Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - CISA, NSA, and FBI Warn of Ongoing Chinese State-Sponsored Cyber Espionage
Attacks Critical Infrastructure Security News & Analysis Security

CISA, NSA, and FBI Warn of Ongoing Chinese State-Sponsored Cyber Espionage

Kirsten DoyleBy Kirsten DoyleAugust 29, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Chinese sponsored Cyber Espionage
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, and more than a dozen international partners, has issued a joint advisory on Chinese state-sponsored cyber activity.  

The alert, AA25-239A, details the long-running operations of Advanced Persistent Threat (APT) actors tracked as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor. 

These actors have been compromising networks worldwide since at least 2021. They target telecoms, government, transportation, lodging, and military infrastructure. Their campaigns rely on exploiting network edge devices (routers and gateways) to gain persistent access, pivot into trusted networks, and monitor global communications. 

Unlike opportunistic ransomware attacks, these intrusions are calculated and long-term. They are espionage campaigns, designed to track movements, intercept data, and map trusted interconnections across industries and borders. 

Abusing Network Edge Devices 

According to an analysis by Picus Security, “Their campaigns center on abusing network edge devices, particularly backbone and customer routers, to gain persistent access, pivot into trusted networks, and collect sensitive communications. Unlike opportunistic ransomware operations, these intrusions are long-term espionage campaigns, enabling Chinese intelligence services to track global communications and movements.” 

CISA names a few companies: Sichuan Juxinhe and Beijing Huanyu Tianqiong. Sichuan Zhixin Ruijie. They supply the tools and the infrastructure directly to the PLA and China’s Ministry of State Security. 

“Investigations associated with these APT actors indicate that they are having considerable success exploiting publicly known common vulnerabilities and exposures (CVEs) and other avoidable weaknesses within compromised infrastructure,” CISA’s advisory says. 

“Exploitation of zero-day vulnerabilities has not been observed to date. The APT actors will likely continue to adapt their tactics as new vulnerabilities are discovered and as targets implement mitigations, and will likely expand their use of existing vulnerabilities.” 

Exploiting the Known 

Investigators say the actors favor known vulnerabilities over zero-day exploits. Devices from Cisco, Palo Alto, and Ivanti, among others, have been repeatedly compromised. Common attack vectors include command injection, authentication bypass, and remote code execution on internet-facing devices. 

Once inside, the actors establish resilient footholds. They modify access control lists, enable SSH backdoors, manipulate TACACS+ and SNMP configurations, and set up persistent GRE/IPsec tunnels. Even older vulnerabilities, like Cisco’s Smart Install flaw (CVE-2018-0171), remain in play. 

Persistence is paired with stealth. On Cisco IOS XE and NX-OS devices, Guest Shell containers allow the attackers to stage scripts, capture network traffic, and hide artifacts. They can even disable or destroy these environments to erase evidence. 

Lateral Movement and Data Collection 

Once inside, they spread. Laterally. Snatching credentials, capturing authentication traffic, mirroring network flows. Pulling routing tables, mapping the environment. Every protocol, every feature abused. Administrators tracked. Access maintained. Quietly. 

The goal is simple: steal the data. Get it out without being seen. The attackers watch communications. They map the paths. They set the stage for what comes next. 

Defending Against the Threats 

CISA’s advisory is simple: patch the known holes. Watch your edge devices. Layer your defenses. Tools exist to test your resilience. Picus, for example, lets you simulate attacks from Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor, and see if your defenses hold. 

It’s clear that Chinese state-backed actors combine commercial technology and military objectives. They exploit predictable infrastructure gaps. And they do so with patience, precision, and persistence. 

For organizations handling sensitive communications, the message is urgent: patch, monitor, and assume that sophisticated adversaries are already looking for the next foothold. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Klue supply chain breach exposes Salesforce data at several security firms
  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Miasma worm spreads from Red Hat packages to Microsoft repositories

June 11, 20264 Mins Read

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}