabilities — and its willingness — to attack or choke off Taiwan.” https://www.nytimes.com/...
-
@julianku
Julian Ku
on x
“American intelligence agencies and Microsoft detected what they feared was a more worrisome intruder: mysterious computer code appearing in telecommunications systems in Guam and elsewhere in the United States."" https://www.nytimes.com/...
-
@argevise
Martial Gervaise
on x
The National Security Agency NSA has released a Cybersecurity Advisory with additional information and hunting guide for Volt Typhoon TTPs: https://www.nsa.gov/... https://twitter.com/... Microsoft customers can get ongoing analysis and access additional threat actor details. [i…
-
@ericgeller
Eric Geller
on x
Microsoft has spotted Chinese government hackers breaching “critical infrastructure organizations in Guam and elsewhere in the United States.” The hackers “live off the land” once they're inside, “rarely” using malware to achieve their goals. https://www.microsoft.com/... [image]
-
@kimzetter
Kim Zetter
on x
“NSA's report is part of a relatively new US...move to publish such data quickly in hopes of burning the Chinese operations. In years past, the US usually withheld such info...that almost always assured that the hackers could stay well ahead of the gov” https://www.nytimes.com/..…
-
@cyb3rops
Florian Roth
on x
This TA is noisy AF .. if your EDR didn't detect and report this with level “high” or “critical” it's bloody useless https://twitter.com/... [image]
-
@msftsecintel
@msftsecintel
on x
Volt Typhoon, a Chinese state-sponsored actor, uses living-off-the-land (LotL) and hands-on-keyboard TTPs to evade detection and persist in an espionage campaign targeting critical infrastructure organizations in Guam and the rest of the United States. https://aka.ms/...
-
@cisacyber
@cisacyber
on x
🚨@CISAgov, @FBI, @NSACyber & international partners published a joint #cybersecurity advisory highlighting a PRC cyber actor living off the land using built-in network admin tools to evade detection & conduct malicious activity. More: https://cisa.gov/... [image]
-
@malwarejake
Jake Williams
on x
Fantastic release from @CISACyber, @NSAGov, and many others highlighting use of living off the land techniques employed by Chinese threat actors. Your EDRs won't save you from LOLBin use, you'll usually need to write custom rules to get that coverage. https://media.defense.gov/..…
-
@nsacyber
@nsacyber
on x
Don't let a malicious actor take advantage of you. Learn how to hunt and mitigate a PRC state-sponsored cyber actor who may be using your systems' resources to hide their activities. https://www.nsa.gov/... [image]
-
@424f424f
@424f424f
on x
ZOMG, look at all these open source tools this State-sponsored threat actor is using. Oh wait, they can operate without them? Who knew.. https://www.cisa.gov/...