Visualização de leitura

Project ORBITAL

Introduction

The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. 

Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.

To construct these networks, adversaries systematically compromise unpatched, end-of-life devices. By targeting legacy, unpatched Small Office/Home Office (SOHO) router and Internet-of-Things (IoT) devices attackers can create a sprawling, decentralised mesh of proxy nodes. By routing their operations through layers of compromised devices, adversaries mask their true origins, making malicious activity blend seamlessly with legitimate regional traffic.

Blogs by my colleagues at Team Cymru as well as Google offer detailed explanations as to why and how these ORBs have grown over many years and continue to expand.

Project Background

Project ORBITAL represents a centralised Open Source Intelligence (OSINT) collection driven by public reporting from advanced research teams across the cybersecurity and technology sectors. This initiative aggregates telemetry and findings from top-tier vendors including Cisco Talos, CrowdStrike, Google, GreyNoise Labs, Lumen Black Lotus Labs, Microsoft, SecurityScorecard, Sekoia, SentinelLabs, Sygnia, and Team Cymru. Furthermore, it incorporates critical alerts and intelligence shared publicly by United States government agencies, specifically the Federal Bureau of Investigation (FBI), the Cyber National Mission Force (CNMF), and the National Security Agency (NSA).

This repository builds on the methodology of my previous OSINT tracking initiatives. It is heavily inspired by the structure and community success of my earlier matrix projects, specifically the Ransomware Tool Matrix (RTM) (here), the Ransomware Vulnerability Matrix (RVM) (here), and the Russian APT Tool Matrix (RUTM) (here). By applying a similar, structured approach to mapping Operational Relay Box (ORB) networks, this project aims to provide defenders with a clear, actionable lexicon for hunting and tracking evasive edge-device botnets.

Graph Visualisation

Once Project ORBITAL was initially assembled, it was then possible to use a GitHub Action automation with NetworkX and PyVis to create a Graph Visualisation using the data collected. Once in this view, some interesting patterns could be observed.

Analysis of the extracted data uncovered that ASUS devices were the most targeted out of all of the targeted devices by ORBs from the public reports.

Another interesting point the graph highlighted is that the LapDogs ORB network had the highest number of reported targeted devices.  

In most reported scenarios, a singular threat group used a dedicated ORB network. However, from extracting the details from the Google and SentinelLabs reports, an adversary like APT15, reportedly leverages both SPACEHOP and PurpleHaze ORB networks, alongside two other separate adversaries UNC2630 and UNC5174.

The overlap in ORB usage suggests these APTs aren't all building their own botnets from scratch. These overlaps likely indicate there are provisioning teams, such as specialised contractors, like Beijing Integrity Tech, who build and maintain these ORB networks and then lease access to the broader Chinese intelligence community in the Ministry of State Security (MSS) and People’s Liberation Army (PLA).

Panda-monium

Below is the list of well-known China-nexus APTs listed using CrowdStrike’s naming scheme and their Google or Microsoft aliases that are all mentioned in Project ORBITAL.

  1. CAULDRON PANDA (aka UNC3886)
  2. ETHEREAL PANDA (aka Flax Typhoon)
  3. JUDGMENT PANDA (APT31, Violet Typhoon)
  4. KEYHOLE PANDA (aka UNC2630, APT5)
  5. MURKY PANDA (aka Silk Typhoon)
  6. VANGUARD PANDA (aka Volt Typhoon)
  7. VIXEN PANDA (aka APT15, Nylon Typhoon) 

The most notable aspect about this list is that it contains APTs with wildly different mandates. VANGUARD PANDA (Volt Typhoon) is famous for pre-positioning within critical infrastructure with the potential disruptive attacks, while KEYHOLE PANDA (APT5) and JUDGMENT PANDA (APT31) are long-running cyber-espionage and IP theft operators. The fact that both the saboteurs and the spies have all adopted ORB networks goes to show that this tactic is not niche but instead is the baseline standard for Chinese APT operational security (OPSEC).

How to Access

You can find Project ORBITAL on my GitHub repository below:


China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns

Chinese, A PRC flag flies atop a metal flagpole

China-sponsored threat groups like Salt Typhoon and Flax Typhoon are increasingly relying on multiple massive botnets comprising edge and IoT devices to run their cyber espionage and network intrusion campaigns, CISA and other security agencies say. The use of such "covert networks" makes it more difficult to detect and mitigate their campaigns.

The post China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns appeared first on Security Boulevard.

Are attackers already embedded in U.S. critical infrastructure networks?

The threat of cyberattacks against critical infrastructure in the United States has evolved beyond data theft and espionage. Intruders are already entrenched in the nation’s most vital systems, waiting to unleash attacks. For instance, CISA has raised alarms about Volt Typhoon, a state-sponsored hacking group that has infiltrated critical infrastructure networks. Their goal? To establish a foothold and prepare for potentially crippling attacks that could disrupt essential services across the nation.

Volt Typhoon embodies a threat far beyond everyday cyber crime. It indicates the dangerous reality of cyber pre-positioning — a tactic that allows cyber actors to infiltrate systems, maintain persistence and potentially launch massively destructive operations. With lifeline sectors such as communications, energy, transportation and water and wastewater systems under threat, the question is no longer if attackers are embedded within U.S. infrastructure but how deeply they have rooted themselves. And the implications directly impact national security.

Nation-state pre-positioning goes beyond espionage

Employed by nation-state actors, pre-positioning goes beyond mere intelligence gathering. By silently lurking within critical infrastructure networks, actors gain the capability to wreak havoc at a moment’s notice. These intrusions, particularly in sectors like water systems and energy grids, serve little espionage value, per Anne Neuberger, the Deputy National Security Adviser for Cyber and Emerging Technologies. This indicates that the infiltrations are likely precursors to far more disruptive objectives.

Volt Typhoon’s methodical approach has allowed them to infiltrate U.S. systems for extended periods — up to five years in some cases — without detection. They’ve targeted the infrastructure that millions of Americans depend on daily. In a time of heightened geopolitical tension, a well-timed cyberattack could grind vital systems to a halt, leaving the nation vulnerable to cascading failures across multiple sectors. The fallout could be unprecedented, impacting national security, the economy and everyday life.

Volt Typhoon’s tactical mastery

Volt Typhoon is no ordinary hacking group. This state-sponsored entity has displayed a level of sophistication that challenges even the most robust cybersecurity defenses. Through its living-off-the-land (LOTL) tactics, the group exploits legitimate network administration tools, blending seamlessly with normal traffic and making detection extremely difficult. Their use of known vulnerabilities in public-facing devices such as routers and VPNs allows them to gain access, while compromised administrator credentials give them the power to burrow deeper into networks and assess operational technology (OT) systems.

The group’s calculated patience is noteworthy. Instead of seeking short-term gains, they carefully study their targets and gain an understanding of the nuances of the systems they infiltrate. In one case, Volt Typhoon spent nine months moving laterally through a water utility’s network, gaining access to crucial OT assets, including water treatment plants and electrical substations. These infiltrations are more than a technical breach — they represent a looming threat to physical infrastructure that could manifest in catastrophic failures.

Read CISA cybersecurity advisories

The FOCAL Plan’s strategic response

In the face of these threats, CISA has developed a robust response: the Federal Civilian Executive Branch (FCEB) Operational Cybersecurity Alignment (FOCAL) Plan. This strategic framework aims to shore up federal cybersecurity defenses by driving coordinated action across agencies. The FOCAL Plan outlines how federal agencies can adopt best practices to defend against pre-positioning and other sophisticated cyber threats, promoting a holistic approach from prevention to incident response.

The FOCAL Plan focuses on five critical areas: asset management, vulnerability management, defensible architecture, cyber supply chain risk management and incident detection and response. Each area plays a crucial role in safeguarding federal systems from persistent threats like Volt Typhoon:

  1. Asset management: Without knowing what assets exist within an organization, it is impossible to protect them. The FOCAL Plan emphasizes comprehensive, continuous visibility into all IT and OT assets to ensure that any unauthorized access can be detected and mitigated quickly.

  2. Vulnerability management: Regular vulnerability scanning and timely patching prevent hackers from exploiting known weaknesses, shutting down one of their primary entry points.

  3. Defensible architecture: Organizations must build resilience into systems, assuming that attacks will happen. This includes implementing zero trust principles to restrict lateral movement within networks and limit the damage attackers can do, even if they gain access.

  4. Supply chain risk management: This addresses the growing reliance on third-party vendors. With many cyberattacks exploiting vulnerabilities in third-party systems, the FOCAL Plan emphasizes the need for agencies to closely monitor their supply chains and ensure that their vendors adhere to strict cybersecurity protocols.

  5. Incident detection and response: This is the FOCAL Plan’s approach to real-time cyber defense. CISA urges agencies to deploy advanced tools like endpoint detection and response (EDR) systems, which can identify and respond to threats before they cause significant damage. The ability to share threat intelligence and coordinate responses across federal agencies is essential for ensuring that the government can act swiftly in the event of an attack.

Mitigation urgency and action

The threat landscape outlined by Volt Typhoon’s actions calls for an urgent response — not just from federal agencies but from every organization that operates critical infrastructure. The key to stopping attackers from exploiting pre-positioned access is to adopt a mentality of constant vigilance and proactive threat hunting. It’s not enough to react to attacks after they happen. Organizations must actively hunt for threats, continually monitor their systems and act quickly to patch vulnerabilities before they can be exploited.

CISA’s FOCAL Plan provides a framework, but it is up to individual organizations to implement these measures at every level. Regular security audits, comprehensive asset management and adherence to the latest cybersecurity best practices are non-negotiable. Organizations must be prepared for the reality of an attack, ensuring that they have backup systems in place. It’s vital to practice incident response through tabletop exercises and maintain open communication channels with CISA and other federal agencies.

The harsh reality is that many organizations may already have pre-positioned attackers within their networks. The objective now is to limit the damage they can do and to ensure that attackers cannot trigger even more widespread disruption.

The clock is ticking

The presence of cyber actors like Volt Typhoon in U.S. critical infrastructure is not hypothetical — it’s happening now, and the consequences of inaction could be devastating. The ability of these attackers to remain hidden within networks for years, studying their targets and preparing for destructive actions, underscores the importance of robust, proactive cybersecurity measures.

The FOCAL Plan is a step in the right direction, but the fight against pre-positioned cyber actors is far from over. It will require a sustained, coordinated effort between federal agencies, private organizations and international allies to ensure that U.S. critical infrastructure is protected and remains resilient.

Explore cybersecurity services

The post Are attackers already embedded in U.S. critical infrastructure networks? appeared first on Security Intelligence.

❌